SCIM with Microsoft Entra ID

Configure automatic user provisioning from Microsoft Entra ID to Stallion using SCIM 2.0, including group-to-role mapping.

SCIM with Microsoft Entra ID

This guide configures Entra ID to create, update and remove Stallion members automatically. Read the SCIM overview first for what SCIM controls and what it deliberately does not.

Before you start

  • An active Stallion SSO connection with a verified domain
  • You are an SSO Admin on the Stallion organization
  • In Entra, you can create and edit enterprise applications (Application Administrator or higher)
  • Microsoft Entra ID P1 or P2. Automatic provisioning to an application that is not in the Entra gallery is a paid feature; on the free tier the Provisioning blade stays unavailable.

Step 1 — Get your endpoint and token

In Stallion, go to Settings → Federation → User provisioning (SCIM).

  1. Set the Default role — what a provisioned user gets when none of their groups is mapped. Leave it as Member unless you have a reason not to.
  2. Click Generate token.
  3. Copy the SCIM Base URL and the bearer token.

Copy the token now:

Only a salted hash is stored, so the token cannot be shown again. If you lose it, rotate to issue a new one — the previous token stops working immediately.

Provisioning needs its own Entra application, separate from the one you use for OIDC sign-in.

  1. In the Azure portal, go to Enterprise applications → New application.
  2. Choose Create your own application.
  3. Name it something like Stallion SCIM.
  4. Select Integrate any other application you don't find in the gallery (Non-gallery), then Create.

Why a second application?:

Entra only offers automatic provisioning on gallery apps and on non-gallery apps created this way. An application you registered under App registrations — which is how OIDC sign-in is set up — uses a template with no provisioning capability, so its Provisioning blade is disabled and shows "Out of the box automatic provisioning to … is not supported today." That message is about how the app was created in Entra, not about Stallion.

Stallion does not mind the split: SCIM requests are authenticated by the bearer token alone, which already identifies your organization. The provisioning app never needs to know about your sign-in app.

You will end up with two applications, which is expected:

Entra applicationPurpose
Your OIDC app (App registration)Who can sign in
Stallion SCIM (non-gallery)Who gets provisioned

Step 3 — Configure provisioning

  1. Open the Stallion SCIM application you just created.

  2. Go to Provisioning → Get started, and set Provisioning Mode to Automatic.

  3. Under Admin Credentials:

    FieldValue
    Tenant URLThe SCIM Base URL from Stallion
    Secret TokenThe bearer token from Stallion
  4. Click Test Connection. Entra fetches the service configuration and verifies the token. If it succeeds, click Save.

Use the URL Stallion gave you:

The base URL is specific to your organization's region. Typing a different Stallion hostname will fail with an error naming the correct one.

Step 4 — Attribute mappings

Entra's defaults work. The attributes Stallion honours are:

Entra attributeStallion use
userNameThe member's email address — must be in a verified domain
activefalse removes the member from the organization
externalIdCorrelation, so the link survives an email change in Entra
displayName, name.givenName, name.familyNameDisplay name

You can safely delete mappings for attributes Stallion does not use (phone numbers, addresses, job title). Leave userName, active and externalId in place.

Email changes are not applied:

Stallion deliberately ignores a userName change pushed over SCIM. A Stallion account's address identifies it across every organization it belongs to, so one tenant's identity provider must not be able to rename it. externalId is what keeps the correlation stable if the address changes in Entra.

Step 5 — Assign users and groups

Under Provisioning → Settings, set Scope to Sync only assigned users and groups, then:

  1. Go to Users and groups on the Stallion SCIM application.
  2. Assign the users, and the groups you intend to map to roles.
  3. Return to Provisioning and set Provisioning Status to On.

Leave your break-glass admin off this list:

Anyone you assign here gets a SCIM record, and from then on unassigning them removes them from the organization. If you want an account Entra cannot touch — typically whoever set the organization up — assign them to the sign-in application only and leave them off this one. See keeping an account outside SCIM.

Assign people on both applications:

Assignment on your OIDC app decides who can sign in; assignment on Stallion SCIM decides who gets provisioned. Someone assigned only to the provisioning app becomes a member but cannot sign in, and someone assigned only to the sign-in app can authenticate but will never be given access to the organization.

To test a single user immediately instead of waiting for a cycle, use Provision on demand on the Provisioning blade. It runs one named user right away and shows each step — import, match, determine action, export — with the exact request and response.

Entra's initial cycle can take up to 40 minutes. Subsequent cycles run roughly every 40 minutes.

Step 6 — Map groups to roles

Once Entra has synced your groups, they appear in Stallion under Group role mapping on the SCIM settings page. Choose Admin or Member for each group you want to grant a role.

A typical setup is two groups:

Entra groupStallion role
Stallion AdminsAdmin
Stallion UsersMember

Anyone assigned the app but in neither group still gets the default role.

Changing a mapping takes effect immediately for everyone currently in the group — you do not have to wait for the next Entra cycle.

What deprovisioning does

When you unassign a user from the application, Entra sends a request setting active to false. Stallion then removes:

  • Organization access
  • Project access
  • SSO tenant membership
  • Every active session — access tokens live 30 days, so revoking them is the point of deprovisioning rather than an extra

The one exception is your last SSO Admin, which Stallion refuses to remove. See SSO Admin is not provisionable.

Troubleshooting

Entra's Provisioning logs (on the enterprise application) show every request and Stallion's response. The SCIM settings page in Stallion shows the same events from the other side, including anything refused.

Entra symptomCause
"Out of the box automatic provisioning … is not supported today"The app was created under App registrations. Create a non-gallery application instead — see Step 2
Provisioning blade unavailable on a non-gallery appThe tenant is on free Entra ID; automatic provisioning needs P1 or P2
Test Connection fails with 401Token was rotated or revoked, SCIM is paused, or the SSO connection is not active
Test Connection fails naming another hostWrong region in the Tenant URL — use the URL shown in Stallion
User skipped: "not in a verified domain"The address is outside the domains verified on your SSO connection
Deprovision fails with 409That member is your only SSO Admin
Provisioning quarantinedEntra quarantines a job after repeated failures. Fix the cause, then Restart provisioning
Users provisioned but all at the same roleTheir groups are not mapped yet