SCIM with Microsoft Entra ID
Configure automatic user provisioning from Microsoft Entra ID to Stallion using SCIM 2.0, including group-to-role mapping.
SCIM with Microsoft Entra ID
This guide configures Entra ID to create, update and remove Stallion members automatically. Read the SCIM overview first for what SCIM controls and what it deliberately does not.
Before you start
- An active Stallion SSO connection with a verified domain
- You are an SSO Admin on the Stallion organization
- In Entra, you can create and edit enterprise applications (Application Administrator or higher)
- Microsoft Entra ID P1 or P2. Automatic provisioning to an application that is not in the Entra gallery is a paid feature; on the free tier the Provisioning blade stays unavailable.
Step 1 — Get your endpoint and token
In Stallion, go to Settings → Federation → User provisioning (SCIM).
- Set the Default role — what a provisioned user gets when none of their groups is mapped. Leave it as Member unless you have a reason not to.
- Click Generate token.
- Copy the SCIM Base URL and the bearer token.
Copy the token now:
Only a salted hash is stored, so the token cannot be shown again. If you lose it, rotate to issue a new one — the previous token stops working immediately.
Step 2 — Create a non-gallery application for provisioning
Provisioning needs its own Entra application, separate from the one you use for OIDC sign-in.
- In the Azure portal, go to Enterprise applications → New application.
- Choose Create your own application.
- Name it something like
Stallion SCIM. - Select Integrate any other application you don't find in the gallery (Non-gallery), then Create.
Why a second application?:
Entra only offers automatic provisioning on gallery apps and on non-gallery apps created this way. An application you registered under App registrations — which is how OIDC sign-in is set up — uses a template with no provisioning capability, so its Provisioning blade is disabled and shows "Out of the box automatic provisioning to … is not supported today." That message is about how the app was created in Entra, not about Stallion.
Stallion does not mind the split: SCIM requests are authenticated by the bearer token alone, which already identifies your organization. The provisioning app never needs to know about your sign-in app.
You will end up with two applications, which is expected:
| Entra application | Purpose |
|---|---|
| Your OIDC app (App registration) | Who can sign in |
Stallion SCIM (non-gallery) | Who gets provisioned |
Step 3 — Configure provisioning
-
Open the
Stallion SCIMapplication you just created. -
Go to Provisioning → Get started, and set Provisioning Mode to Automatic.
-
Under Admin Credentials:
Field Value Tenant URL The SCIM Base URL from Stallion Secret Token The bearer token from Stallion -
Click Test Connection. Entra fetches the service configuration and verifies the token. If it succeeds, click Save.
Use the URL Stallion gave you:
The base URL is specific to your organization's region. Typing a different Stallion hostname will fail with an error naming the correct one.
Step 4 — Attribute mappings
Entra's defaults work. The attributes Stallion honours are:
| Entra attribute | Stallion use |
|---|---|
userName | The member's email address — must be in a verified domain |
active | false removes the member from the organization |
externalId | Correlation, so the link survives an email change in Entra |
displayName, name.givenName, name.familyName | Display name |
You can safely delete mappings for attributes Stallion does not use (phone
numbers, addresses, job title). Leave userName, active and externalId in
place.
Email changes are not applied:
Stallion deliberately ignores a userName change pushed over SCIM. A Stallion
account's address identifies it across every organization it belongs to, so one
tenant's identity provider must not be able to rename it. externalId is what
keeps the correlation stable if the address changes in Entra.
Step 5 — Assign users and groups
Under Provisioning → Settings, set Scope to Sync only assigned users and groups, then:
- Go to Users and groups on the
Stallion SCIMapplication. - Assign the users, and the groups you intend to map to roles.
- Return to Provisioning and set Provisioning Status to On.
Leave your break-glass admin off this list:
Anyone you assign here gets a SCIM record, and from then on unassigning them removes them from the organization. If you want an account Entra cannot touch — typically whoever set the organization up — assign them to the sign-in application only and leave them off this one. See keeping an account outside SCIM.
Assign people on both applications:
Assignment on your OIDC app decides who can sign in; assignment on
Stallion SCIM decides who gets provisioned. Someone assigned only to the
provisioning app becomes a member but cannot sign in, and someone assigned only
to the sign-in app can authenticate but will never be given access to the
organization.
To test a single user immediately instead of waiting for a cycle, use Provision on demand on the Provisioning blade. It runs one named user right away and shows each step — import, match, determine action, export — with the exact request and response.
Entra's initial cycle can take up to 40 minutes. Subsequent cycles run roughly every 40 minutes.
Step 6 — Map groups to roles
Once Entra has synced your groups, they appear in Stallion under Group role mapping on the SCIM settings page. Choose Admin or Member for each group you want to grant a role.
A typical setup is two groups:
| Entra group | Stallion role |
|---|---|
Stallion Admins | Admin |
Stallion Users | Member |
Anyone assigned the app but in neither group still gets the default role.
Changing a mapping takes effect immediately for everyone currently in the group — you do not have to wait for the next Entra cycle.
What deprovisioning does
When you unassign a user from the application, Entra sends a request setting
active to false. Stallion then removes:
- Organization access
- Project access
- SSO tenant membership
- Every active session — access tokens live 30 days, so revoking them is the point of deprovisioning rather than an extra
The one exception is your last SSO Admin, which Stallion refuses to remove. See SSO Admin is not provisionable.
Troubleshooting
Entra's Provisioning logs (on the enterprise application) show every request and Stallion's response. The SCIM settings page in Stallion shows the same events from the other side, including anything refused.
| Entra symptom | Cause |
|---|---|
| "Out of the box automatic provisioning … is not supported today" | The app was created under App registrations. Create a non-gallery application instead — see Step 2 |
| Provisioning blade unavailable on a non-gallery app | The tenant is on free Entra ID; automatic provisioning needs P1 or P2 |
| Test Connection fails with 401 | Token was rotated or revoked, SCIM is paused, or the SSO connection is not active |
| Test Connection fails naming another host | Wrong region in the Tenant URL — use the URL shown in Stallion |
| User skipped: "not in a verified domain" | The address is outside the domains verified on your SSO connection |
| Deprovision fails with 409 | That member is your only SSO Admin |
| Provisioning quarantined | Entra quarantines a job after repeated failures. Fix the cause, then Restart provisioning |
| Users provisioned but all at the same role | Their groups are not mapped yet |