Skip to main content
< All Topics
Print

Azure Entra ID SCIM User Provisioning

If your company uses Azure as an IdP (Identity Provider) to manage employees’ access to services, you can take advantage of Azure Entra ID SCIM user provisioning to manage users in LeaveWizard.

However, Microsoft has suspended new marketplace submissions, so currently you have to configure SSO manually on Azure Entra ID as we cannot add LeaveWizard and make it available in the gallery.

When you enable SCIM provisioning, you will accomplish user management tasks, such as adding users and updating their details, with Azure Entra ID. LeaveWizard will deactivate these functions on the web app.

We use the industry standard protocol SCIM (System for Cross-domain Identity Management) to provide the integration between Azure Entra ID and LeaveWizard.

Configuring Provisioning

You need to enable SCIM provisioning on LeaveWizard and enable API (Application Programming Interface) integration and provisioning on Azure Entra ID. However, before you do this, you need to set up Azure Entra ID SSO (Single Sign On) if you have not done so already.

Enable Provisioning In LeaveWizard

As a LeaveWizard administrator, select company settings from the configuration option on the main menu. Navigate to the authentication section and click the ‘Reconfigure’ button.

A screenshot showing the authentication section on the company settings page of LeaveWizard displaying the 'Reconfigure' button.

If you only see a ‘Configure’ button, you need to configure SAML authentication first. Please follow the guidance in our Azure Entra ID SSO (Single Sign On) article to do that.

A screenshot showing the authentication section on the company settings page of LeaveWizard displaying the 'Configure' button.

Then tick the ‘Enable SCIM Provisioning’ box and click ‘Submit’.

A screenshot showing the 'Enable SCIM Provisioning' box on the Configure SAML authentication page which you should tick.

 

Create A LeaveWizard API Client And Get An Access Token

Entra ID will need access to the LeaveWizard API to synchronise user data. Please register a new API client and generate an access token on LeaveWizard.

From ‘Configuration’ on the main menu, select the ‘Company Settings’ sub menu from the drop-down and then navigate down to the ‘API Access’ section on the page.

A screenshot showing the ‘API Access’ section of the ‘Company Settings' page with no clients.

Register a new client and get an ID and secret (password) from our server to use the API in the Add Client section. Securely save the client secret for later use.

A screenshot showing the 'Add client' page to register a new client and get an ID and secret (password) from our server to use the API.

Once you successfully add a new client, the system will add it to the list showing the name you chose and the client ID that was generated. Click on its name, which is a link to edit the client and to generate tokens. In the Generate Token section, generate a token and copy it to your clipboard using the ‘Copy’ button so you can paste it into Entra. If you want to enable provisioning on Entra later, you should securely save the token, as the system will not show it once you leave the page. You can, however, generate a new token if you lose it or it expires.

A screenshot showing the 'Edit Client' page. Once you successfully add a new client, the system will add it to the list showing the name you chose and the client ID that was generated. Click on its name, which is a link to this page, and generate a token.

Enable Provisioning On Azure Entra ID

On the Microsoft Azure portal, navigate to the ‘Enterprise applications’ service. Either select ‘Enterprise Applications’ from the Azure services list on the main page or, if it does not list it, select ‘More services’ and select it on the ‘All services’ page from the ‘Identity’ category.

A screenshot showing the Azure home page and the Azure services list.

Select the LeaveWizard app you previously created when you set up Azure Entra ID SSO (Single Sign On). On the LeaveWizard app overview page, in the ‘Getting Started’ section, click the ‘Get started’ link in the ‘Provision User Accounts’ box or you can select ‘Manage’ and then ‘Provisioning’ from the menu on the left-hand side of the page.

A screenshot showing the LeaveWizard app overview page with the ‘Provision User Accounts’ box and the ‘Provisioning’ option on the menu.

Then click the ‘Get started’ button on the provisioning page.

A screenshot showing the 'Get started' button on the provisioning overview page.

On the next page, select ‘Manage’ and then ‘Provisioning’ from the menu on the left-hand side of the page.

A screenshot showing the manage provisioning option on the menu.

Expand the ‘Admin credentials’ section and paste the token from LeaveWizard into the Secret Token field.

Then enter https://scim.leavewizard.com/scim in the ‘Tenant URL’ field.

A screenshot showing the expanded 'Admin credentials' section with the Secret Token and Tenant URL fields.

Click the ‘Test Connection’ button to check that the connection works. You should get a confirmation message on the top right-hand side of the page. You have now established a connection between LeaveWizard and Azure Entra for provisioning, which should work until the token expires after the duration you chose when you created it.

A screenshot showing a successful confirmation message which appears at the top right-hand side of the page when you click the 'Test Connection' button.

Click the ‘Save’ icon at the top of the page to save your updates.

Now expand the ‘Mapping’ section and click the ‘Provision Microsoft Entra ID Users’ link.

A screenshot showing the expanded 'Mapping' section with the 'Provision Microsoft Entra ID Users' link.

Locate ‘externalId’ in the list of attribute mappings and click the ‘Edit’ button on the right-hand side of its row.

A screenshot showing the 'externalId' attribute on the attribute mappings page with an 'Edit' button on the right-hand side of its row.

Using the drop-down, select ‘objectId’ for the ‘Source attribute’. Then click ‘OK’ at the bottom of the page.

A screenshot showing 'objectId' set for the 'Source attribute' on the edit attribute page for the 'externalId' attribute.

It will then return you to the attribute mappings. Click ‘Save’ at the top of the page to save your update.

A screenshot showing the 'Save' button at the top of the attribute mapping page.

Using SCIM

After you have enabled SCIM provisioning on LeaveWizard and Azure, you need to add your users to Entra ID so you can then add them to the Azure LeaveWizard app you created. However, if you already have users configured in Entra, you can skip this step.

Add Users To Entra ID

On the Microsoft Azure portal, navigate to the ‘Microsoft Entra ID’ service. Either select ‘Microsoft Entra ID’ from the Azure services list on the main page or, if it does not list it, select ‘More services’ and select it on the ‘All services’ page from the ‘Identity’ category. You can add users using the ‘+ Add’ drop-down at the top of the page and then select ‘User’.

A screenshot showing the Entra ID overview page with the Add drop-down with the user option selected.

Assign Users To The LeaveWizard App

Once you have added users to Entra ID, they will be available to assign to your LeaveWizard app. On the Microsoft Azure portal, navigate to the ‘Enterprise applications’ service and select the LeaveWizard app. On the overview page, in the ‘Getting Started’ section, click the ‘Get started’ link in the ‘Assign users and groups’ box or you can select ‘Manage’ and then ‘Users and groups’ from the menu on the left-hand side of the page. You can then add users using the ‘+ Add user/group’ button at the top of the page.

A screenshot showing the empty LeaveWizard app manage user and groups page.

When you first go to the Add assignment page, you have selected no users. Click the ‘None selected’ link under ‘Users and groups’ from the menu on the left-hand side of the page.

A screenshot showing the add assigment (users and groups to LeaveWizard app) and the ‘None selected’ link to start adding.

This will open a user and group search and selector page. Select the users you wish to assign to the LeaveWizard app and click the ‘Select’ button at the bottom of the page.

A screenshot showing the user and group search and selector page to select which to assign to the LeaveWizard app.

This will return you to the Add assignment page, which will now show the number of users you have selected in the link under ‘Users and groups’ on the menu.

A screenshot showing the add assigment page and a link with the number currently selected.

If you are happy with your selection, then click the ‘Assign’ button or click the link to amend your selection. When you assign users, you will get a confirmation message on the top right-hand side of the page.

A screenshot showing the LeaveWizard app manage user and groups page with the added user and a confirmation message.

Provision Users

Once you have added users to the app, you can start automatic provisioning. On the Microsoft Azure portal, navigate to the ‘Enterprise applications’ service and select the LeaveWizard app. On the overview page, in the ‘Getting Started’ section, click the ‘Get started’ link in the ‘Provision user accounts’ box or you can select ‘Manage’ and then ‘Provisioning’ from the menu on the left-hand side of the page. This will take you to the page where you previously enabled provisioning. You can start provisioning here by moving the ‘Provisioning Status’ slider to ‘On’. You can also start provisioning on the app overview page.

A screenshot showing the manage Provisioning page and the Provisioning Status slider on.

Unfortunately, when configuring manually, the access token you created previously will expire. When this happens, Azure will log an error and the automatic provisioning will enter a quarantined state. You will need to generate a new token in LeaveWizard and enter this in the provisioning ‘Secret Token’ field as you did previously. You can restart provisioning on the app overview page.

We recommend you enable ‘Send an email notification when a failure occurs’ in the ‘Settings’ section of the provisioning page so it notifies you when this occurs.

A screenshot showing the expanded 'Mapping' section of the manage provisioning page with the 'Send an email notification when a failure occurs' tick box and 'Notification Email' field.

Using SCIM Considerations

When you add and assign new LeaveWizard users from Azure, it will add them as pending users. You will need to complete the add user process on LeaveWizard for these users. See the Adding New Users With SCIM Enabled section in the Adding New Users knowledge base article. If the user already exists on LeaveWizard, Azure will try to match the user using their Entra ‘User principal name’ with their LeaveWizard ‘User Name’ .

Azure sets their four basic attributes.

‘First Name’ LeaveWizard field matches with ‘First name’ on Entra ID

‘Last Name’ LeaveWizard field matches with ‘Last name’ on Entra ID

‘User Name’ LeaveWizard field matches with ‘User principal name’ on Entra ID

‘Email’ LeaveWizard field matches with ‘Display name’ on Entra ID

Note that if Azure matches a user but their attributes differ, it will overwrite the attributes on LeaveWizard. For example, if the user has a different username and email on LeaveWizard and the email does not match that on Azure, it will overwrite the email on LeaveWizard.

Also note that the user password is not an attribute that Entra synchronises, so existing users should use their original LeaveWizard password to sign in when using the username-password combination and don’t want to use SSO. New users will not have a LeaveWizard password. If they want to use the username-password combination to sign in, then they should use the ‘Forgot Password?’ link on the login page to generate one.

Supported Provisioning Features

LeaveWizard supports the following provisioning features.

Push Users

Azure Entra ID adds users assigned to the LeaveWizard application as members of your LeaveWizard company. Either Azure Entra ID matches them with an existing LeaveWizard user or it creates a new user.

Push Groups

You can push Azure Entra ID ‘Groups’ and their members to LeaveWizard ‘workgroups’ and members.

Update User Attributes

Users in Azure Entra ID that are assigned to the LeaveWizard application can have their profile information updated from Azure Entra ID. It can only update their basic attributes, such as ‘First Name’ and ‘Last Name’. It cannot change custom attributes, such as ‘Position’ and ‘Nationality’, that they may have on LeaveWizard.

Deactivate And Reactivate Users

You can deactivate or reactivate users in Azure Entra ID that are assigned to the LeaveWizard application.

Single Sign On

SP-Initiated flow allows the SP (Service Provider), LeaveWizard, to start the SSO (Single Sign On) process. This option gives users the ability to sign into LeaveWizard with their SSO email address. LeaveWizard sends an authorisation request to the IdP, Azure Entra ID, and when they authenticate the user’s identity, LeaveWizard logs them in.

Limitations

Here is a list of limitations and characteristics of Azure Entra ID provisioning with LeaveWizard.

Groups

LeaveWizard only allows a user to belong to a single workgroup at a time. If you push a group from Azure Entra ID to LeaveWizard when you had already assigned a user to a different workgroup, it will automatically move them from their old workgroup to the newly pushed workgroup.

 

Table of Contents