Azure Entra ID SCIM User Provisioning
If your company uses Azure as an IdP (Identity Provider) to manage employees’ access to services, you can take advantage of Azure Entra ID SCIM user provisioning to manage users in LeaveWizard.
However, Microsoft has suspended new marketplace submissions, so currently you have to configure SSO manually on Azure Entra ID as we cannot add LeaveWizard and make it available in the gallery.
When you enable SCIM provisioning, you will accomplish user management tasks, such as adding users and updating their details, with Azure Entra ID. LeaveWizard will deactivate these functions on the web app.
We use the industry standard protocol SCIM (System for Cross-domain Identity Management) to provide the integration between Azure Entra ID and LeaveWizard.
Configuring Provisioning
You need to enable SCIM provisioning on LeaveWizard and enable API (Application Programming Interface) integration and provisioning on Azure Entra ID. However, before you do this, you need to set up Azure Entra ID SSO (Single Sign On) if you have not done so already.
Enable Provisioning In LeaveWizard
As a LeaveWizard administrator, select company settings from the configuration option on the main menu. Navigate to the authentication section and click the ‘Reconfigure’ button.

If you only see a ‘Configure’ button, you need to configure SAML authentication first. Please follow the guidance in our Azure Entra ID SSO (Single Sign On) article to do that.

Then tick the ‘Enable SCIM Provisioning’ box and click ‘Submit’.

Create A LeaveWizard API Client And Get An Access Token
Entra ID will need access to the LeaveWizard API to synchronise user data. Please register a new API client and generate an access token on LeaveWizard.
From ‘Configuration’ on the main menu, select the ‘Company Settings’ sub menu from the drop-down and then navigate down to the ‘API Access’ section on the page.

Register a new client and get an ID and secret (password) from our server to use the API in the Add Client section. Securely save the client secret for later use.

Once you successfully add a new client, the system will add it to the list showing the name you chose and the client ID that was generated. Click on its name, which is a link to edit the client and to generate tokens. In the Generate Token section, generate a token and copy it to your clipboard using the ‘Copy’ button so you can paste it into Entra. If you want to enable provisioning on Entra later, you should securely save the token, as the system will not show it once you leave the page. You can, however, generate a new token if you lose it or it expires.

Enable Provisioning On Azure Entra ID
On the Microsoft Azure portal, navigate to the ‘Enterprise applications’ service. Either select ‘Enterprise Applications’ from the Azure services list on the main page or, if it does not list it, select ‘More services’ and select it on the ‘All services’ page from the ‘Identity’ category.

Select the LeaveWizard app you previously created when you set up Azure Entra ID SSO (Single Sign On). On the LeaveWizard app overview page, in the ‘Getting Started’ section, click the ‘Get started’ link in the ‘Provision User Accounts’ box or you can select ‘Manage’ and then ‘Provisioning’ from the menu on the left-hand side of the page.

Then click the ‘Get started’ button on the provisioning page.

On the next page, select ‘Manage’ and then ‘Provisioning’ from the menu on the left-hand side of the page.

Expand the ‘Admin credentials’ section and paste the token from LeaveWizard into the Secret Token field.
Then enter https://scim.leavewizard.com/scim in the ‘Tenant URL’ field.

Click the ‘Test Connection’ button to check that the connection works. You should get a confirmation message on the top right-hand side of the page. You have now established a connection between LeaveWizard and Azure Entra for provisioning, which should work until the token expires after the duration you chose when you created it.

Click the ‘Save’ icon at the top of the page to save your updates.
Now expand the ‘Mapping’ section and click the ‘Provision Microsoft Entra ID Users’ link.

Locate ‘externalId’ in the list of attribute mappings and click the ‘Edit’ button on the right-hand side of its row.

Using the drop-down, select ‘objectId’ for the ‘Source attribute’. Then click ‘OK’ at the bottom of the page.

It will then return you to the attribute mappings. Click ‘Save’ at the top of the page to save your update.

Using SCIM
After you have enabled SCIM provisioning on LeaveWizard and Azure, you need to add your users to Entra ID so you can then add them to the Azure LeaveWizard app you created. However, if you already have users configured in Entra, you can skip this step.
Add Users To Entra ID
On the Microsoft Azure portal, navigate to the ‘Microsoft Entra ID’ service. Either select ‘Microsoft Entra ID’ from the Azure services list on the main page or, if it does not list it, select ‘More services’ and select it on the ‘All services’ page from the ‘Identity’ category. You can add users using the ‘+ Add’ drop-down at the top of the page and then select ‘User’.

Assign Users To The LeaveWizard App
Once you have added users to Entra ID, they will be available to assign to your LeaveWizard app. On the Microsoft Azure portal, navigate to the ‘Enterprise applications’ service and select the LeaveWizard app. On the overview page, in the ‘Getting Started’ section, click the ‘Get started’ link in the ‘Assign users and groups’ box or you can select ‘Manage’ and then ‘Users and groups’ from the menu on the left-hand side of the page. You can then add users using the ‘+ Add user/group’ button at the top of the page.

When you first go to the Add assignment page, you have selected no users. Click the ‘None selected’ link under ‘Users and groups’ from the menu on the left-hand side of the page.

This will open a user and group search and selector page. Select the users you wish to assign to the LeaveWizard app and click the ‘Select’ button at the bottom of the page.

This will return you to the Add assignment page, which will now show the number of users you have selected in the link under ‘Users and groups’ on the menu.

If you are happy with your selection, then click the ‘Assign’ button or click the link to amend your selection. When you assign users, you will get a confirmation message on the top right-hand side of the page.

Provision Users
Once you have added users to the app, you can start automatic provisioning. On the Microsoft Azure portal, navigate to the ‘Enterprise applications’ service and select the LeaveWizard app. On the overview page, in the ‘Getting Started’ section, click the ‘Get started’ link in the ‘Provision user accounts’ box or you can select ‘Manage’ and then ‘Provisioning’ from the menu on the left-hand side of the page. This will take you to the page where you previously enabled provisioning. You can start provisioning here by moving the ‘Provisioning Status’ slider to ‘On’. You can also start provisioning on the app overview page.

Unfortunately, when configuring manually, the access token you created previously will expire. When this happens, Azure will log an error and the automatic provisioning will enter a quarantined state. You will need to generate a new token in LeaveWizard and enter this in the provisioning ‘Secret Token’ field as you did previously. You can restart provisioning on the app overview page.
We recommend you enable ‘Send an email notification when a failure occurs’ in the ‘Settings’ section of the provisioning page so it notifies you when this occurs.

Using SCIM Considerations
When you add and assign new LeaveWizard users from Azure, it will add them as pending users. You will need to complete the add user process on LeaveWizard for these users. See the Adding New Users With SCIM Enabled section in the Adding New Users knowledge base article. If the user already exists on LeaveWizard, Azure will try to match the user using their Entra ‘User principal name’ with their LeaveWizard ‘User Name’ .
Azure sets their four basic attributes.
‘First Name’ LeaveWizard field matches with ‘First name’ on Entra ID
‘Last Name’ LeaveWizard field matches with ‘Last name’ on Entra ID
‘User Name’ LeaveWizard field matches with ‘User principal name’ on Entra ID
‘Email’ LeaveWizard field matches with ‘Display name’ on Entra ID
Note that if Azure matches a user but their attributes differ, it will overwrite the attributes on LeaveWizard. For example, if the user has a different username and email on LeaveWizard and the email does not match that on Azure, it will overwrite the email on LeaveWizard.
Also note that the user password is not an attribute that Entra synchronises, so existing users should use their original LeaveWizard password to sign in when using the username-password combination and don’t want to use SSO. New users will not have a LeaveWizard password. If they want to use the username-password combination to sign in, then they should use the ‘Forgot Password?’ link on the login page to generate one.
Supported Provisioning Features
LeaveWizard supports the following provisioning features.
Push Users
Azure Entra ID adds users assigned to the LeaveWizard application as members of your LeaveWizard company. Either Azure Entra ID matches them with an existing LeaveWizard user or it creates a new user.
Push Groups
You can push Azure Entra ID ‘Groups’ and their members to LeaveWizard ‘workgroups’ and members.
Update User Attributes
Users in Azure Entra ID that are assigned to the LeaveWizard application can have their profile information updated from Azure Entra ID. It can only update their basic attributes, such as ‘First Name’ and ‘Last Name’. It cannot change custom attributes, such as ‘Position’ and ‘Nationality’, that they may have on LeaveWizard.
Deactivate And Reactivate Users
You can deactivate or reactivate users in Azure Entra ID that are assigned to the LeaveWizard application.
Single Sign On
SP-Initiated flow allows the SP (Service Provider), LeaveWizard, to start the SSO (Single Sign On) process. This option gives users the ability to sign into LeaveWizard with their SSO email address. LeaveWizard sends an authorisation request to the IdP, Azure Entra ID, and when they authenticate the user’s identity, LeaveWizard logs them in.
Limitations
Here is a list of limitations and characteristics of Azure Entra ID provisioning with LeaveWizard.
Groups
LeaveWizard only allows a user to belong to a single workgroup at a time. If you push a group from Azure Entra ID to LeaveWizard when you had already assigned a user to a different workgroup, it will automatically move them from their old workgroup to the newly pushed workgroup.
