Azure

1. Enable SCIM

  1. Open the application that is configured for SAML in the Entra Id admin dashboard. Then select Provisioning on the left sub-nav

    Screenshot 2024-03-27 at 3.39.31 PM.png

  1. If this is the first time Provisioning is being configured, an informational screen will be presented. Select “Connect your application”. if this is not the first time configuring Provisioning, select "Connectivity".
Screenshot 2024-03-27 at 3.40.49 PM.png
  1. On the Connectivity page, enter the following values:

    • Select authentication method: Bearer authentication
    • Tenant URL: https://<your-api-domain>/scim/v2
      • Your API domain is similar to your Alloy application domain, but uses api instead of app.

        For example:

    • Secret Token: <base64_encode(alloy_api_token:alloy_api_secret)>
      • You can create your alloy_api_token and alloy_api_secret in the Alloy dashboard under Settings > API Keys.

      • To create the Secret Token, Base64-encode the API token and secret in the following format:

        alloy_api_token:alloy_api_secret

        For example, you can run the following command in your browser's developer console:

        btoa("alloy_api_token:alloy_api_secret")

        Enter only the resulting Base64-encoded value in the Secret Token field. Do not add a prefix such as Bearer.

        For more information, see the Alloy authentication guide. Alloy currently supports only Bearer authentication for SCIM.

    • Select Test Connection. After Microsoft Entra ID successfully connects to Alloy, select Save.

  2. Once the saving process is complete, scroll down as the toggle header Mappings should now be visible. Select Provisioning Microsoft Entra ID Users.

Screenshot 2024-03-29 at 5.31.03 AM.png

  1. Modify the Users Attribute Mapping to mirror the below image then select Save. That’s it! SCIM Provisioning is now configured. (phoneNumbers[type eq "mobile"].valueis optional)

    Screenshot 2024-03-29 at 5.31.03 AM.png

2. Assign Users to Alloy app.

  1. Open the application that is configured for SAML in the Entra Id admin dashboard and select Assign users and groups or select Users and Groups on the left sub nav.

    Screenshot 2024-03-29 at 6.16.56 AM.png
  2. The application may already contain assigned users. To assign a user, select “Add user/group”. A modal should display. Select “None Selected” to begin selecting users to assign.

    Screenshot 2024-03-29 at 6.19.35 AM.png
    Screenshot 2024-03-29 at 6.24.13 AM.png
  3. Click “Select” then “Assign” to complete the process.

    Screenshot 2024-03-29 at 6.30.48 AM.png
    Screenshot 2024-03-29 at 6.32.33 AM.png
  4. Navigate to “Provisioning” on the left sub-nav.

    Screenshot 2024-03-29 at 6.39.36 AM.png
  5. The user has been assigned to the application on Entra Id. Entra Id updates Alloy with these changes on a 40 mins fixed interval basis. Due to the secret token’s short lifespan (1hr), its recommended to use the “**Provision on demand “**option when attempting to synchronize a small number users or groups.

    Screenshot 2024-03-29 at 6.40.20 AM.png
  6. Provisioning on Demand. After clicking Provision, any changes made to the users active status, first name, last name, or phone number will propagate to Alloy.

Screenshot 2024-03-29 at 6.40.20 AM.png

3. Assign Groups to Alloy app

  1. Open the application that is configured for SAML in the Entra Id admin dashboard and select Assign users and groups or select Users and Groups on the left sub nav.

    Screenshot 2024-03-29 at 6.16.56 AM.png
  2. To assign a Group, select “Add user/group”. A modal should display. Select “None Selected” to begin selecting groups to assign.

    Please note:💡: To assign a group to an existing role, make sure the group name exactly matches the role within Alloy. Any users assigned to that group will be provisioned into the corresponding Alloy role.

    Screenshot 2024-03-29 at 6.19.35 AM.png
    image (3).png
  3. Click “Select” then “Assign” to complete the process.

    image (4).png
  4. Navigate to “Provisioning” on the left sub-nav.

    Screenshot 2024-03-29 at 6.39.36 AM.png
  5. The group has been assigned to the application on Entra Id. Entra Id updates Alloy with these changes on a 40-minute fixed interval basis. Due to the secret token’s short lifespan (1hr), it's recommended to use the “**Provision on demand “**option when attempting to synchronize a small number of users or groups.

    Screenshot 2024-03-29 at 6.40.20 AM.png
  6. Provisioning on Demand. After clicking Provision, any changes made to the group's name will propagate to Alloy.

    Screenshot 2024-03-29 at 6.40.20 AM.png
    Screenshot 2024-03-29 at 6.40.20 AM.png
    Screenshot 2024-03-29 at 6.40.20 AM.png
    Screenshot 2024-03-29 at 6.40.20 AM.png

4. Verify the User and Groups created on the Alloy app

  1. Login to the Alloy app. go to the settings, nav to Agents and Groups page. verify the user and group are added to the Alloy app

    Screenshot 2024-03-29 at 6.40.20 AM.png
    Screenshot 2024-03-29 at 6.40.20 AM.png

Did this page help you?