Skip to main content

About SCIM Directory Integration with Microsoft Entra ID

SCIM Directory Integration with Microsoft Entra ID in Iru Endpoint allows you to set up SCIM-based user directory synchronization between Microsoft Entra ID and Iru Endpoint, enabling automatic user and group provisioning and deprovisioning.

How It Works

The SCIM integration creates a secure connection between Microsoft Entra ID and Iru Endpoint, enabling automatic synchronization of user and group data. When users or groups are added, modified, or removed in Microsoft Entra ID, these changes are automatically reflected in Iru Endpoint through the SCIM protocol.

Prerequisites

  • Be sure to review the supported user and group attributes listed in the SCIM Directory Integration article.
  • Ensure that nested groups are not included with SCIM as Microsoft does not support this functionality.

Get the SCIM Token and API URL

Complete these steps in Iru Endpoint first. You will need the SCIM access token and API URL when configuring Microsoft Entra ID. For full details, see the SCIM Directory Integration article.
1

Open Integrations

In Iru Endpoint, in the sidebar, select the Account Menu Button, then select Integrations.
Screenshot of the account menu with Integrations option highlighted
2

Browse all integrations

Select Browse all integrations in the upper-right of the Integrations page.
3

Filter Directory integrations

Check the Directory integrations filter.
4

Select SCIM protocol

Select the SCIM protocol tile.
Add new integration page with SCIM protocol tile
5

Start Configuration

Select Get started.
6

Name the Integration

Enter a unique name for the SCIM integration.
7

Generate Authentication Token

Select Generate token. The SCIM integration uses an HTTP authorization header with a Bearer Token.
Configure a SCIM user integration screen with name field and Generate token button
8

Copy the Token

Select Copy token. The token will not be visible again after you select Done. Store it securely, as you will need it in the Microsoft Entra ID tab.
9

Confirm and Complete Setup

Confirm that you have copied the token by checking the box, then select Done. You will return to the Integrations page.
Copy token and configure with your identity provider dialog with Copy token button
10

Access Integration Details

Select the ellipsis on the SCIM directory integration you created.
11

View Details

Select View Details.
Directory integrations list with SCIM integration and ellipsis menu showing View details, Rename, Rotate token, Delete
12

Copy API URL

Copy the SCIM API URL (e.g. https://subdomain.api.iru.com/api/v1/scim). Your identity provider will require this. The URL displayed in your tenant may still show the api.kandji.io domain. The api.kandji.io version of the SCIM API URL will also work for this purpose.
13

Close Details

Select Close.
View user integration details modal with SCIM API URL and copy button
14

Switch to Microsoft Entra ID Tab

Keep the token and API URL available, then switch to the Microsoft Entra ID tab to create and configure the SCIM app integration.