Skip to content
  • There are no suggestions because the search field is empty.

Azure SCIM - Automatic User Provisioning

 

This article describes instructions that handle Step 2: Configuring the Directory sync for automatic user provisioning


Requirements:

  1. Activated Azure SSO in the Wizer Admin Panel. Azure Provisioning won’t work without it.

    Azure SSO instructions

  2. SCIM bearer token. Generate a SCIM bearer token on the SSO Settings page.

  3. Azure AD account with correct permissions to configure provisioning (e.g. Application Administrator, Cloud Application Administrator, or Global Administrator).

Instructions for SCIM application setup:

The SCIM application must be set up for Azure Provisioning (user synchronization) to work. Users will continue to use the SSO application to log in.

Instructions:

  1. Log into the Azure Administration Dashboard https://portal.azure.com/

  2. Click the Microsoft Entra ID buttonimage-png-Apr-09-2024-08-27-33-8437-AM

  3. Click the Enterprise applications Tab

     

  4. Click the New application button

  5. In the Microsoft Entra Gallery, click Create your Own Application

    1. Enter application name (e.g. “Wizer Provisioning”)

    2. Click Integrate any other application you don't find in the gallery option

    3. Click Create

  6. Click the Properties tab and turn off the visibility for users and then click Save

  7. Click the Provisioning tab and then click the New configuration:

  8. In the Provisioning tab enter the SCIM Base URL and SCIM Bearer Token

    • Select Automatic Provisioning Mode

    • For Tenant URL enter: https://api.wizer-training.com/api/v1/scim/v2

    • For Secret Token (SCIM bearer token) enter the value that was generated via the Wizer admin console

    • Click Test Connection

    • After you get notified that the supplied credentials are authorized, click Create

  9. Define who will be in scope for provisioning

    Only users that are in scope for provisioning will appear in Wizer.

    The Azure AD provisioning service allows you to scope who will be provisioned based on assignment to the application (option A) or based on attributes of the user/group (option B).

    We recommend provisioning users through assigning groups (option A).

    Start small. Test with a small set of users and groups before rolling out to everyone.

    - (option A) When the scope for provisioning is set to assigned users and groups, you can control this by assigning one or two users or groups to the app.

    - (option B) When the scope is set to all users and groups, you can specify an attribute-based scoping filter (https://docs.microsoft.com/en-us/azure/active-directory/app-provisioning/define-conditional-rules-for-provisioning-user-accounts).

    Assigning users and groups - option A (recommended)

    If you choose to scope who will be provisioned to your app based on assignment, you can use the following steps to assign users and groups to the application

    • Click the Users and groups tab. Then click Add user button

    • On the Add assignment screen, choose Users and groups tab, then select users and groups from the list. Then click the Assign button

    Assignment to the application based on attributes of the user/group - option B

    If you choose to scope who will be provisioned based solely on attributes of the user or group, you can use a scoping filter as described here (https://docs.microsoft.com/en-us/azure/active-directory/app-provisioning/define-conditional-rules-for-provisioning-user-accounts) (option B).

  10. Select the Scope option in the Provisioning Settings section

    - (recommended) Select Sync only assigned users and groups to only sync users and groups assigned in the Users and groups tab. But if you use attribute-based scoping filter (option B), you can select the Sync all users and groups option

    Be careful with the “Sync all users and groups” option. If the attribute-based scoping filter is not configured correctly, it can synchronize all of your Directory users including your service accounts.
    Assign the same users and groups as for the SSO application. If some users are assigned to the SCIM application but aren’t assigned to the SSO application, they won’t be able to log in.

    - (Optional) In the Notification Email field, enter the email address of a person or group who should receive the provisioning error notifications and select the Send an email notification when a failure occurs check box.

  11.  Open the Mappings panel and select Provision Microsoft Entra ID Users:


    Here you need to adjust the below 3 attribute settings by pressing the edit button:

    1. Look for the userPrincipalName row and change the Matching precedence option to 3:
    2. Look for the externalId row and press on edit.

      While editing the attribute set the source attribute to objectId.
      Change Match objects using this attribute option to Yes and set the matching precedence to 1
      as shown in the screenshot below:

      Save the settings afterward.

    3. Click the mail row. Change Match objects using this attribute option to Yes. The Matching precedence  to 2:
    4. Leave all the other fields unchanged. The result should look like this:
    5. (recommended) If you don’t want to synchronize Azure Directory Groups with Wizer departments you can turn off Provision Azure Active Directory Groups

      Click on Azure Directory Groups

      Turn off the Enabled option. Then click Save. This way Azure AD Groups won’t be created as Wizer Departments.

       
      For now, the Wizer application synchronizes only first name, last name, email, and department fields. But we plan to add support for other fields later, so it’s better to leave all the other attributes unchanged.

      Please note, per above the UPN (user principal name) synced only in case the mail field is empty. If the mail field is empty, upn will be synced as email in Wizer instead of the mail field
      If you don’t want to synchronize user departments with Wizer departments you can turn it off by deleting the “department” field from mapping.
  12. Click Save

  13. Turn on Provisioning by selecting the On option in Provisioning Status Row and click Save

  14. Provisioning should start immediately, but it might take some time before you start seeing users and groups in Wizer. The first initial sync might take a while depending on your directory size. Synchronization occurs every 40 minutes.

    Alternatively, you can press on the start provisioning option, once the process runs you will see the configuration status as enabled:

  15. If you experience any issues with provisioning - a user or group (department in Wizer) not showing up in Wizer, it's important to check the "Provisioning Logs" section for errors. If the sync process encounters an error it will stop and the user/group provisioning will not be successful.

    After the possible errors have been addressed, the provision should happen automatically in the next few hours, or you can restart the full synchronization manually by clicking Restart Provisioning.

Frequently Asked Questions & Answers

If an admin starts provisioning users via SCIM, what happens to the existing ones that are already enrolled (the emails and names are the same for both accounts)? Do they sync? 
Users' props will be updated if they differ (last name, name, department. If it's the same, nothing will be changed.
What happens to the users who already exist on the Wizer side, but do not exist in the provisioning?
Active users remain active without changes. Disabled users remain disabled.
How will it work when an existing user will be added to the new provisioning group?
If AD groups are synced as Wizer departments, user department assignments will be changed on the Wizer side (Will it be moved to a new group/department).
If AD groups are synced as Wizer groups, user group assignments will be changed on the Wizer side (Will it be moved to a new group/department).
if AD groups are not synced with Wizer - nothing will change.
Will two accounts sync or will they be separate accounts?
If emails are the same, accounts will be synced (merged).
What if the users are enabled on the Azure side, and disabled on the Wizer side?
Please follow these recommendations. Could you please test these users using on-demand provisioning? It should show the actual status of the users.
Additionally, please press this button and check if the users are re-enabled.


If that doesn't help, please send us a Support Ticket at support@wizer-training.com, and we will go through the logs and manually enable the users for your account.
Azure groups create Wizer departments. How can Wizer groups be created with Azure provisioning?
Currently, Wizer groups can be created only manually, except the automatically created 'Phished Users" group (article How to Create and Manage Groups. Dynamic group "Phished Users")

What if you do not have an option of adding groups in automatic provisioning?

Since the AD plan on your end does not allow this option you can either:
1. Assign all users to the user sync application.
Just so you know, this option will sync every assigned user, including the service accounts if there are any on your end.
2. You can use the attribute-scope filtering.
Kindly note that those filters are purely Azure's functionality, in case you have additional questions about those filters' functions or setup processes we can only suggest reaching out to Azure's support directly.
Is it possible to bulk-edit groups for all our existing users by uploading a CSV? Unfortunately, Wizer currently does not support bulk editing groups via CSV.

If you want to manage groups on the SSO side, you can sync your Microsoft Entra (Azure AD) groups with Wizer Groups. This allows group management on the SSO side, and Wizer will reflect those changes automatically.

If you prefer to manage groups only within Wizer, changes will need to be made manually. We support bulk operations to assign multiple users to a group, but these must be done through the Wizer Admin Panel UI; CSV uploads are not supported.

Can a deleted user be added again to the users list on Wizer's side if they are added to the provisional group and Azure auto-provisioning sync is active?
The user will be added later during a new sync cycle - maybe not immediately, but after some changes to the user's profile. We can suggest two options:
  1. Create a new group with the same members, excluding those 4–5 users (recommended).
  2. Configure a user scope filter - this can help exclude specific users based on certain fields. However, this option requires more advanced Entra knowledge and might be harder to implement. Please check the article Microsoft Docs – Define conditional rules for provisioning user accounts.

 

Any questions? Please contact our support specialists at support@wizer-training.com 

Best regards,

wizer_logo_dark