Overview
This is not for initial setup of SCIM-based Directory Sync (see Configure Directory Sync for all vendors for initial setup). Use this procedure only when a previously operational SCIM Sync with Microsoft Entra ID stops working because the Enterprise application was deleted in Azure.
Before starting, get the following from the F5 SurePath AI technical support team:
Tenant URL
Bearer Token
Create Entra ID SCIM Application
Log in to the Azure portal.
From the Enterprise Application dashboard, select "New Application".
Select "Create your own application" and continue.
Give the application a descriptive name such as SurePath AI - SCIM, select the "Integrate any other application you don't find in the gallery (Non-gallery)" option, then click "Create".
Configure the Entra ID SCIM Admin Credentials
Select "Provisioning" from the "Manage" section in the navigation menu of the SCIM application.
Click the "Get Started" button.
Select the "Automatic" Provisioning Mode from the dropdown menu.
Copy and paste the endpoint into the "Tenant URL" field.
Provided by SurePath AI support
Copy and paste the Bearer Token into the Secret Token field.
Provided by SurePath AI support
Setup and enable attribute mapping
Expand the "Mappings" section.
Verify that the group and user attribute mappings are enabled and mapping the correct fields. The default mapping works for most setups, but some Azure configurations require a custom mapping.
Verify that "objectId" is mapped to "externalId" within the Attribute Mapping section.
Ensure the emails[type eq "work"].value SCIM attribute receives a valid email value. For cloud-managed users, confirm that a known email attribute, such as UPN, is pulled from the mail attribute in Exchange. If the directory has synchronized users, verify that the userPrincipalName attribute is mapped to emails[type eq "work"].value.
Assign People & Groups to Entra ID SCIM Application
Add the previous users and groups to sync to SurePath AI. This information is available from the SurePath AI admin if needed.
Select "Users and groups" from the "Manage" section of the navigation menu.
Select "Add user/group" from the top menu.
Select "None selected" under "Users and Groups". In the menu, select the users and groups to add to the SCIM application, and click "Select".
Select "Assign" to add the selected users and groups to the SCIM application.
Confirm the "Provisioning Status" is set to "On" and that the "Scope" is set to "Sync only assigned users and groups".
Save the configuration when done.
Verify expected operations
Select "Provisioning" from the "Manage" menu.
Review the "Completed" time. This takes a few minutes.
The SurePath AI support team can also confirm on request that internal systems are receiving data again.
