> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.getunleash.io/provisioning/how-to-setup-provisioning-with-entra/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.getunleash.io/_mcp/server. # Set up Entra provisioning > Learn how to configure SCIM provisioning for Unleash using Microsoft Entra ID to automatically manage user accounts and access. v6.1 Enterprise ## Unleash Configuration > **Info** > > Before you begin, ensure that you have a strategy in place to prevent being [locked out of all admin accounts](/support/troubleshooting#got-locked-out-of-an-admin-account-after-configuring-scim). ### Step 1: Navigate to Provisioning configuration First you'll need to log in to Unleash as an admin user. Navigate to the Single Sign-On section and select the "SCIM" tab. The SCIM API URL will be shown in this section, you'll need this to configure Entra later. ![Navigate to the SCIM Config](/_fern-img/350dbf92c4e4a1649a6202d22fd34f57d7978a8caa55268cdaf134b1074fad66.webp) ### Step 2: Enable Provisioning Enable SCIM by turning on the toggle and keep the token Unleash provides you for the Entra setup below. ![Enable the SCIM toggle](/_fern-img/822b2545b78eba3ebb85ae994508b427e0523a8f1f0576e8770d2aa2f45c912b.webp) ## Entra Configuration ### Step 1: Navigate to Provisioning in Entra > **Info** > > This guide assumes you already have an SSO application setup for Unleash. If you don't already have an application configured, please see our [guide](/single-sign-on/how-to-add-sso-azure-saml) on setting up SSO. **1) Navigate to "Enterprise Applications"** ![Navigate to Enterprise Applications](/_fern-img/08acf1ff44f6d0da0d5360767dfd434adfb08488c7a1cbc1b6ed1a92514122bd.webp) **2) Navigate to your SSO Application** ![Select your Application](/_fern-img/633ba4ae94fecf9384857a1cda13f0ffb4c42b567506538594f717a87c714301.webp) **3) Navigate to provisioning** ![Navigate to the provisioning overview menu item](/_fern-img/822935a92bf9e425745655e92a89ae0e7ef747816f756e462b833601b1361a2d.webp) ### Step 2: Connect Unleash to your Entra Application **1) Navigate to the Provisioning overview** **2) Set the Tenant URL** This the SCIM API URL provided by the Unleash UI in the [configuring Unleash](how-to-setup-provisioning-with-entra#step-1-navigate-to-provisioning-configuration) section.\*\* If you plan on deprovisioning users at any point with SCIM, you'll also need to enable the [SCIM compliance flag](https://learn.microsoft.com/en-us/entra/identity/app-provisioning/application-provisioning-config-problem-scim-compatibility#flags-to-alter-the-scim-behavior) on Entra. This can be done by appending `?aadOptscim062020` to your URL. **3) Set the Secret Token** This was provided by the Unleash UI in the [configuring Unleash](how-to-setup-provisioning-with-entra#step-2-enable-provisioning) section. **4) Save** ![Setting up SCIM credentials](/_fern-img/6441d39a1ea22964ea06c44b9c16194154fbfa2d08692182f69b8956d08e22fc.webp) ### Step 3: Configure Provisioning **1) Expand the mappings tab** **2) Navigate to "Provision Microsoft Entra ID Users"** ![Navigate to user provisioning setup](/_fern-img/2f7ea8771d86a39590f446829a4b07303f8826cff0d0cd816f793912041e5c1d.webp) This was provided by the Unleash UI in the [configuring Unleash](how-to-setup-provisioning-with-entra#step-2-enable-provisioning) section. ![Connect Unleash](/_fern-img/2f7ea8771d86a39590f446829a4b07303f8826cff0d0cd816f793912041e5c1d.webp) **3) Remove unneeded properties** You should remove all unnecessary properties. This ensures that Entra will reach a steady state when synchronizing. The properties that you must retain are: * userName * displayName * emails * externalId **4) Update the email property to "userPrincipleName"** ![Update provisioning properties](/_fern-img/2e07003ee9ba455b37b638ce061258a42d8f8fbfe6bcdb54598897aa2fcf17ba.webp) **5) Save** ### Step 4: Enable Provisioning **1) Enable provisioning** ![Enable provisioning](/_fern-img/d6109f22a9ceb2aa2e5fd07dd9e7ba10a59dfd31b36dcfb09fe402ae65a3206e.webp) **2) Enable automatic provisioning** ![Enable provisioning](/_fern-img/ab3e7601943738b6e12e026ff33130bbe0e4412146503c1dcd11038793a37137.webp) > Learn how to configure SCIM provisioning for Unleash using Microsoft Entra ID to automatically manage user accounts and access.