Scim Validator Tutorial
The tutorial now explains that the Microsoft Entra SCIM Validator is for endpoint testing, while App Gallery publishing requires running the Azure Logic Apps validation template and submitting its results.
Daily.Entra.NewsA cross-product view of Microsoft Entra changes related to Standards.
The tutorial now explains that the Microsoft Entra SCIM Validator is for endpoint testing, while App Gallery publishing requires running the Azure Logic Apps validation template and submitting its results.
A new guide explains how ISVs create an Entra Gallery Provisioning Test App, deploy the Azure Logic Apps validation template, configure permissions and parameters, and run SCIM provisioning tests.
The page author changed from hsaini to himanshusainig.
The article explains how to inspect failed Azure Logic Apps validation runs, identify root causes, and resolve common SCIM endpoint, authentication, permissions, filtering, and conflict errors.
The document’s author metadata changed from hsaini to himanshusainig.
The documentation replaces its embedded onboarding checklist with links to current requirements and validation instructions. App publishers validate their SCIM integration and submit the results with their gallery application; customers obtain OAuth configuration values from the app’s admin experience.
The SCIM provisioning documentation now links to guidance for the OAuth 2.0 client credentials grant.
A new article explains how to validate SCIM user and group provisioning with an Azure Logic Apps template, run 25 tests, and submit the results with a Logic App run ID for App Gallery review. It covers both AI-agent and Azure portal setup methods.
The page author changed from `hsaini` to `himanshusainig`.
The SCIM API reference now states that mailNickname may be omitted, null, or empty when creating a user. Microsoft Entra ID derives it from the characters before the first @ in userName. After creation, it cannot be removed with PATCH.
The breaking-changes documentation now uses a different client application ID in its OAuth authorization URL and description.
The breaking-changes documentation updates the sample OAuth authorization request and its description with a different client application ID.
The documentation now states that standard users can create groups by default regardless of SSGM, and that SSGM controls behavior only in the My Groups portal. The MSODS reference was removed.
The guide title now uses quoted punctuation, and the table separator spacing was standardized.
Microsoft added a page detailing SAML 2.0 and multitenant OpenID Connect requirements for validating and publishing applications in the Entra App Gallery, with links to general prerequisites and provisioning requirements.
The new page lists SCIM API, authentication, testing, support, documentation, customer deployment, and cloud compliance requirements for publishing user provisioning integrations in Microsoft Entra App Gallery.
A tutorial now explains how to use the Microsoft Entra App Validator browser extension with non-gallery enterprise applications, including IdP- and SP-initiated SSO, certificate scenarios, optional Single Logout, and result submission.
The documentation explains how to use the Microsoft Entra App Validator browser extension to test an OIDC multitenant app, review fixes, and generate the Test ID required for gallery publishing.
The page title changed from “What is single sign-on (SSO) in Microsoft Entra ID?” to “What is single sign-on in Microsoft Entra ID?”
The example request now uses client ID `ffffffff-eeee-dddd-cccc-bbbbbbbbbbb0` instead of `00001111-aaaa-2222-bbbb-3333cccc4444`.
The documentation now labels synced passkeys as phishing-resistant MFA and clarifies that this designation for certificate-based authentication applies to multi-factor CBA. The associated SAML mappings are unchanged.
The documentation now describes clearing mapped target attributes when inbound provisioning payloads contain null or empty values. It also recommends complete user records for full and delta sync when this preview capability is enabled.
The documentation now explicitly states that child agent identities, like their parent blueprints, cannot initiate interactive `/authorize` flows. Interactive consent attempts return `AADSTS82014`; required delegated permissions must be preauthorized instead.
The documentation now explains that Tc must target the agent identity blueprint, while T1 targets the token-exchange resource and is validated as bound to the blueprint and child agent identity. It also states that agent identities cannot use interactive consent and must have delegated permissions preauthorized through inheritable blueprint permissions.
The tutorial replaces the Orgvue authentication and SAML callback URLs with orgvue-staging URLs and changes the Sign-on URL to include the application login path and domain parameter. It also clarifies that both Reply URL and Sign-on URL values are placeholders.
- To implement support of SCIM 2.0 Provisioning follow this tutorial: [build a SCIM endpoint and configure user provisioning with Microsoft Entra ID](~/identity/app-provisioning/use-scim-to-provision-users-and-groups.md)
Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Azure Databricks using SCIM.
`https://<FortiGate IP or FQDN address>:<Custom SSL VPN port>/remote/saml/login`.
Specifies whether this web app can request OAuth2.0 implicit flow ID tokens. The default is false. This flag is used for browser-based apps, like JavaScript single-page apps. We, however, discourage the use of implicit grant even in SPAs and recommend using the [authorization code flow](./v2-oauth2-auth-code-flow.md) with PKCE.
Before you can call the SCIM API endpoints described in this article, you must enable the SCIM Provisioning API feature, configure billing, set up credentials, and obtain an access token. For step-by-step instructions, see [Enable the SCIM Provisioning API in Microsoft Entra ID](enable-scim-api.md).
Map each Microsoft identity platform OpenID Connect (OIDC) extensibility surface to the configuration article and the Microsoft Graph API resource that programs it.
Sign in Microsoft Entra users by using the Microsoft identity platform's implementation of the OpenID Connect extension to OAuth 2.0.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Adobe Identity Management (SAML).
Learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Insightly SAML.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Lexmark Cloud Services (SAML).
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Palo Alto Networks SCIM Connector.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to TimeClock 365 SAML.
Set up direct federation with SAML 2.0 or WS-Fed identity providers so users can sign in with work accounts. Understand attributes and claims for federation.
Learn how to automatically provision and de-provision user accounts from Microsoft Entra ID to Klaxoon SAML.
Compare SAML 2.0 and OpenID Connect (OIDC) protocols to choose the right approach for your application's SSO integration with Microsoft Entra ID.
Learn how Microsoft Entra ID implements single sign-on (SSO) as a centralized identity platform for both SAML and OpenID Connect protocols.
Learn about single sign-on for enterprise applications in Microsoft Entra ID, including SAML and OpenID Connect protocols.
Learn how to migrate AI agents from standard Microsoft Entra app registrations to Agent ID for agent-specific governance and security.
This article describes the Single Sign-Out SAML Protocol in Microsoft Entra ID
Learn how to configure token lifetimes for access, SAML, and ID tokens in Microsoft Identity Platform to enhance security.
Learn how to configure inheritable permissions for agent identity blueprints to automatically grant OAuth 2.0 delegated permission scopes and application roles to agent identities.
A Microsoft Entra documentation page was updated: Configure Insightly SAML for Single sign-on with Microsoft Entra ID.
Learn how to configure OpenID Connect-based single sign-on (SSO) in Microsoft Entra ID for both gallery applications and your own custom (non-gallery) applications.
Learn how to configure the role claim issued in the SAML token for enterprise applications in Microsoft Entra ID.
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Adobe Identity Management (SAML) so that I can streamline the user management process and ensure that users have the appropriate access to Adobe Identity Management (SAML)..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Insightly SAML so that I can streamline the user management process and ensure that users have the appropriate access to Insightly SAML..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Klaxoon SAML so that I can streamline the user management process and ensure that users have the appropriate access to Klaxoon SAML..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Lexmark Cloud Services (SAML) so that I can streamline the user management process and ensure that users have the appropriate access to Lexmark Cloud Services (SAML)..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Palo Alto Networks SCIM Connector so that I can streamline the user management process and ensure that users have the appropriate access to Palo Alto Networks SCIM Connector..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Templafy OpenID Connect so that I can streamline the user management process and ensure that users have the appropriate access to Templafy OpenID Connect..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Templafy SAML2 so that I can streamline the user management process and ensure that users have the appropriate access to Templafy SAML2..
A Microsoft Entra documentation page was updated: Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Timeclock 365 SAML so that I can streamline the user management process and ensure that users have the appropriate access to Timeclock 365 SAML..
In this article, you learn how to integrate HubSpot with Microsoft Entra ID. When you integrate HubSpot with Microsoft Entra ID, you can:
In this article, you learn how to integrate Insignia SAML SSO with Microsoft Entra ID. When you integrate Insignia SAML SSO with Microsoft Entra ID, you can:
In this article, you learn how to integrate ON24 Virtual Environment SAML Connection with Microsoft Entra ID. When you integrate ON24 Virtual Environment SAML Connection with Microsoft Entra ID, you can:
This article focuses on applications in the application gallery that implement OpenID Connect. For more information on enabling OpenID Connect for other applications, including in-house developed applications, see [OpenID Connect on the Microsoft identity platform](~/identity-platform/v2-protocols-oidc.md) and [Configure OIDC SSO for custom (non-gallery) applications](~/identity/enterprise-apps/add-application-portal-setup-oidc-sso.md?#configure-oidc-sso-for-custom-non-gallery-applications).
In this article, you learn how to integrate SAML 1.1 Token enabled LOB App with Microsoft Entra ID. When you integrate SAML 1.1 Token enabled LOB App with Microsoft Entra ID, you can:
In this article, you learn how to integrate SAML SSO for Bamboo by resolution GmbH with Microsoft Entra ID. When you integrate SAML SSO for Bamboo by resolution GmbH with Microsoft Entra ID, you can:
In this article, you learn how to integrate SAML SSO for Bitbucket by resolution GmbH with Microsoft Entra ID. When you integrate SAML SSO for Bitbucket by resolution GmbH with Microsoft Entra ID, you can:
In this article, you learn how to integrate SAML SSO for Confluence by resolution GmbH with Microsoft Entra ID. When you integrate SAML SSO for Confluence by resolution GmbH with Microsoft Entra ID, you can:
In this article, you learn how to integrate SAML SSO for Jira by resolution GmbH with Microsoft Entra ID. When you integrate SAML SSO for Jira by resolution GmbH with Microsoft Entra ID, you can:
Learn how to customize the claims issued by Microsoft identity platform in the SAML token for enterprise applications.
Debug SAML-based single sign-on to applications in Microsoft Entra ID.
Set up direct federation with SAML 2.0 or WS-Fed identity providers so users can sign in with work accounts. Understand attributes and claims for federation.
Learn how to disable the SCIM Provisioning API feature in the Microsoft Entra admin center to stop all API access and billing.
Learn how to enable the SCIM Provisioning API feature in the Microsoft Entra admin center and link an Azure subscription for billing.
Learn how to configure a Microsoft Entra ID tenant as an OpenID Connect identity provider in Microsoft Entra External ID, enabling users to sign in using their existing organizational accounts.
Learn how to fetch data from Microsoft Graph without prompting an AD FS-federated user for credentials by using the SAML bearer assertion flow.
This article provides an overview of the single sign-on and Single Sign-Out SAML profiles in Microsoft Entra ID.
Build custom integrations to provision users and groups to Microsoft Entra ID using the System for Cross-domain Identity Management (SCIM) v2.0 protocol.
This article provides a reference for SCIM schema attributes, including core user and group attributes, enterprise extensions, and Microsoft Entra-specific extensions, along with their mappings to Microsoft Entra ID properties.
Protocol reference for the Microsoft identity platform's implementation of the OAuth 2.0 authorization code grant
Secure single-page apps using Microsoft identity platform implicit flow.
Learn about common token exchange scenarios when working with SAML and OIDC/OAuth in Microsoft Entra ID.
Learn how to migrate AI agents from standard Microsoft Entra app registrations to Agent ID for agent-specific governance and security.
Migrate users, credentials, and applications from Azure AD B2C to Microsoft Entra External ID using the standard migration approach.
Sign in Microsoft Entra users by using the Microsoft identity platform's implementation of the OpenID Connect extension to OAuth 2.0.
Choose between the standard migration approach and High Scale Compatibility (HSC) mode when moving from Azure AD B2C to Microsoft Entra External ID.
Claims reference with details on the claims included in SAML 2.0 tokens issued by the Microsoft identity platform, including their JWT equivalents.
Learn about openID connect scopes and permissions in the Microsoft identity platform endpoint.
This article describes the single sign-on (SSO) SAML protocol in Microsoft Entra ID.
Troubleshoot issues with a Microsoft Entra app configured for SAML-based single sign-on.
Learn how to enforce secret and certificate standards using application management policies in Microsoft Entra ID.
`https://login.microsoftonline.com/contoso.com/oauth2/authorize?resource=https://gateway.contoso.com/api&response_type=token&client_id=00001111-aaaa-2222-bbbb-3333cccc4444&...`
Learn how to configure the standard OpenID Connect claims with the claims your identity provider provides in your external tenant.