Enable provisioning using SCIM API for Microsoft Entra ID
Learn how to configure System for Cross-domain Identity Management (SCIM) 2.0 provisioning in Microsoft Entra ID to automatically manage Zuora users and groups through Zuora OneID.
-
You are an administrator in both Microsoft Entra ID and Zuora OneID.
-
Your custom SAML application is active and working for single sign-on (SSO). To set up the application, see Set up SSO with Microsoft Entra ID using SAML in OneID.
-
If your provisioning scope is restricted to assigned objects only, the required users or groups are assigned to the enterprise application.
-
Your custom SAML application has the required attributes configured for SCIM provisioning.
-
You have created an OAuth 2.0 client in Zuora OneID to generate the client identifier and client secret that Microsoft Entra ID uses to authenticate requests to the OneID SCIM API. For more information, see Manage OAuth 2.0 clients.
System for Cross-domain Identity Management (SCIM) 2.0 is a standard that enables Microsoft Entra ID to automatically manage your users and groups in Zuora. When you add or remove a user in Microsoft Entra ID, the change is applied in Zuora through the Zuora OneID service.
Although Zuora OneID is not listed as an official Microsoft Entra ID marketplace application, you can integrate SCIM provisioning by using the same custom SAML application that you created for SSO. After the application is configured for SSO, you can enable SCIM provisioning within the same application.
Microsoft Entra ID begins provisioning the assigned users and groups to Zuora OneID. The initial synchronization can take several minutes to complete, depending on the number of objects in scope.
Validate that Microsoft Entra ID provisions users and group memberships to Zuora correctly:
- To validate individual user creates, select Provision on demand and select a test user.
- Set Scope to Sync only assigned users and groups, and then assign a single test group. Limiting the scope reduces the size of the synchronization cycle, so results appear faster.
- Select Restart provisioning to start a fresh synchronization cycle.
- Review the results in Provisioning logs.
The ?aadOptscim062020 parameter does not apply to Provision on demand. Microsoft documents this limitation. On-demand requests are sent in the legacy format, so on-demand group membership updates fail against Zuora with a JSON parse error even when your configuration is correct. Validate group membership through a full synchronization cycle instead.
For more information, see Known issues and resolutions with SCIM 2.0 protocol compliance of the Microsoft Entra user provisioning service in the Microsoft Entra documentation.