Admin Effort: ~5 minutes
System Sync Time: Varies (Entra handles the user resynchronization in the background; completion depends on directory size and the next automated cycle).
Managing your SCIM integration? Here’s how to safely replace your SCIM token in both the NINJIO platform and your Azure Enterprise Application. Follow these steps to keep your user provisioning secure and working smoothly.
How-to Video:
Step-by-step Instructions:
Obtain New Secret Token in NINJIO Platform
- Step 1: Log into NINJIO Platform
- Step 2: Locate the Settings button in the top right corner.
- Step 3: Click the Sync drop-down and select SCIM.
- Step 4: Within the SCIM Integration page, locate your active SCIM integration and click the Edit (Pencil) button.
- Step 5: In the SCIM Integration Settings, select Apply on the bottom right corner.
- Step 6: On the next page, locate your Secret Token, copy it and store it securely and then hit the Finish button.
Pause provisioning in Microsoft Entra ID
Step 7: Sign in to Microsoft Entra ID using an administrator account.
- Step 8: Open the Enterprise Application to locate your NINJIO SCIM Application.
- Step 9: Select Provisioning.
- Step 10: Select Pause provisioning, and keep provisioning paused while you complete the remaining steps.
Update the SCIM token in Microsoft Entra ID
- Step 11: Go to Provisioning->Mappings and expand the drop-down do the following:
- Make sure Provision Microsoft Entra ID Groups is set to "No"
- Make sure Provision Microsoft Entra ID Users is set to "Yes"
- Step 12: Select the Provision Microsoft Entra ID Users button and under Attribute Mappings, locate the customappsso Attribute->userName->userPrincipalName->Matching precendence and click the Edit button.
- Step 13: In the Edit Attribute configuration, select the Source attribute drop-down, and replace userPrincipalName with objectid and hit OK
- Step 14: Back to the Attribute Mapping configuration, select the Save button.
- Step 15: Go to Provisioning-> Admin Credentials and open the provisioning configuration.
- Step 16: Locate the Secret Token field and replace the existing Secret Token with the newly generated SCIM token.
- Step 17: Test the connection and then Save the configuration.
Preparing your Active Launch Group - Unassigning All Users from your Group in NINJIO Platform
- Step 18: Go back to the NINJIO Platform -> User Management-> Users & Groups
- Step 19: Locate your Active SCIM Group via the Groups dropdown
- Step 20: Once your group is filtered, click the select all check box, confirm the Select all # of users matching this filter, and hit the Unassign button and confirm the action.
Resuming Your Provisioning in Your Enterprise App
- Step 21: Go back to your Enterprise App, click Overview and select Restart provisioning.
Confirm provisioning is working as expected
After provisioning restarts, complete the following checks:
- Step 22: Confirm that no authentication errors are displayed.
- Step 23: Run Provision on Demand for a test user to confirm the connection.
- Step 24: Verify that users are syncing as expected in platform.
- Step 25: Review the provisioning logs for any failed attempts.
Troubleshooting
- If provisioning does not start successfully, confirm that the new SCIM token was copied exactly, without any added spaces or missing characters.
- If authentication errors continue, stop provisioning, re-enter the token, save the configuration, and restart provisioning.
- If users are not syncing, confirm that the correct users or groups are assigned to the NINJIO Enterprise Application.
- If you continue to experience issues, please contact NINJIO Support and include any relevant provisioning error messages or log details.
If you need further assistance, please contact NINJIO Support. We’re happy to help and can schedule a call to resolve your request.
Comments
0 comments
Please sign in to leave a comment.