azureblog.co.uk
← cd ~/posts

SCIM provisioning when every target is its own app

Some SaaS platforms need a separate Enterprise App for each instance or library. A few habits keep that manageable.

2 min read⚠ checked 19 Nov 2025Entra ID
On this page
  1. Habits that help
  2. How a provisioning cycle works
  3. Troubleshooting checklist
  4. A useful expression

Entra's provisioning works per Enterprise Application. When a vendor splits their platform into several instances or libraries, each one gets its own app, its own token, its own attribute mappings and its own provisioning cycle. With three or four of those, small differences creep in fast.

Entra IDSCIM provisioningApp: Library AApp: Library BApp: Library CApp: Region 2
One Entra tenant provisioning into several targets, each through its own Enterprise App.

Habits that help

  • Name apps consistently. A pattern like Vendor - Library - Region makes the list sortable and obvious to the next engineer.
  • Assign groups, not users. One security group per app keeps scope visible and auditable.
  • Document the mappings once. Keep a single table of source attribute, target attribute and any expression, then check each app against it.
  • Use Provision on demand to test a single user before you start the full cycle.
  • Watch the provisioning logs, not just the app status. A cycle can report success while quietly skipping users with a missing attribute.

How a provisioning cycle works

Entra provisioningEntra directoryTarget app (SCIM)Reads users and groups inscope1Applies attribute mappings andexpressionsGET /Users?filter=… (does the user exist?)3POST or PATCH /Users4Response; errors go to provisioning logs5
What happens in each cycle.

The first cycle processes everyone in scope and can take a while. Later cycles only process changes, so they're much quicker. If you change attribute mappings, Entra may need another full cycle.

Troubleshooting checklist

  • User not created: check they're assigned to the app (directly or via a group) and that the scope is set to assigned users only.
  • "Skipped" in the logs: usually a scoping filter or a missing required attribute.
  • Duplicates in the target: the matching attribute differs between Entra and the app. Fix the matching rule before re-running.
  • Authentication errors: the secret token or tenant URL is wrong or has expired. Test the connection on the Provisioning blade.

A useful expression

Many targets want a username without the domain. This mapping takes the part of the UPN before the @:

text
Replace([userPrincipalName], , "(?<user>[^@]+)@.*", "user", "${user}", , )
Before you go live: agree with the vendor what happens on deprovisioning. "Disable" and "delete" mean very different things when a user owns content in the target system.

Use Provision on demand for one user whenever you change a mapping. It shows each step of the cycle for that user, which is far quicker than waiting for the next scheduled run.

This post was last checked against Microsoft's documentation over six months ago. The approach should still hold, but check the linked sources for anything that has changed before you act on it.