SCIM Setup for Microsoft Entra ID (Formerly Azure AD)

In this article:


 

Organizations using Microsoft Entra ID (formerly known as Azure Active Directory) can set up the System for Cross-domain Identity Management (SCIM) for user management in Keycafe.

Business Pro Feature

Microsoft Entra ID for Keycafe is only available to users on the Business Pro plan.

Generate a SCIM Token


Note

Generating a SCIM token can only be done by the Organization owner on desktop.

  1. On desktop, select SettingsIdentity Provisioning.
  2. Click Generate new SCIM token, and copy the token. Note that if you exit this page, the token will not be displayed again.
Screenshot 2026-02-18 at 1.55.10 PM.jpg

 

Entra ID Provisioning Setup


  1. Log in to the Microsoft Entra portal.

  2. From the Home screen, navigate to Entra IDManageEnterprise AppsNew Registration.

  3. Set a name for the registration, and the Supported Account Type to Single Tenant (this should be the default setting). Leave the redirect URI blank.

  4. In your new app, navigate to ManageProvisioningConfigure automatic provisioning (in the bottom right).

  5. Paste your Keycafe SCIM Tenant URL in the Tenant URL field, and the Keycafe SCIM token in the Secret Token field.

  6. Click Test Connection to confirm the Tenant URL and SCIM token are correct.

 

Set Up Attribute Mapping


Coming Soon

Support for mapping user roles and key access permissions is coming soon.

  1. Navigate to Provisioning → Manage → Attribute Mapping → Provision Microsoft Entra ID Users.
Screenshot 2026-02-20 at 10.26.30 AM.jpg
  1. Click Add New Mapping at the bottom of the page.
Screenshot 2026-02-20 at 10.27.25 AM.jpg

 

User Type

Default Value

If User Type is not specified, users will default to being created as Full Users.

  1. Set an appropriate Mapping Type. In this example we will use Constant, but you can read more about Mapping Types in Microsoft's Help Centre.
  2. Set the Constant Value as either FULL or SMARTBOX. This will dictate whether users provisioned from Entra ID will be Full Users or SmartBox Users.
  3. Set Target attribute to userType.
Screenshot 2026-02-20 at 10.30.45 AM.png
  1. Click OK to complete.
Was this article helpful?
0 out of 0 found this helpful