Skip to main content

SCIM Provisioning Users [Azure AD]

Provision, update, and deactivate Blinq users and their cards automatically from Azure AD.

System for Cross-domain Identity Management (SCIM) is a protocol for user management across multiple applications. It allows an IT or Operations team to provision (add), deprovision (deactivate), and update user data across multiple applications at once.

To set up SCIM provisioning in Azure AD, you'll need both your Blinq organization admin and the manager of your Azure AD account involved.


What you can do

  • Provision one or more users and their Blinq cards

  • Deprovision users and their Blinq cards

  • Update user details, which can propagate to a Blinq card

Note: User provisioning works with any service that adheres to the SCIM protocol. To set up provisioning with a service other than Azure AD, contact [email protected].


Step 1: Create the Blinq application in Azure AD

  1. Navigate to portal.azure.com and log in.

  2. Search for Enterprise Applications.

  3. Select New Application.

  4. Search for Blinq.

  5. Select the first option.

  6. Select Create.


Step 2: Set up user provisioning

Navigate to your newly created Enterprise Application in Azure, then:

  1. Select Provisioning in the left panel.

  2. Select Get started.

  3. Set the Provisioning Mode to Automatic.

You'll see a Tenant URL field and a Secret Token field. Get those values from Blinq:

  1. Navigate to the dashboard in a separate browser tab.

  2. Log in to Blinq if you aren't already.

  3. Select your workspace in the top left of the screen.

  4. In the dropdown, select Settings.

  5. Under the Integrations page you'll see Team Card Provisioning, which contains a URL and Token. Generate the token by selecting Generate.

  6. Copy the URL and Token, navigate back to the Provisioning page in your Azure app, and paste them into the corresponding fields.

  7. Select Test Connection.

  8. After a few seconds you should see a success message confirming the credentials are authorized. Select Save.

Note: You can generate a new token at any time from this Integrations settings page by selecting Regenerate next to the token field. The Security tab of the settings page lists your active tokens and lets you delete one.


Step 3: Configure user provisioning in Azure

After saving, you'll see a Mappings and Settings section.

Optionally, to restrict what information is sent to Blinq:

  1. Select Provision Azure Active Directory Users.

  2. Select Delete on the Attribute Mapping you want to remove.

Finally, under Settings, set Provisioning Status to On to start provisioning, then select Save in the top left of the page.

Note: A sync occurs between Azure and Blinq every 40 minutes.


Step 4: Configure user provisioning in Blinq

When a user is provisioned in your Blinq workspace, by default:

  1. A user is created in your Blinq workspace.

  2. A card is automatically created for that user, containing any relevant details from their Azure AD profile. These card fields stay in sync with the values in their profile.

  3. An email is sent to the user so they can activate their account.

You can extend this with the Card Settings section in Blinq, found on the same page as the URL and Token. Card Settings lets you configure which Templates are applied to newly created cards, and whether an activation email is sent to new users automatically.

Configuring which Templates are applied

Templates are the best way to keep branding consistent across a team, department, or company. If a template contains your company logo and name, every card created from it contains them too. Edit the logo or name in the template and every card inheriting from it picks up the new value.

In Card Settings you can choose when a particular Template is applied to a new card. For example, you could add a Filter that applies Template A when a new user is in the Marketing department, or in the Sales department. If a newly provisioned user belongs to either, Template A is applied to their card.

Note: Template fields take precedence over fields from Azure. If their Azure AD profile says the company is Blinq and the applied Template says Blinq Inc., their card shows Blinq Inc.

Note: Templates are only applied to a newly provisioned user's card. After a user has been provisioned, you'll need to assign the Template to their card manually on the Blinq dashboard.

Configuring activation emails

With this toggle on, users get an email as soon as they're provisioned, letting them activate their account. With it off, no activation email is sent and you'll need to send activation emails manually from the Team Cards page in the Blinq dashboard.


Step 5: Provision your users

  1. Navigate back to the main page of your Azure application.

  2. Select Users and Groups on the left-hand side of the page.

  3. Select Add user/group.

  4. Select Users and groups.

  5. Select the users you'd like to provision.

  6. Select the Select button at the bottom of the selection section.

  7. Select the Assign button at the bottom left of the screen.

Note: Group provisioning isn't supported at this time.

Note: Deprovisioning can be done by removing the user from Azure, or removing them from the group you're syncing to SCIM via the Blinq Enterprise Users and Groups menu. A deprovisioned user remains in Blinq as an inactive user and isn't counted towards your Blinq user count.


Supported user attributes

A user's attributes come from their Azure AD User Profile. Blinq supports:

  • Name

  • First name

  • Last name

  • Job title

  • Department

  • Company name

  • Office phone

  • Mobile phone

  • Email

Note: Blinq supports syncing profile images via SCIM, but Azure AD doesn't expose them. Profile images need to be uploaded to each card by the card owner or the team admin.


Viewing a provisioned user in Blinq

To view a provisioned user's card, go to the Team Cards section in the Blinq dashboard, select the corresponding row, and select Edit.

By default, all card fields created when the user was provisioned are locked so they can't be overridden by the card owner, and linked so any changes to the user's Azure profile sync across.

If you edit a field value and save, that field is unlinked so your changes aren't overridden by later changes in the user's Azure profile. The same applies if you remove a lock to let the card owner edit a field.


FAQ

What happens if the admin who set up the initial SCIM token is no longer an admin, or their account was deactivated?
If the original admin who created the SCIM provisioning token was deactivated, SCIM stops working on your account. To reactivate it, the current workspace admin can generate a new token and enter it into the provisioning details of your Azure application.


Related guides

Using Okta instead? See SCIM Provisioning Users [Okta ID]. Setting up single sign-on as well? See Configuring Enforced SSO [Azure AD].


Need help?

Reach out via the chat widget in the Help Center or email [email protected].

Did this answer your question?