Tenant Administration
Users - Single Sign on
Microsoft Entra
-
Add Nodefusion Account to Microsoft Entra Enterprise Applications - this can be done in a way that administrator from your Tenant Registers on Nodefusion Account - prompt should pop up
-
Configure scope to users which you want to be able to access by defining Users and Groups in the Nodefusion Account Enterprise Application
Users - SCIM Provisioning
Enable SCIM User Provisioning in Nodefusion Account
- Have a permission role for Tenant Admin on Nodefusion Account
- Go to Nodefusion Account, and choose manage your Tenant link
- In the left menu, navigate to SCIM and click Create New
- Choose your login provider (Microsoft) and enter your internal notes about scim config if needed
- Click Create and copy your Generated APIKey
- Then go back to list to confirm your key is on the list
Configure Microsoft Entra - SCIM Provisioning
- Go to Microsoft Entra, Enterprise Applications, choose + New Application on the ribbon
- Then from 'Browse Microsoft Entra Gallery' choose + Create your own application on the ribbon
- Enter Nodefusion Account SCIM and choose: Integrate any other application you don't find in the gallery (Non-gallery)
- Open Nodefusion Account SCIM - and then Provisioning - then again Provisioning
- Set Provisioning Mode to Automatic
- For Tenant URL enter: https://login.nodefusion.com/scim/v2
- Paste your previously generated APIKey under Secret Token
- Click Test Connection and then if successful, Click Save in the ribbon
- Then after saving url and secret, under Mappings you should
- Disable provisioning of Entra ID Groups
- Edit User mappings; externalId as matching attribute:
You should edit externalId mapping to map objectId source attribute and to be set as matching attribute. Mappings other than this five from picture should be deleted
After configuring mappings you can check if provisioning works by using provision on demand functionality on Microsoft Entra. After that you can proceed to configure which part of your directory will be synced to Nodefusion Account, how often and so on.