SCIM Provisioning¶
SCIM 2.0 lets your identity provider automatically create, update and deactivate BongoShield users (and groups) as people join, move and leave — no manual user management and no CSV imports. When someone is offboarded in your IdP, they're deactivated in BongoShield too.
You set this up yourself in Settings → SCIM: copy the base URL, generate a bearer token, and paste both into your IdP's provisioning connector. You must be a BongoShield Owner or Admin. SCIM works well alongside SSO — SSO handles sign-in, SCIM handles account lifecycle.
1. Get the connection details in BongoShield¶
- Go to Settings → SCIM.
-
Under Connection, copy the Tenant / base URL. It looks like:
https://<your-host>/scim/v2 -
Click Generate token. The bearer token is revealed in a dialog and is shown only once — copy it now and keep it safe. If you lose it, generate a new one.
You now have the two values every SCIM connector needs: the base (tenant) URL and the bearer/secret token.
Managing the token later
The SCIM tab shows whether a token is Configured, its prefix, and when it was last used. Use Regenerate token to replace it (your IdP will need the new value to keep provisioning) or Revoke to stop SCIM entirely.
2. Configure provisioning in Microsoft Entra ID¶
- In the Entra admin center, open Identity → Applications → Enterprise applications and select (or create) the app you use for BongoShield.
- Go to Provisioning → New configuration (or Get started), and set Provisioning Mode to Automatic.
- Under Admin Credentials:
- Tenant URL — paste the SCIM base URL from step 1
(
https://<your-host>/scim/v2). - Secret Token — paste the bearer token from step 1.
- Tenant URL — paste the SCIM base URL from step 1
(
- Click Test Connection. Entra confirms it can reach BongoShield and authenticate.
- Save.
- Under Mappings, review the Provision Azure Active Directory Users mapping — ensure the user's email / userPrincipalName, display name, and active status are mapped. These are what BongoShield matches on.
- Under Settings, set Scope (e.g. Sync only assigned users and groups), then set Provisioning Status to On and Save.
- Assign the users/groups to the enterprise app (Users and groups) so they fall into scope, then use Provision on demand to test a single user before the first full cycle.
The same pattern applies to Okta and other SCIM 2.0 IdPs: create a provisioning integration, set the SCIM connector base URL to the base URL, use HTTP Header / OAuth Bearer Token authentication with the generated token, and enable create/update/deactivate.
Joiner / mover / leaver behaviour¶
| Event in your IdP | What BongoShield does |
|---|---|
| Joiner — user assigned/created | Creates the BongoShield user (matched by email), subject to your seat limit. New users start with the user role. |
| Mover — profile changes | Updates name and attributes on the matching user. |
Leaver — deprovisioned / active=false |
Deactivates the BongoShield user so they can no longer sign in. |
| Groups | Groups are created/updated over SCIM; IdP group membership never grants a BongoShield role — promote people on the Users page. |
Provisioning is subject to your licence seat cap — see Licensing & Seats.
Tenant isolation¶
The bearer token is per-organization and scoped to your tenant only. Everything created or updated through your SCIM base URL belongs to your organization and can never touch another tenant's data. Treat the token like a password: anyone who holds it can manage your users over SCIM, so revoke and regenerate it if it may have leaked.
Troubleshooting¶
| Symptom | Likely cause | Fix |
|---|---|---|
| Test Connection fails with 401 / unauthorized | Wrong or revoked bearer token | Regenerate the token in Settings → SCIM and paste the new value into the IdP. |
| Test Connection fails to reach the URL | Wrong base URL, or a trailing typo | Copy the Tenant / base URL exactly — it ends in /scim/v2 with no trailing slash. |
| Users aren't being created | They're not in scope, or you're at your seat cap | Assign the users/groups to the enterprise app; check remaining seats on the Licence tab. |
| Users are created but not deactivated on offboarding | The active attribute isn't mapped, or scope excludes them | In the IdP mappings, ensure active is mapped; confirm deprovisioning is enabled in the IdP. |
| A user is duplicated | Their IdP email doesn't match the existing BongoShield email | Align the email so SCIM matches the existing account instead of creating a new one. |
| "Last used" never updates | The IdP hasn't run a cycle yet, or the token was regenerated after setup | Run Provision on demand; re-paste the current token if you regenerated it. |