Microsoft Entra ID: SCIM provisioning

Let Microsoft Entra ID create, update and deactivate people in MuchSkills, with their roles. You add SCIM provisioning to your MuchSkills enterprise app in Entra, map the email address and roles, test with a few people and start provisioning.

Updated

Connected on requestITAdmins and HR

Who
A MuchSkills Owner or Admin, with an Application Administrator in Entra
How it connects
Support sends SCIM credentials, then you set up provisioning in Entra
Updates
About every 40 minutes, set by Microsoft
Plans
Included in all plans

Before you start

  • In MuchSkills: the Owner or Admin role.
  • In Microsoft Entra: an Application Administrator or Cloud Application Administrator.
  • SCIM credentials from MuchSkills. We create an OAuth 2.0 client ID and client secret for you. The secret does not expire. Step 1 covers this.
  • Single sign-on first. We recommend setting up Microsoft Entra ID: single sign-on before provisioning, and adding provisioning to the same enterprise app, so people can log in as soon as they arrive.
  • One way in. If you already sync people with the Microsoft Entra ID connector in Settings › Integrations, decide which of the two you keep for the same people.
  • Start small. Assign yourself and a few colleagues first. You can widen the scope afterwards.

Steps

In MuchSkills

  1. Ask support for SCIM credentials. Email support@muchskills.com or use the chat, and say you use Microsoft Entra ID. Until provisioning is set up, Team/Org › Settings › Security & SAML says SCIM provisioning is available for your organisation. See the setup guide for next steps.

In Microsoft Entra

  1. Open the MuchSkills app. In the Microsoft Entra admin center, go to Entra ID › Enterprise apps and open the MuchSkills app you use for single sign-on. If you have none, click New application › Create your own application, name it MuchSkills, choose Integrate any other application you don't find in the gallery (Non-gallery) and click Create.
  2. Create the MuchSkills roles. Go to Entra ID › App registrations, open All applications and select the MuchSkills app. Under App roles, click Create app role. Enter Member as both Display name and Value, choose Users/Groups under Allowed member types, add a Description, keep Do you want to enable this app role? ticked and click Apply. Repeat for Analyst and Admin. The values must be spelt exactly like this. Microsoft's guide to app roles
  3. Connect to MuchSkills. Back in Enterprise apps, open the MuchSkills app, select Provisioning and click New configuration. Enter:
    Leave Secret Token empty: MuchSkills does not issue static tokens. Some tenants still show the classic screen: there, set Provisioning Mode to Automatic, open Admin Credentials, choose OAuth2 Client Credentials Grant as the Authentication Method and fill in Tenant URL, Token Endpoint, Client Identifier and Client Secret. Click Test Connection, then Create, or Save on the classic screen. Microsoft's guide to connecting a SCIM app
  4. Check the email mapping. Select Attribute mapping and open the user mapping. By default Entra sends userPrincipalName as userName. If your users' principal names are not their email addresses, edit the userName row and set Source attribute to mail. userName must be the address people log in to MuchSkills with. Microsoft's guide to attribute mappings
  5. Add the role mapping. In the same user mapping, click Add New Mapping. Set Mapping type to Expression, Expression to SingleAppRoleAssignment([appRoleAssignments]) and Target attribute to roles[primary eq "True"].value. Click Ok, then Save. Turn off the group mapping, because MuchSkills accepts users only. Microsoft's reference for expressions
  6. Assign your test users with their roles. Open Users and groups › Add user/group. Pick your test users, choose Member, Analyst or Admin under Select a role, and click Assign. Keep the scope at Sync only assigned users and groups. Microsoft's guide to assigning users and groups
  7. Test one person. Select Provision on demand, search for a test user and run it. Every step should show success.
  8. Set up alerts. Select Overview › Properties, click the pencil, turn on notification emails and accidental deletions prevention, and click Apply.
  9. Start provisioning. On Overview, click Start provisioning. On the classic screen, set Provisioning Status to On and click Save. The first cycle takes longer than the later ones.

Back in MuchSkills

  1. Check the people who arrived. Team/Org › Members lists your test users with the roles you picked. When all is well, assign the rest of your people in Entra.

Check it worked

  • Provision on demand shows success for your test user.
  • In Entra, Provisioning logs list your users as created, with no failures.
  • Team/Org › Members lists them with the right names, departments, managers and roles.
  • Team/Org › Settings › Security & SAML says SCIM provisioning is enabled for your organisation.

What you get

  • Joiners and leavers handled in Entra. Assign someone and they get a MuchSkills account. Unassign or disable them and they are deactivated.
  • Roles from Entra. Who is a Member, Analyst or Admin in MuchSkills is decided by the app role you assign.
  • Managers and departments in place. Reporting lines and departments arrive with each person, ready for My Circle and reports.

Important to know

What syncs. Only email and name are required. Map as many of the other attributes as you hold in Entra, because each one makes MuchSkills more useful.

Entra attributeSCIM attributeNeededUsed in MuchSkills for
userPrincipalName or mailuserNameRequiredEmail and login
mailemails, type workRequiredEmail. Must match userName
displayNamedisplayNameRequiredName
givenName, surnamename.givenName, name.familyNameRecommendedName
jobTitletitleRecommendedJob title
departmententerprise extension: departmentRecommendedDepartment
managerenterprise extension: managerRecommendedReporting lines and My Circle
address attributesaddresses, type workRecommendedLocation. Keep country mapped
Not deleted or disabledactiveRecommendedDeactivating leavers
App role assignmentroles, primary valueOptionalRole: Member, Analyst or Admin

Managers need to be in scope too. Entra can only send a manager who is also provisioned to MuchSkills. Assign managers along with their teams.

One role per person. With SingleAppRoleAssignment, give each person one app role. If someone has two, Microsoft does not guarantee which one is sent. This mapping also needs the scope Sync only assigned users and groups.

Leavers are deactivated, not deleted. When a person is unassigned, disabled or deleted in Entra, Entra sends active set to false. MuchSkills deactivates them, and their project history and certificates stay on record.

Email addresses are managed by Entra. Provisioned people cannot change their email address in MuchSkills. They see Managed by automated provisioning in Profile Settings › Account.

Keep the credentials safe. Treat the client secret like a password. It does not expire, and Entra fetches a new one-hour access token on its own. If you think it has leaked, ask support for new credentials and update them in Entra.

Troubleshooting

What you seeWhyWhat to do
Test Connection failsThe Tenant URL, token endpoint or credentials are wrongCheck each value against step 4 and what support sent you. Ask support for new credentials if you are unsure
Requests fail with 401 Unauthorized in Provisioning logsThe credentials are wrong or no longer validEnter the credentials again, or ask support for new ones
No one is provisionedNo users or groups are assigned, or provisioning has not been startedAssign people in Users and groups, then click Start provisioning
A user fails with 409 ConflictA MuchSkills account with that email address already existsCheck the email in MuchSkills and in Entra, and that userName is the person's email address
A user fails because userName is not a valid emailuserName gets the user principal name, which is not an email addressMap mail to userName (step 5)
Everyone arrives as MemberThe role mapping is missing, or the app role values do not matchCheck step 6, and that the app role values are exactly Member, Analyst and Admin
A manager is missingThe manager is not assigned to the appAssign the manager too, then run Provision on demand for the person
The app goes into quarantineEntra met repeated errors, often a credentials problemFix the error shown in Provisioning logs, then restart provisioning
Which Microsoft roles do we need?

An Application Administrator or a Cloud Application Administrator can set up provisioning, create the app roles and assign people. In MuchSkills you need the Owner or Admin role.

How often does Entra send changes?

Microsoft runs a provisioning cycle about every 40 minutes. To push one person straight away, use Provision on demand on the app's Provisioning page.

What happens when someone leaves?

When you unassign or disable a person in Entra, Entra sends active set to false and MuchSkills deactivates them. They leave everyday views, and their project history and certificates stay on record. Nothing is deleted.

How do we give someone the Admin or Analyst role?

Create the app roles Member, Analyst and Admin, add the role mapping in step 6, and pick the role when you assign the person. People assigned without a MuchSkills role join as Member.

Can we make someone an Owner through SCIM?

No. SCIM accepts Admin, Member and Analyst. Ask an existing Owner to make the change in MuchSkills.

Can we choose who gets a MuchSkills account?

Yes. Only the users and groups you assign to the app are provisioned. Assigning groups needs Microsoft Entra ID P1 or P2.

Do our Entra groups appear in MuchSkills?

No. MuchSkills accepts users, not groups. Groups only decide who is provisioned. Departments come from each person's department attribute.

Do profile photos sync?

Not through Entra provisioning. Microsoft does not support sending a photo attribute to apps. People can add their own photo in MuchSkills.

Should we use this or the Microsoft Entra ID sync connector?

Use one of them for the same people. SCIM is driven from Entra and carries roles. The connector in Settings › Integrations is driven from MuchSkills, syncs every 5 hours and lets you pick departments or groups there. See Microsoft Entra ID: sync users.

Checking Daniel’s calendar...

Ask us anything

A real person replies, usually the same working day.

Live webinar · 13 Oct, 17:00 CEST

How to analyse the Skill Gaps in your organisation

MuchSkills allows organisations to conduct an in-depth skills gap analysis in a matter of minutes and uncover the skill gaps that hurt organisational performance In this webinar, you will learn how t…