DeepFabric supports System for Cross-domain Identity Management (SCIM) with Microsoft Entra ID (Azure Active Directory) for automated user provisioning and deprovisioning. This integration streamlines user management by synchronizing user accounts between Entra ID and DeepFabric, ensuring secure access control and operational efficiency.
Overview
SCIM (System for Cross-domain Identity Management) is an open standard that allows for automated user provisioning between identity providers (like Entra ID) and applications (like DeepFabric). Using SCIM with DeepFabric enables:
- Automatic user creation when assigned in Entra ID
- Profile updates synchronized to DeepFabric
- Automatic deactivation when users are unassigned or deleted in Entra ID
- Group membership synchronization
Setup Guide
Prerequisites
- A Microsoft Entra ID (Azure AD) tenant with administrator access
- DeepFabric Enterprise account with SCIM integration capabilities
- Admin privileges in your DeepFabric organization
Configuration Steps
Step 1: Obtain SCIM Endpoint and Token from DeepFabric
- Navigate to [Profile Icon] > Organizations > [Organization Name] > Identity Management
- Toggle the Enable SCIM switch to On under Dashboard tab.

- You can copy your SCIM Base URL from Dashboard tab.

- You can generate your new Token (Bearer Authentication) from Auth Tokens tab.

Your Token is copied to your clipboard upon generation. Make sure to save it in a secure location as it will be used in the next step.
Step 2: Configure Microsoft Entra ID (Azure AD)
- Sign in to the Azure portal
- Navigate to Microsoft Entra ID > Enterprise applications, and click on + New application in the command bar.
- You'll be redirected to Microsoft Entra Gallery. In this screen, select + Create your own application in the command bar.
- Provide a name (Ex: DeepFabric) and select Integrate any other application you don't find in the gallery

- Once created, select Provisioning blade from the left sidebar.
Starting March 2025, Entra ID users are redirected to a new provisioning user experience.
- In the Command bar, click on + New configuration
- You'll be redirected to a wizard for creating a New Provisioning Configuration. Under Admin Credentials section, fill the following fields:
- Tenant URL: Enter your DeepFabric SCIM Base URL
- Secret Token: Enter your DeepFabric API Token
- Click Test Connection to verify the configuration

- If the test connection is successful, click on Create button. After successful creation, you will be taken to the configuration details page to manage advanced settings.
Step 3: Verify Attribute Mappings
- From the left sidebar, select Attribute mapping (Preview) blade.
- By default, attribute mappings are created on two resource types:
- User (view mappings by clicking on Provision Microsoft Entra ID Users link)
- Group (view mappings by clicking on Provision Microsoft Entra ID Groups link)
- For User resource type, ensure that the following attributes are mapped:
- externalId → mailNickname
- userName → userPrincipalName
- ...other attributes
- For Group resource type, ensure that the following attributes are mapped:
- externalId → objectId
- displayName → displayName
- ...other attributes
Step 4: Start Provisioning
- Return to the Overview page.
- In the command bar, click on Start provisioning button to begin an immediate sync.

Verification
After configuration, Entra ID will begin synchronizing users based on your settings. To verify:
- Assign a test user to the DeepFabric application in Entra ID
- Wait for the provisioning cycle to complete (may take up to 40 minutes for the initial sync)
- Check DeepFabric to confirm the user has been created with the correct attributes
- Test deprovisioning by removing the application assignment in Entra ID

Troubleshooting
Common Issues
- Connection Errors: Verify your SCIM URL and token are correct
- User Not Provisioned: Check if the user is properly assigned to the DeepFabric application in Entra ID
- Attribute Mapping Issues: Review provisioning logs in Entra ID for specific error messages
Getting Help
If you encounter issues with your SCIM integration, please contact DeepFabric Support at support@deepfabric.ai or your dedicated account manager.
