SCIM (System for Cross-domain Identity Management)
7 min
this feature allows users to be automatically synchronised between the identity provider(idp) and the service provider(sp) which means that users can be managed entirely on the idp side and then they flow to the application where users are created as assigned groups automatically please note you will need the scim feature toggled on in order to use this feature please email support\@fusionsignage com au mailto\ support\@fusionsignage com au to request this feature be enabled requirements active directory enterprise application users assigned to this application an api key for authenticating the service level requests url for the service to communicate with (scim endpoint) setup the enterprise application within active directory, navigate to provisioning select edit provisioning enter the admin credentials here tenant url β this will be the scim endpoint of fusion signage secret token β the api key that was generated as part of this access test the connection to confirm that this is all correct and click save expand mappings and select provision azure active directory users the mappings are required to map to fusion signage ensure that this set of attributes are enabled and click save once the scim provisioning feature has been turned on, refresh your browser and navigate to the security tab, you should be able to see the scim credentials click the refresh symbol to generate an api key and click assign api key to save it copy this key (by clicking the copy to clipboard icon next to the scim api key heading) enter this into the credentials part of the enterprise application and click test connection to ensure that the credentials are working add users within the enterprise application navigate to users and groups add users that need to be synchronised start the sync from the provisioning menu option, click the start provisioning button to start the process group synchronisation scim also facilitates the ability to sync groups to the platform, these are just logical groupings of users the concept of user groups may need to be implemented into your platform each user object that gets synchronised follows a similar flow as the users sync group is synced without users in a payload containing it's name, external id and no users this gets parsed in the api and created accordingly the next step is for each user to be synchronised as an add operation for the group object the user is queried for its existence on the sp side and if preset it is processed accordingly if the user doesn't exist in the sp the same flow for user creation occurs before being assigned to the group scim, with respect to azure provisioning, only uses 3 rest verbs to achieve the outcome get to fetch the resource by the external id post to create the resource on the sp patch to update the resource looking for something else? we canβt wait to hear about it reach out to our sunshiney support and we'll be in touch in a flash