# Setting up Entra SCIM

Last updated 9 days ago

### Who can use this feature

- Supported on **Enterprise** plans
- Anyone with an org admin or IT admin role can access and edit SCIM settings

This article shows how to retrieve key pieces of information from Entra to complete the SCIM provisioning process. For the rest of the SCIM setup process, see our article [Setting up SCIM provisioning](https://support.writer.com/article/88-setting-up-scim-provisioning).

## Before you begin

- [Set up SAML SSO](https://support.writer.com/article/43-setting-up-saml-sso) before you begin SCIM provisioning.
- Collect key data from WRITER to share with Entra, as explained [here](https://support.writer.com/article/88-setting-up-scim-provisioning#Set-up-SAML-SSO-between-Writer-and-your-IdP-maqBv).

## Configure SCIM in Entra

Go to the **Provisioning** page in your Entra WRITER application and select **Connect your application** in the **Create configuration** section.

Select the `automatic` provisioning mode, then paste your **endpoint** and **bearer token** from WRITER (step 1 [here](https://support.writer.com/article/88-setting-up-scim-provisioning#Step-by-step-configuration-instructions-iJSb-)) into the Tenant URL and Secret Token fields. The Tenant URL should always be `https://app.writer.com/api/scim/v2`. You can then test the connection and save.

### Enable attribute mapping in Entra

Expand the **Mappings** section and make sure that both group and user attribute mappings are enabled, and are mapping the correct fields into WRITER.

We **require** mapping `emails[type eq "work"].value` to `mail`. All other attribute mappings are optional.

For most users, the default mapping doesn't require any changes.

### Push users and groups

To sync users/groups from Entra into WRITER, you'll need to assign them to your Entra Application. From the **Users and groups** page, select **Add user/group** from the top menu.

Select `None selected` under **Users and Groups**, then select the entities you want to add to the SCIM app, and click **Select**.

Select **Assign** to add them to your SCIM app.

### Enable SCIM provisioning in Entra

Once you've reviewed the attribute mapping and user/group push settings, return to the **Provisioning** page, expand the **Settings** section, and set the **Scope** to `Sync only assigned users and groups`, and the **Provisioning Status** to `On`. SCIM's now set up!

### Configure role attribute in Entra (optional)

You can add a custom attribute to assign `team member` and `org admin` roles to WRITER users. To get started, select the **Add New Mapping button** at the bottom of the **Mappings** list. The source attribute is `appRoleAssignments`, and the target attribute is `urn:custom:params:scim:schemas:extension:writer:2.0:User`. Ensure that **Apply this mapping** is set to `Always`.

## Finish the SCIM provisioning process

Return to [Setting up SCIM provisioning](https://support.writer.com/article/88-setting-up-scim-provisioning#Choose-default-team-in-Writer-Z_6VF) to complete this process.
