Configure Azure AD SAML first so provisioned users can sign in. SCIM manages workspace membership; SAML handles authentication.
Prerequisites
- Microsoft Entra ID admin access
- Retrac workspace owner role
- Enterprise plan with SCIM enabled
- SAML SSO configured (recommended)
Set up Azure AD SCIM
Open Retrac SCIM settings
In Retrac, go to Settings → Security and open SCIM configuration. Generate or copy your:
- SCIM endpoint URL
- Bearer token (shown once — store in a secrets manager)
Enable provisioning in Entra ID
In the Microsoft Entra admin center, open your Retrac enterprise application.Go to Provisioning and set Provisioning Mode to Automatic.
Enter SCIM credentials
Under Admin Credentials:
- Tenant URL — Retrac SCIM endpoint URL
- Secret Token — Retrac bearer token
Configure attribute mappings
Review Provisioning → Mappings → Provision Microsoft Entra ID Users. Ensure mappings include:
Adjust mappings so the email Entra sends matches how users are identified in Retrac.
| Entra attribute | SCIM field |
|---|---|
userPrincipalName or mail | userName / emails |
givenName | name.givenName |
surname | name.familyName |
Switch([IsSoftDeleted], , "False", "True", "True", "False") | active |