> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gumloop.com/llms.txt
> Use this file to discover all available pages before exploring further.

# SCIM with Entra

> Configure SCIM user provisioning for Gumloop with Microsoft Entra ID (formerly Azure Active Directory)

SCIM (the system for cross-domain identity management) lets Entra synchronize user data with Gumloop through recurring communication: Gumloop periodically receives updates about the users that should have access, and uses them to provision or deprovision users — or simply update data about a user (e.g., a first name). See [SSO, SAML & SCIM](/enterprise-features/sso_saml_scim#scim-provisioning).

<Warning>Entra's SCIM implementation has many unresolved issues. (See [here](https://learn.microsoft.com/en-us/entra/identity/app-provisioning/application-provisioning-config-problem-scim-compatibility) for a known subset.) In rare cases, Entra's unusual behavior may result in an unsuccessful integration. Please contact [support@gumloop.com](mailto:support@gumloop.com) if you encounter unexpected behavior.</Warning>

Connecting Entra to Gumloop requires sharing two pieces of information with Entra, both of which come from Gumloop:

1. A **base URL** that Entra will perform operations on (e.g. via HTTP PATCH)
2. A **bearer token** that Entra will include with its requests

When Entra has both of those pieces of information, the connection is complete. No additional Gumloop-side configuration is necessary. With that said, configuration within Entra can be somewhat involved.

## Before you start: get your base URL and bearer token from Gumloop

SCIM is an Enterprise add-on — a Gumloop organization admin requests enablement via [support@gumloop.com](mailto:support@gumloop.com), then generates a setup link at [gumloop.com/settings/organization/sso](https://www.gumloop.com/settings/organization/sso). The setup page shows your SCIM **base URL** and lets you generate the **bearer token**.

<Warning>
  Gumloop **does not store bearer tokens** — the token is shown once, at generation time. You can generate a new one at any time, which immediately invalidates the previous token.
</Warning>

# Configuring Entra

Start at the Entra home page. Navigate to *enterprise applications* in the navigation bar.

<Frame caption="Visiting *enterprise applications* in Entra">
  <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-scim-assets/entra/image_0.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=4c700e8f4f3a702063e54d23bc9aaa29" width="1438" height="752" data-path="images/idp-guides/idp-scim-assets/entra/image_0.png" />
</Frame>

You'll now see a list of applications. In this case, we have just one: *test\_application*. Click the blue text to see more details about the application.

<Info>If the relevant application does not exist, you may benefit from reading the [SAML with Entra](/enterprise-features/idp-guides/saml-with-entra) guide on creating an enterprise application.</Info>

<Frame caption="Opening the application in Entra">
  <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-scim-assets/entra/image_1.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=791eada763d6e9692af44aae848c4353" width="1436" height="750" data-path="images/idp-guides/idp-scim-assets/entra/image_1.png" />
</Frame>

You'll see an *Overview* page. Click on the menu item labeled *Provisioning* on the left.

<Frame caption="Navigating to *Provisioning* in Entra">
  <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-scim-assets/entra/image_2.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=243855d6266ea672f52b56a5b9123ed0" width="1440" height="753" data-path="images/idp-guides/idp-scim-assets/entra/image_2.png" />
</Frame>

This will take you to a new menu. Look toward the top/center of the page for a button with a plus icon labeled *New configuration*. Click this.

<Frame caption="Selecting *New configuration* in Entra">
  <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-scim-assets/entra/image_3.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=329d0f215c8c4db2c8b20a042a4facaa" width="1440" height="751" data-path="images/idp-guides/idp-scim-assets/entra/image_3.png" />
</Frame>

You'll land on a page with a few data input options. Start with the field labeled *Tenant URL*. This is what Gumloop calls the *base URL* — the location where Entra will send its SCIM communications. Copy this value from your Gumloop SCIM setup page and paste it here.

It should look something like the below:

<Frame caption="Pasting Gumloop's *base URL* as the *Tenant URL* in Entra">
  <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-scim-assets/entra/image_4.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=49bdfec600fc56ad5e7d01ea5f94a442" width="1433" height="751" data-path="images/idp-guides/idp-scim-assets/entra/image_4.png" />
</Frame>

Next, look at the field labeled *Secret token* directly below the *Tenant URL*. This is the other value that Gumloop provides: the *bearer token*. Paste it into Entra as the *Secret token*.

The *Secret token* is sensitive. Please treat it like a password. Do not share it.

<Frame caption="Pasting the *Secret token* in Entra">
  <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-scim-assets/entra/image_5.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=7a717bc86eac8b80571007425e93f055" width="1433" height="751" data-path="images/idp-guides/idp-scim-assets/entra/image_5.png" />
</Frame>

In Entra, you need to click *Test connection* to move on. Click this button and wait a moment.

<Frame caption="Clicking *Test connection* in Entra">
  <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-scim-assets/entra/image_6.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=5d0e95f7a0c78e47018e710c4ed25645" width="1433" height="751" data-path="images/idp-guides/idp-scim-assets/entra/image_6.png" />
</Frame>

Once it's clickable, hit *Create* in the lower left.

<Frame caption="Pressing the *Create* button in Entra">
  <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-scim-assets/entra/image_7.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=c1b8e680c71e6fa1fb03b08830722a18" width="1433" height="751" data-path="images/idp-guides/idp-scim-assets/entra/image_7.png" />
</Frame>

You'll land on a new page showing an overview of the Entra application. Find the *Users and groups* button in the left navbar and click it.

<Frame caption="Visiting *Users and groups* in Entra">
  <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-scim-assets/entra/image_8.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=1b4ca29e2987143dcc0e0c3bf47f7d8c" width="1441" height="752" data-path="images/idp-guides/idp-scim-assets/entra/image_8.png" />
</Frame>

We need to assign users and/or groups to the application. Start by clicking the *Add user/group* button toward the top/center of the page. It's marked with a plus icon.

<Frame caption="Hitting *Add user/group* in Entra">
  <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-scim-assets/entra/image_9.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=622e5df1852854984844f6c961ac77dd" width="1440" height="752" data-path="images/idp-guides/idp-scim-assets/entra/image_9.png" />
</Frame>

Exactly what you'll see might vary here, but you'll see a searchable list of users and/or groups. Decide which users should have access to the application, select each, and then press *Select* in the lower left.

<Frame caption="Selecting users and/or groups to add to the application">
  <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-scim-assets/entra/image_10.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=341543ece6aa417b29d4a7a9dd9dc645" width="1439" height="753" data-path="images/idp-guides/idp-scim-assets/entra/image_10.png" />
</Frame>

You'll see another menu. If you're content with your selection, press the *Assign* button in the lower left. Entra will now consider those users and/or groups to be *assigned* to the application.

<Frame caption="Assigning a selection of users and/or groups to the application">
  <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-scim-assets/entra/image_11.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=cb1245f64f6cbf9724945860a5afcbc9" width="1440" height="753" data-path="images/idp-guides/idp-scim-assets/entra/image_11.png" />
</Frame>

Entra will not yet have begun SCIM provisioning. To get Entra to begin SCIM provisioning, press the *Overview* button in the left navbar.

<Frame caption="Returning to the application's *Overview*">
  <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-scim-assets/entra/image_12.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=99fdacfec20c60ccbc6fca29893fcdd5" width="1437" height="751" data-path="images/idp-guides/idp-scim-assets/entra/image_12.png" />
</Frame>

Press the *Start provisioning* button. It has a play button icon — kind of like you'd see on a remote control.

Within a few moments, you'll see a pop-up in the top right. It will say *Provisioning is scheduled to start*.

This means that Entra has successfully begun its communications with Gumloop.

<Frame caption="Provisioning started in Entra">
  <img src="https://mintcdn.com/agenthub/zL6qAgistqWft1iw/images/idp-guides/idp-scim-assets/entra/image_13.png?fit=max&auto=format&n=zL6qAgistqWft1iw&q=85&s=c1fd7ca17f95f06ca06d6628390b492a" width="1438" height="751" data-path="images/idp-guides/idp-scim-assets/entra/image_13.png" />
</Frame>

# Enabling synchronization in Gumloop

Provisioned users only reach your organization once synchronization is enabled on the Gumloop side. A Gumloop organization admin returns to [gumloop.com/settings/organization/sso](https://www.gumloop.com/settings/organization/sso), selects the SCIM directory, and enables synchronization — see [Setting Up SCIM](/enterprise-features/sso_saml_scim#setting-up-scim).

Once enabled, configuration is complete: assigned users appear in your organization's member list after the next sync (automatic every 15 minutes, or triggered manually by the admin).
