You must be logged in to Microsoft Entra using one of the following roles: Application Administrator, Cloud Application Administrator, or Global Administrator.
For information on the entire workflow for configuring SCIM provisioning, see Microsoft Entra ID SCIM Configuration.
User mapping
Sign in to the Microsoft Entra Admin Center at https://entra.microsoft.com.
Navigate to Entra ID > Enterprise apps.
Open the Hyperproof SCIM application you created. See Adding a Microsoft Entra non-gallery application for SCIM.
From the left menu, select Provisioning.
Click the Attribute mapping section.
Click Provision Microsoft Entra ID Users.
Remove the following unnecessary mappings. Hyperproof doesn't use them:
name.formattedaddresses[type eq "work"].*(all address fields)phoneNumbers[type eq "work"].valuephoneNumbers[type eq "mobile"].valuephoneNumbers[type eq "fax"].valuetimezoneexternalIddisplayName displayNameurn:ietf:params:scim:schemas:extension:enterprise:2.0:User:employeeIdurn:ietf:params:scim:schemas:extension:enterprise:2.0:User:departmenturn:ietf:params:scim:schemas:extension:enterprise:2.0:User:managerMake sure the following required mappings are configured:
Hyperproof attribute | Microsoft Entra ID attribute | Matching precedence | Notes |
|
| 1 | Primary identifier |
|
|
| User's email address |
|
|
| User status (active/inactive) |
|
|
| First name (required) |
|
|
| Last name (required) |
Expression mapping
Scroll to the bottom and click Add New Mapping.
Configure the mapping as follows:
Mapping type - Expression
Expression -
SingleAppRoleAssignment([appRoleAssignments])Target attribute -
roles[primary eq "True"].valueApply this mapping - Always
Click OK.
Add the following optional mappings:
These mappings are recommended for richer user data.
Hyperproof attribute | Microsoft Entra ID attribute |
|
|
|
|
Group mapping
Optionally, configure group mappings as follows:
Return to the Attribute mappings section.
Click Provision Microsoft Entra ID Groups
Delete the following unnecessary mapping:
externalIDKeep these mappings:
displayName → displayNamemembers → members
Click Save.
