Configure Azure AD SAML first so provisioned users can sign in. SCIM manages workspace membership; SAML handles authentication.
Prerequisites
- Microsoft Entra ID admin access
- Retrac workspace owner role
- Enterprise plan with SCIM enabled
- SAML SSO configured (recommended)
Set up Azure AD SCIM
1
Open Retrac SCIM settings
In Retrac, go to Settings → Security and open SCIM configuration. Generate or copy your:
- SCIM endpoint URL
- Bearer token (shown once — store in a secrets manager)
2
Enable provisioning in Entra ID
In the Microsoft Entra admin center, open your Retrac enterprise application.Go to Provisioning and set Provisioning Mode to Automatic.
3
Enter SCIM credentials
Under Admin Credentials:
- Tenant URL — Retrac SCIM endpoint URL
- Secret Token — Retrac bearer token
4
Configure attribute mappings
Review Provisioning → Mappings → Provision Microsoft Entra ID Users. Ensure mappings include:
Adjust mappings so the email Entra sends matches how users are identified in Retrac.
5
Assign users and start provisioning
- Assign users or groups to the Retrac enterprise app under Users and groups.
- Set Provisioning Status to On.
- Review the Provisioning logs for successful create and deactivate events.