Azure SCIM Integration
Swimlane Turbine supports SCIM 2.0 integration with Microsoft Entra ID (formerly Azure Active Directory). This integration enables administrators to automatically provision users and groups to Swimlane using the SCIM standard.
Choose Your Path
Goal | Go to |
|---|---|
Connect Entra to Swimlane | |
Understand sync timing | |
Field mapping and API details | Provisioning with SCIM IntegrationProvisioning with SCIM Integration |
Configure SCIM in Microsoft Entra
- In the Microsoft Entra admin center, create an Enterprise application for Swimlane Turbine (non-gallery custom app if needed).
- Open the Provisioning tab and set Provisioning mode to Automatic.
- Under Admin Credentials, enter:
Field | Value |
|---|---|
Tenant URL | https://<your-swimlane-host>/tenant/api/account/<ACCOUNT_ID>/scim/v2 |
Secret Token | Swimlane Personal Access Token (PAT) |
Replace <your-swimlane-host> with your Swimlane Turbine hostname and <ACCOUNT_ID> with your Swimlane account UUID. Create the PAT in Swimlane under Edit Profile > Personal Access Token. Use a PAT for a user with Account Admin privileges. Entra sends the token as the secret; Swimlane maps Bearer authentication for SCIM. See Provisioning with SCIM IntegrationProvisioning with SCIM Integration for authentication and authorization.
- Click Test Connection, then save when the test succeeds.
- Under Users and groups, assign the users and groups Entra should provision to Swimlane.
- Use Provision on demand when you need an immediate sync for a single user or group.
Roles are not provisioned through SCIM. After groups sync, assign roles to groups manually in Swimlane Turbine.
User Provisioning
Provisioning users from Microsoft Entra ID to Swimlane Turbine takes approximately 40 minutes. This interval is controlled by Microsoft and applies to all user-related operations, such as updating user details or removing user assignments. These changes are synced to Swimlane at the end of the next 40-minute cycle.
Group Provisioning
Provisioning groups, with or without users, typically takes 20 minutes to sync with Swimlane. This applies to changes such as:
- Adding or removing users from a group
- Updating group details
- Deleting groups or removing group assignments from the SCIM application
Understanding Provisioning Cycles
In the Overview tab of your Entra provisioning configuration, you can view provisioning cycle timestamps. The most relevant fields are Last cycle start time and Last cycle completed time. Any user- or group-related changes made after Last cycle start time are processed in the next provisioning runβapproximately 40 minutes later for users and 20 minutes later for groups.
Immediate Provisioning (Provision on Demand)
To sync a user or group immediately, use Provision on demand in the Entra provisioning configuration. This triggers an instant provisioning attempt for the selected user or group. Keep the following in mind:
- Provision on demand only supports provisioning; it does not support updates, deletions, or group membership changes.
- When provisioning groups, you can select individual users rather than syncing the entire group.
Attribute Handling
Entra requires only userPrincipalName and displayName in the default mapping. Swimlane expects additional attributes, including first name, last name, email, and display name. If any required attribute is missing, Swimlane uses the userPrincipalName value as a fallback.
For more information on how Entra provisioning works, see How provisioning works on Microsoft Learn.
See Also
- Provisioning with SCIM IntegrationProvisioning with SCIM Integration β Prerequisites, PAT authentication, REST endpoints, and field mapping