Relevant Products
SCIM is available in PRO PRINT PRO MFD
This page provides hints and tips on how to switch the existing Authentication Provider configuration to OIDC + System for Cross-domain Identity Management (SCIM), with a focus on preventing misconfiguration and thus eliminating the time your users will be unable to log in into SAFEQ Cloud.
|
An original Authentication Provider configuration |
|
|---|---|
|
OIDC: type “Built-in” |
Switching to “OIDC + System for Cross-domain Identity Management (SCIM)” is safe and straightforward; no need to follow instructions on this page |
|
OIDC: type “Customizable” |
Please read this page carefully before switching to “OIDC + System for Cross-domain Identity Management (SCIM)”. |
|
OIDC + Service Account |
|
|
Service Account |
The basis of any safe approach to switch an existing Authentication Provider configuration to SCIM is to configure and verify the Entra ID part first.
Only when it is confirmed that the SCIM provisioning works from your Entra ID instance to SAFEQ Cloud, will the existing Authentication Provider configuration be changed.
The chapters below depict different approaches that lead to the same result.
Choose one that suits you the most.
Create a testing Authentication Provider in your SAFEQ Cloud customer
Let’s say you have an existing, well-configured, and working “Production Entra ID“ Authentication Provider in SAFEQ Cloud.
Let’s keep this “Production Entra ID“ untouched for a while.
Follow these steps to prepare and test the Entra ID setup:
-
Create a new “Testing Entra ID“ Authentication Provider in SAFEQ Cloud
Follow the instructions from the chapter “Configuring an Authentication provider in SAFEQ CloudDispatcher Paragon CloudCloudStreamPMC“-
Set one specific domain of your domains in the field “Domains“
-
Set the Hide on Login page toggle to ON - it will prevent any user log-ins accidentally to this “Testing Entra ID“ Authentication Provider
-
Further, for the same reason, adjust the field Priority in the “Testing Entra ID“ Authentication Provider - put a lower number there than it is in the “Production Entra ID“ Authentication Provider
-
-
In Microsoft Entra ID, create a few dummy users that are similar to your real users.
-
These dummy users will be used to test provisioning synchronization
-
The User principal name of these dummy users should be based on that specific domain specified in the previous step
-
You can make the dummy users members of some dummy user groups
-
-
Set up SCIM configuration in Microsoft Entra ID
Follow the instructions from the chapter “Configuring SCIM in Microsoft Entra ID“-
When mapping the user’s attributes, take inspiration from mapping in your existing “Production Entra ID“ Authentication Provider in SAFEQ Cloud.
-
When specifying the scope to be provisioned, limit it to the dummy users and related user groups
-
Activate the provisioning in Microsoft Entra ID and wait for the initial sync cycle to finish.
-
-
Verify the provisioning is working properly
-
Check there are no errors in Microsoft Entra ID Provisioning Overview and no errors in Provisioning Logs.
-
In the SAFEQ Cloud Web UI, go to Users and select “Testing Entra ID“ in the select box
-
Verify all the dummy users are listed there
-
Verify all the dummy users have expected attributes
-
Try to set up some Roles for the provisioned groups in the Access Control page
-
-
In SAFEQ Cloud Web UI, try to log in as one of the dummy users
-
The login has to succeed
-
The user has to have the expected user rights based on its user groups' membership - only those menu entries are available for the user that correspond to the roles of groups the user is a member of.
-
-
If all verifications succeed, it's time to adapt the existing, well-configured, and working “Production Entra ID“ Authentication Provider.
Follow these steps to switch production to SCIM
-
in SAFEQ Cloud
-
Delete the “Testing Entra ID“ Authentication Provider
-
Change the configuration of the “Production Entra ID“ Authentication Provider to “OIDC + System for Cross-domain Identity Management (SCIM)“
Follow the instructions from the chapter “Configuring an Authentication provider in SAFEQ CloudDispatcher Paragon CloudCloudStreamPMC“
-
-
in Microsoft Entra ID
-
Adapt the scope to be provisioned - instead of the dummy users and related user groups only, set up the scope you need
-
Remove the dummy users
-
Change the Provision Connectivity - replace the original (“Testing Entra ID”) Tenant URL and Secret Token with the values from the “Production Entra ID“ Authentication Provider
-
Click Test Connection to verify connectivity and Save the changes
-
-
On the Provisioning Overview, click Restart Provisioning - a new initial sync cycle will be executed
-
From now on, your automatic provisioning of users and groups is set up and working for your “Production Entra ID“ Authentication Provider.
Create a testing customer in SAFEQ Cloud
Let’s say you have an existing, well-configured and working “Production Entra ID“ Authentication Provider in SAFEQ Cloud.
If the partner supplying you the SAFEQ Cloud provides such a possibility, ask them to create a testing customer in the SAFEQ Cloud. The following text will refer to it as “Testing customer“.
Follow these steps to prepare and test the Entra ID setup:
-
Create a new “Testing Entra ID“ Authentication Provider in SAFEQ Cloud “Testing customer“
Follow the instructions from the chapter “Configuring an Authentication provider in SAFEQ CloudDispatcher Paragon CloudCloudStreamPMC“ -
Set up SCIM configuration in Microsoft Entra ID
Follow the instructions from the chapter “Configuring SCIM in Microsoft Entra ID“-
When mapping the user’s attributes, take inspiration from the mapping in your existing Authentication Provider in your real SAFEQ Cloud customer.
-
Activate provisioning in Microsoft Entra ID and wait for the initial sync cycle to finish.
-
-
Verify the provisioning is working properly
-
Check that there are no errors in Microsoft Entra ID Provisioning Overview and no errors in Provisioning Logs.
-
Log in as an administrator to the SAFEQ Cloud “Testing customer“ Web UI, go to Users, and select “Testing Entra ID“ in the select box
-
Verify all the users you included in the provisioning scope in Entra ID are listed there in “Testing customer“
-
Verify all the users have the expected attributes
-
Try to set up some Roles for the provisioned groups in the Access Control page
-
-
In SAFEQ Cloud Web UI, try to log in as one of the users
-
The login has to succeed
-
The user has to have the expected user rights based on their user groups' membership - only those menu entries are available for the user that correspond to the roles of groups the user is a member of.
-
-
If all verifications succeed, it's time to adapt the “Production Entra ID“ Authentication Provider in your real SAFEQ Cloud customer.
Follow these steps to switch production to SCIM
-
in the real SAFEQ Cloud customer
-
Change the configuration of the “Production Entra ID“ Authentication Provider to “OIDC + System for Cross-domain Identity Management (SCIM)“
Follow the instructions from the chapter “Configuring an Authentication provider in SAFEQ CloudDispatcher Paragon CloudCloudStreamPMC“
-
-
in Microsoft Entra ID
-
Change the Provision Connectivity - replace the original (“Testing Entra ID”) Tenant URL and Secret Token with the values from the “Production Entra ID“ Authentication Provider
-
Click Test Connection to verify connectivity and Save the changes
-
-
On the Provisioning Overview, click Restart Provisioning - a new initial sync cycle will be executed
-
From now on, your automatic provisioning of users and groups is set up and working for your “Production Entra ID“ Authentication Provider in the real SAFEQ Cloud customer.