Hello there!

Need Help? We are right here!

support
miniOrange Email Support
success

Thanks for your inquiry.

If you dont hear from us within 24 hours, please feel free to send a follow up email to info@xecurify.com

Azure AD Provisioning & Deprovisioning


Azure Active Directory Provisioning helps to provision users to SaaS applications and other systems by connecting to user management API endpoints provided by each application vendor. These user management API endpoints allow Azure AD to programmatically create, update, and remove users. miniOrange integrates seamlessly with Azure Active Directory. With the miniOrange provisioning feature, you can provision all the users with their identities automatically in the Azure Active Directory.

Azure AD Provisioning involves the process of creating, updating and deleting a user's account in Azure Active Directory from your miniOrange portal.

Provisioning saves time when setting up new users and teams, and also manages access privileges through the user lifecycle. miniOrange can create, read, and update user accounts for new or existing users, remove accounts for deactivated users, and synchronize attributes across multiple user stores.

Azure AD User Provisioning and deprovisioning actions are bi-directional, so you can create accounts inside an external application and import them into miniOrange, or alternatively create the accounts in miniOrange and then push them out to any linked external applications.

Azure AD Deprovisioning means deleting a user and removing their access from multiple applications and network systems at once. Deprovisioning action is triggered when an employee leaves a company or changes roles within the organization. The deprovisioning features increase your organization's security profile by removing access to sensitive applications and content from people who leave your organization.



What is SCIM for?

System for Cross-domain Identity Management (SCIM) is an open standard to automate user provisioning. SCIM standard is a communication medium between an Identity Provider (IDP) and a Service Provider (SP) that requires user identity information.

SCIM provides a defined schema for representing users and groups, and a RESTful API to run CRUD operations on those user and group resources.

With the SCIM protocol, user data is stored in a consistent way and can be shared with different applications. Since data is transferred automatically, complex exchanges are simplified and the risk of error is reduced.

Azure AD Provisioning flow

Provisioning & Deprovisioning Scenarios


miniOrange provides solutions for all scenarios of provisioning, which includes AD Integration, LDAP Integration and automated provisioning for all External Applications such as Office 365, Google Workspace, Workday, etc



Follow the Step-by-Step Guide given below to setup Azure AD Provisioning

1. Setup Provisioning in Azure AD

  • Login into miniOrange Admin Console.
  • Go to the User Stores, Click on Add Users Store.
  • Configure ldap as a User Store to set up user provisioning with AD/LDAP. You can choose any of the user store mentioned there.
    • Store LDAP Configuration in miniOrange: Keep configuration in miniOrange. Make sure to open the firewall to allow incoming requests to your LDAP.
    • Store LDAP Configuration On-Premise: Keep configuration in your premise and only allow access to LDAP inside premises. You will have to download and install miniOrange gateway in your premise.
    Configure LDAP for Azure AD provisioning

  • In the Provisioning section and select Active Directory from the dropdown.
  • Enter the Admin Username and click on Verify Credentials.
  • Azure AD Provisioning Setup

  • In User Provisioning/Deprovisioning tab enable the provisioning features such as Import User, Create User, Edit User, Delete User and Password Sync which you want for users.
  • Azure AD Provisioning Configure Users

  • In Group Provisioning/Deprovisioning tab enable the group provisioning features such as Import Group, Create Group, Delete Group and Add/Remove Group membership of User.
  • Azure AD Provisioning: Google Workspace Provisioning Configure

  • Click Save.

2. Import Users

  • To import the users from Active Directory, go to the Import Users tab.
  • Select the Active Directory from the drop down menu and click on import.
  • Azure AD Provisioning: Import user from AD for provisioning

  • Now go to the Users >> User List and you will find the all the users imported from Active Directory.

3. Import Groups

  • To import groups from Active Directory, go to the Import Groups tab.
  • Select the Active Directory from the drop down menu and click on Import.
  • Azure AD Provisioning: Import groups from AD for provisioning

4. Create Users

  • To create a user in miniOrange, Go to Users >> User List >> click on the Add User button.
  • Fill out user basic information and click on Create User button.
  • Azure AD Provisioning Add User

  • After creating user in miniOrange it will automatically create the same user in Azure AD.
  • View user details after AD Provisioning

5. Edit Users

  • To update user profile, Go to Users >> User List.
  • Select a particular user and in Actions dropdown select Edit.
  • Azure AD Provisioning Select Edit User

  • Fill out user updated information and click on Save button.
  • Azure AD Provisioning Edit User

6. Delete Users

  • To delete user, Go to Users >> User List.
  • Select a particular user and in Actions dropdown select Delete.
  • Azure AD Provisioning Select Delete User

  • A pop up will appear in which click on Yes button.
  • Azure AD Provisioning Delete User

7. Password Sync

  • To send password sync emails to the users with link to reset their Active Directory account password, Go to Users >> User List and click on On Boarding Status tab.
  • Select users and in Select Action dropdown select Send Activation Mail with Password Reset Link.
  • Click on Apply.
  • Azure AD Provisioning Password Sync

  • Click on the activation link and it will direct to reset password.
  • Once, the new password is set it will be synced.

External References

Our Other Identity & Access Management Products