Provision Users to Microsoft Entra ID
Overview
You can provision users from Fixiam into Microsoft Entra ID, allowing you to manage user identities centrally while keeping your Entra environment up to date.
Once configured, users assigned access in Fixiam can be created and updated in Microsoft Entra ID automatically.
Before You Begin
Make sure the following are in place:
-
The Microsoft Entra ID application has been added in Fixiam
→ See: [How to Add and Configure Applications] -
You have admin access to your Microsoft Entra ID tenant
-
You can create and manage app registrations in Entra ID
-
Users in Fixiam must have valid email domains that match your Entra ID tenant
(e.g. [email protected])
Important:
If a user does not have a valid domain, provisioning to Entra ID will fail.
How It Works
- You connect Fixiam to Microsoft Entra ID using API credentials
- You assign users access through groups in Fixiam
- Fixiam provisions those users into Entra ID
- Entra ID creates the user account
Step 1: Prepare Microsoft Entra ID
You need to create an application in Entra ID to generate the required credentials.
- Log in to Microsoft Entra ID
- Go to App Registrations
- Click New Registration
- Enter a name for the application
- Complete the registration
Get the required details:
-
Tenant ID
Found in your Entra tenant overview -
Client ID
Found in the application overview
Create Client Secret
- Go to Certificates & Secrets
- Click New Client Secret
- Add a description and expiration
- Save
Important:
- Copy the Client Secret immediately
- You will not be able to view it again after leaving the page
Additional Details
-
Token Endpoint
Provided by Microsoft based on your tenant -
Scope
Defined based on the permissions required for provisioning
Step 2: Open Provisioning in Fixiam
- Go to the Provisioning section
- Select Outbound Provisioning
- Locate your Microsoft Entra ID application
Step 3: Set Up Connection
- Open the action menu
- Click Set Up Connection
Provide the following:
- Tenant ID
- Client ID
- Client Secret
- Token Endpoint
- Scope
- Click Save
- Click Test Connection
If successful, the connection will be established.
Step 4: Provision Users
Users are provisioned based on access.
- Only users assigned to the application through groups will be provisioned
- If a user is not assigned via a group, they will not be created in Entra ID
To provision users:
- Assign users to a group that has access to the application
- Ensure the group is linked to Microsoft Entra ID
→ See: [Managing Groups and Access]
What Happens After Provisioning
- Users are created in Microsoft Entra ID
- A temporary password is generated by Fixiam
Important:
- The temporary password is not visible to the user
- Fixiam does not send the password to the user
To complete onboarding:
- An Entra ID administrator must reset the user’s password
- The user will receive a password setup link from Entra ID
Troubleshooting
User is not provisioned
- Ensure the user has a valid email domain
- Confirm the user is assigned via a group
Connection test fails
- Verify all credentials are correct
- Ensure the client secret is valid and not expired
User cannot log in after provisioning
- Reset the user’s password in Entra ID
- Ensure onboarding is completed
Permission or authentication errors
- Verify API permissions in Entra ID
- Confirm admin consent has been granted if required
Summary
Provisioning to Microsoft Entra ID allows you to:
- Manage users centrally from Fixiam
- Keep Entra ID in sync automatically
- Reduce manual user creation and onboarding effort
Updated 9 days ago
