provisioningmicrosoft-entra-id

Does the SCIM endpoints have to be available from Internet when using Microsoft Entra Provisioning?


Our app is usually only available from our customers Intranet and not Internet.

Would this work with Microsoft Entra Provisioning? It seems it can only be accessed by Internet since I have to configure the URL under https://entra.microsoft.com.

Thank you in advance!


Solution

  • The SCIM endpoint must be internet-facing for use with the Entra provisioning service unless you use Entra's on-premises provisioning agent. The agent requires outbound internet connectivity and opens a connection to Entra, eliminating the need for inbound connections to be allowed. The agent also doesn't need to be on the same server as the application, as long as it has internal (intranet) network connectivity to the application.