Hello IFS Team,
we are currently implementing Microsoft Entra ID (Azure AD) user and group provisioning for IFS Cloud using the SCIM interface.
Our environment is operated as a managed service in Microsoft Azure. Each customer has its own Microsoft Entra tenant, while the IFS Cloud environment is hosted in a separate managed Azure tenant operated by us.
During our design phase, we identified that the standard Microsoft Entra SCIM provisioning service typically requires the SCIM endpoint to be reachable by Microsoft's cloud-based provisioning service via public IP addresses. Microsoft also provides an alternative architecture based on the Microsoft Entra Provisioning Agent, which allows provisioning to SCIM-enabled applications located in private networks without exposing the SCIM endpoint to the Internet.
We would like to understand whether the IFS Cloud SCIM implementation supports this scenario.
Could you please confirm the following:
- Does IFS Cloud support SCIM provisioning through the Microsoft Entra Provisioning Agent (On-Premises SCIM Application)?
- Are there any known limitations or unsupported features when using the Microsoft Entra Provisioning Agent instead of a publicly accessible SCIM endpoint?
- Have other IFS Cloud customers successfully implemented Microsoft Entra provisioning via the Provisioning Agent?
- Does the IFS SCIM endpoint require a publicly resolvable URL, or can a private DNS name and private IP endpoint be used when connectivity is provided through the Provisioning Agent?
- Are there any IFS-specific recommendations or best practices for securely implementing Microsoft Entra SCIM provisioning in a multi-tenant Azure environment?
Our goal is to avoid exposing the IFS SCIM endpoint to the public Internet if possible and instead use a private connectivity model.
Thank you for your support.
Kind regards,
Marion Erlebach