Skip to main content
Question

Support for Microsoft Entra Provisioning Agent with SCIM User Provisioning

  • September 7, 2026
  • 1 reply
  • 54 views

Forum|alt.badge.img+2

Hello IFS Team,

we are currently implementing Microsoft Entra ID (Azure AD) user and group provisioning for IFS Cloud using the SCIM interface.

Our environment is operated as a managed service in Microsoft Azure. Each customer has its own Microsoft Entra tenant, while the IFS Cloud environment is hosted in a separate managed Azure tenant operated by us.

During our design phase, we identified that the standard Microsoft Entra SCIM provisioning service typically requires the SCIM endpoint to be reachable by Microsoft's cloud-based provisioning service via public IP addresses. Microsoft also provides an alternative architecture based on the Microsoft Entra Provisioning Agent, which allows provisioning to SCIM-enabled applications located in private networks without exposing the SCIM endpoint to the Internet.

We would like to understand whether the IFS Cloud SCIM implementation supports this scenario.

Could you please confirm the following:

  1. Does IFS Cloud support SCIM provisioning through the Microsoft Entra Provisioning Agent (On-Premises SCIM Application)?
  2. Are there any known limitations or unsupported features when using the Microsoft Entra Provisioning Agent instead of a publicly accessible SCIM endpoint?
  3. Have other IFS Cloud customers successfully implemented Microsoft Entra provisioning via the Provisioning Agent?
  4. Does the IFS SCIM endpoint require a publicly resolvable URL, or can a private DNS name and private IP endpoint be used when connectivity is provided through the Provisioning Agent?
  5. Are there any IFS-specific recommendations or best practices for securely implementing Microsoft Entra SCIM provisioning in a multi-tenant Azure environment?

Our goal is to avoid exposing the IFS SCIM endpoint to the public Internet if possible and instead use a private connectivity model.

Thank you for your support.

Kind regards,

Marion Erlebach

1 reply

Forum|alt.badge.img+2
  • Author
  • Do Gooder (Partner)
  • October 9, 2026

Answer from IFS:

 

IFS Cloud implements the standard SCIM 2.0 protocol over REST and supports user and group provisioning through SCIM endpoints. Based on the standard SCIM implementation in IFS Cloud and Microsoft's documented architecture for the Microsoft Entra Provisioning Agent, we would expect the solution to be compatible with IFS Cloud SCIM provisioning.

You can find the SCIM configuration guidance in the IFS documentation:

https://docs.ifs.com/techdocs/26r1/030_administration/010_security/025_scim/010_scim_configuration_example/

1. Does IFS Cloud support SCIM provisioning through the Microsoft Entra Provisioning Agent (On-Premises SCIM Application)?

IFS Cloud supports the SCIM 2.0 standard for user and group provisioning. Based on the standard SCIM implementation in IFS Cloud and Microsoft's documented architecture, the Microsoft Entra Provisioning Agent appears to be compatible with IFS Cloud SCIM endpoints.

2. Are there any known limitations or unsupported features when using the Microsoft Entra Provisioning Agent?

We are not aware of any IFS-specific limitations or unsupported features related to the use of the Microsoft Entra Provisioning Agent. Standard SCIM functionality and configuration requirements remain unchanged.

3. Have other IFS Cloud customers successfully implemented Microsoft Entra provisioning via the Provisioning Agent?

We do not have visibility into other customers' specific implementations and therefore cannot confirm whether this architecture has been deployed elsewhere.

4. Does the IFS SCIM endpoint require a publicly resolvable URL?

The IFS SCIM implementation itself does not require a publicly accessible endpoint. A private DNS name or private IP endpoint may be used, provided the Microsoft Entra Provisioning Agent has network connectivity to reach the IFS SCIM endpoint.

5. Are there any IFS-specific recommendations or best practices?

We suggested:

• Following the standard IFS SCIM configuration documentation.
• Using a dedicated SCIM service user and SCIM Offline Token.
• Restricting access to the SCIM endpoint to authorized systems only.
• Validating connectivity, DNS resolution, certificates, and authentication before enabling provisioning.
• Testing the configuration in a non-production environment before production rollout.

Based on your objective of avoiding public Internet exposure, the Microsoft Entra Provisioning Agent appears to be a suitable approach for enabling private connectivity to the IFS SCIM endpoint.