How to set up SCIM provisioning with Vatix
SCIM provisioning is a paid add-on. If you're interested in enabling it, contact your Vatix account manager.
This guide walks you through connecting Microsoft Entra ID (formerly Azure Active Directory) to Vatix using SCIM (System for Cross-domain Identity Management). Once SCIM is configured, changes you make in Entra ID, such as adding new joiners, removing leavers, or updating user roles, are automatically synced to Vatix.
Note: This guide covers Microsoft Entra ID. If you use a different identity provider, raise a ticket with Vatix support at support@vatix.com or ask to be connected to a live agent in the chat window, and our team will provide tailored instructions.
Before you start
Before you begin, make sure you have:
- Administrator access to your Microsoft Entra ID tenant.
- SSO already configured with Vatix. SCIM provisioning builds on your existing SSO setup.
- SCIM credentials from Vatix. Your Vatix account manager will provide a Tenant URL (the SCIM endpoint) and a Secret Token (the access token for authentication).
If you haven't received your SCIM credentials yet, contact your Vatix account manager before proceeding.
Step 1: Create an Enterprise Application in Entra ID
You'll create a dedicated Enterprise Application that acts as the connector between Entra ID and Vatix.
- Log in to the Microsoft Entra admin centre.
- Go to 'Identity'.
- Select 'Applications'.
- Select 'Enterprise Applications'.
- Click 'New Application'.
- Select 'Create your own application'.
- Enter a name for the application, for example 'Vatix SCIM Provisioning'.
- Select 'Integrate any other application you don't find in the gallery (Non-gallery)'.
- Click 'Create'.
For more details, see Microsoft's documentation.
Step 2: Set up groups for roles and licences
Vatix uses your Entra ID groups to automatically assign roles and product licences to provisioned users. Set up the groups that will control access in Vatix before assigning users to the application.
How it works
Each Entra ID group that you assign to the Vatix application can be mapped to a Vatix role and a set of product licences. When a user is added to a group, they automatically receive the corresponding role and licences in Vatix.
Your Vatix account manager will work with you to configure the mapping between your Entra ID groups and Vatix roles and licences. To prepare, decide which groups should map to which Vatix access levels and share this mapping with your account manager.
Recommended group structure
Create dedicated security groups in Entra ID that correspond to how you want users to access Vatix.
For example:
| Entra ID Group | Vatix Role | Vatix Licences |
|---|---|---|
| Vatix - Account Owners | Account Owner | All product licences |
| Vatix - Managers | Manager | Events, Documents |
| Vatix - Standard Users | User | Events, Audits |
The exact group names and mappings are flexible. Use whatever naming convention works for your organisation. Groups don't need to map to both a role and licences. Either can be left empty.
For example, you might have one group that only assigns a role and separate groups that grant specific product licences. This gives you flexibility to manage roles and licences independently.
Creating groups in Entra ID
- In the Entra admin centre, go to 'Identity'.
- Select 'Groups'.
- Select 'All groups'.
- Click 'New group'.
- Set 'Group type' to 'Security'.
- Enter a name, for example 'Vatix - Managers'.
- Add the relevant users as members.
- Click 'Create'.
- Repeat for each access level you need.
Tip: If you have Entra ID P1 or P2 licences, consider using dynamic membership rules to automatically add users to groups based on attributes. Group membership stays up to date without manual management.
Key things to know about group-based access
- Users in multiple groups receive the union of all licences from their groups and are assigned the highest role among them. For example, a user in both 'Vatix - Managers' and 'Vatix - Standard Users' would get the Manager role plus all licences from both groups.
- Removing a user from a group doesn't immediately revoke permissions. Changes are applied during the next provisioning sync cycle, at which point Vatix evaluates all of the user's current group memberships to determine their correct role and licences.
- Users who are not in any mapped groups default to the basic User role with no product licences.
- Removing a user from all groups revokes their elevated role and licences, reverting them to the baseline.
- Deactivating a user in Entra ID removes their access and licences in Vatix entirely, regardless of group membership.
Share your mapping with Vatix
Once your groups are ready, provide your Vatix account manager with a mapping table listing each group name and the Vatix role and licences it should grant. Your account manager will configure this on the Vatix side once provisioning is active and the groups have synced.
Note: Until the mapping is configured, no changes will be made to your users' existing roles or licences.
Step 3: Assign users and groups to the application
Only users and groups assigned to the Enterprise Application will be synchronised with Vatix. This gives you full control over which users are provisioned.
- In your Enterprise Application, go to 'Users and groups'.
- Click 'Add user/group'.
- Select the groups you created in Step 2 (and any individual users) to provision to Vatix.
- Click 'Assign'.
Note: Assigning a group to the application provisions all members of that group. Make sure your group memberships are correct before starting provisioning.
Step 4: Configure the provisioning connection
This is where you connect Entra ID to Vatix using the SCIM credentials provided by your Vatix account manager.
- In the Enterprise Application, go to 'Provisioning'.
- Click 'Get started' (or 'Edit provisioning' if provisioning has been opened before).
- Set 'Provisioning Mode' to 'Automatic'.
- Under 'Admin Credentials', paste the SCIM endpoint URL provided by Vatix into the 'Tenant URL' field.
- Paste the access token provided by Vatix into the 'Secret Token' field.
- Click 'Test Connection' to verify that Entra ID can connect to the Vatix SCIM endpoint. You should see a confirmation that the credentials are authorised.
- Click 'Save'.
Step 5: Start provisioning
Once the connection is verified, you're ready to begin synchronising users.
- Still in the 'Provisioning' section, set the 'Provisioning Status' toggle to 'On'.
- Click 'Save'.
Entra ID will now run an initial provisioning cycle, synchronising all assigned users and groups to Vatix. After the initial cycle, Entra ID automatically syncs changes approximately every 40 minutes.
Tip: To sync a user immediately, use the 'Provision on demand' feature in Entra ID to push individual user changes to Vatix without waiting for the next automatic cycle. Go to 'Provisioning', then select 'Provision on demand', search for the user, and click 'Provision'.
What happens next
Once provisioning is active:
- New users assigned to the application are automatically created in Vatix with the role and licences determined by their group membership.
- Group membership changes are synchronised during the next provisioning cycle. Adding a user to a mapped group grants them the corresponding role and licences. Removing a user from a group triggers a full re-evaluation of their access based on their remaining group memberships.
- Updated user details, such as name, email address and phone number, are kept in sync automatically. To bring across more details, see 'Syncing employee details from your directory' below.
- Deactivated or unassigned users are deprovisioned from Vatix, and their licences are released.
Your Vatix account manager will confirm that provisioning is working correctly and that your group-to-role mappings are applied as expected.
Syncing employee details from your directory
Alongside roles and licences, you can have a wider set of employee details come across from your directory, so they stay right in Vatix without anyone maintaining them by hand:
- Job title
- Department
- Cost centre
- Line manager
- Country
- Employee ID
- Employment type
- Region
- Site
- Start date
- Up to five details of your own
Each detail you choose is mapped to an attribute in your directory. Once mapped, your directory owns it: the value in Vatix follows the one in your directory on the next provisioning cycle, in the same way email address, phone number and role already do.
This also keeps dynamic Groups accurate, because a dynamic Group's membership rule is built from most of these same details. Someone moves department in your directory and they move between Groups at the same time. See 'How to set up a dynamic Group with membership rules'.
How to set it up
- Decide which of the details above you want to bring across from your directory.
- Check with whoever looks after your identity provider that each one exists there as an attribute. Job title, department, cost centre, line manager, country, employee ID and employment type map to standard attributes. Region, site, start date and your own details are defined as custom attributes first.
- Send that list to your Vatix account manager, or to support@vatix.com, and we configure the mapping for you.
Note: A detail that comes from your directory is shown in Vatix but can't be edited there, so that the two never disagree. To change it, change it in your directory. Only the details you map work this way, so everything else on the user record stays editable in Vatix, and a detail taken back out of the mapping becomes editable again.
If a value arrives that matches none of the options your organisation has set up, for Department, Region, Employment type or Site, or a line manager we can't match to a Vatix user, no new option is created and the person keeps the value they already had. The value that couldn't be matched is shown on their record, so you can add the option on the 'User Fields' page or ask us to correct the mapping. See 'How to manage user fields'.
Troubleshooting
| Issue | What to do |
|---|---|
| Testing connection fails | Double-check the Tenant URL and Secret Token. Make sure there are no trailing spaces. If the problem persists, contact your Vatix account manager to verify the credentials. |
| Users not appearing in Vatix | Confirm the users are assigned to the Enterprise Application. Check the 'Provisioning logs' in Entra ID for errors. |
| Sync is slow | Entra ID syncs approximately every 40 minutes. Use 'Provision on demand' for immediate updates. |
| User has wrong role or licences | Check the user's group membership in Entra ID. Roles and licences are determined by group mappings. Contact your Vatix account manager if the mapping needs to be adjusted. |
| Error in provisioning logs | Share the error details with your Vatix account manager for investigation. |
If you run into any issues or have questions about the setup process, contact your Vatix account manager or reach out to the Vatix support team at support@vatix.com or ask to be connected to a live agent in the chat window.