Explore documentation

Microsoft Azure / Entra ID SSO & SCIM Provisioning

This guide will help integrate Microsoft Azure with Better Stack for Single Sign-On (SSO) and System for Cross-domain Identity Management (SCIM) provisioning.

SSO Setup

Let's set up SSO for your organization using Microsoft Azure.

Steps

  1. Go to Single Sign-On Settings.
  2. Select Microsoft Azure from the list of providers.
  3. Log in to your Microsoft Azure account.
  4. Grant permissions to the Better Stack app.
  5. A flash message "Azure Single Sign-On was successfully connected." and you're all set!

Admin Access Required

You must be an admin to configure SSO or make any related changes in Better Stack.

SCIM User Provisioning

With Microsoft Azure SSO, you can also use the SCIM provisioning, which automates user management in Better Stack directly from Microsoft Azure.

Steps

  1. Go to Single Sign-On Settings → Provisioning → hit Enable provisioning button.
  2. Open the Better Stack Enterprise Application in your Azure account.
  3. Click Provisioning in the left menu.
  4. Select Automatic Provisioning Mode.
  5. Enter the Tenant URL: https://betterstack.com/scim/v2.
  6. Copy & Paste your Secret Token.
  7. Click Test Connection to ensure Azure can connect to Better Stack.
  8. Click Save.

Provisioning is now active. Users and teams will now be automatically pushed from Azure to Better Stack.

Group Provisioning

Pushing user groups from Azure to Better Stack will create corresponding teams in Better Stack. Deprovisioning a group from Azure will delete the respective team and its resources in Better Stack.

Caution

Ensure you don’t lose any critical data when deprovisioning.

Additional details

  • User Removal: Deactivating a user in Azure will remove them from Better Stack. If the user belongs to multiple organizations, they are only removed from your organization.
  • Reactivation: Reactivating a user in Azure will automatically re-add them to Better Stack.

After configuring provisioning, use Azure’s provisioning logs to monitor user synchronization status. Ensure that the provisioning cycle is healthy and troubleshoot any errors as needed.

For more detailed guidance, visit the Microsoft Entra SCIM provisioning tutorial.