Nametag Docs
Get help Launch Nametag
SCIM Entra ID

SCIM provisioning with Microsoft Entra ID

Configure Microsoft Entra ID to provision a Nametag directory over SCIM 2.0

Beta: SCIM provisioning is in beta and is enabled per organization. Report any issues to help@nametag.co.

This guide configures an enterprise application in Microsoft Entra ID to provision users and groups to Nametag. It picks up where SCIM provisioning leaves off and covers what Nametag requires; for the Entra controls themselves, follow the Microsoft documentation linked in each step.

Before you begin

  • Complete the Nametag-side setup in SCIM provisioning: enable SCIM on your Entra ID directory and gather the SCIM endpoint URL, Directory ID, and Admin API key.
  • You need permission to manage enterprise applications and provisioning in your Entra tenant.
  • Keep the connection configured in Entra ID account recovery. SCIM supplies accounts and groups; Nametag still uses that connection to perform recovery operations.

Step 1 — Add the enterprise application

Create a non-gallery enterprise application (Integrate any other application you don’t find in the gallery) and give it a name you’ll recognize, such as Nametag. See the Microsoft SCIM integration guide.

Step 2 — Connect to Nametag

In the application’s provisioning settings, choose automatic provisioning and enter:

Field Value
Tenant URL https://nametag.co/scim/v2
Secret Token <directory-id>:<admin-api-key>

The secret token is your Directory ID and Admin API key joined by a colon, without a Bearer prefix. Test the connection and save, but leave provisioning off until you’ve reviewed the mappings in Step 3. See the Microsoft provisioning configuration guide.

Step 3 — Review the attribute mappings

Do this before provisioning any user, including with Provision on demand. Nametag needs two settings in the user mapping; the other Entra defaults can stay:

  • Map objectId to externalId. Don’t rely on the default mapping. Nametag uses this value to identify the user in Entra during recovery and to match accounts previously imported through pull provisioning. It is fixed when the account is created: correcting the mapping later does not repair accounts already provisioned. If that has happened, stop provisioning and contact help@nametag.co.
  • Match users on userName only. Nametag looks users up by userName; any other matching attribute makes provisioning fail with 501 Not Implemented.

Keep the default Entra active mapping so that users Entra deprovisions are deactivated in Nametag. The attributes Nametag reads are listed under user attributes. See the Microsoft attribute mapping guide.

Step 4 — Assign users and groups

Assign the users and groups to provision to the application, following the Microsoft assignment guide. Nametag records a group’s memberships only for users provisioned into the same directory.

Warning: Every group you assign needs a display name that no other assigned group shares, ignoring case. Entra ID allows duplicate group names but matches groups to Nametag by display name, so a second group with an existing name can be linked to the group already provisioned in Nametag, and its members added to it, without any error. Recovery policy rules that name that group would then apply to the members of both Entra groups. Rename duplicate groups before assigning them.

When a provisioned group is deleted, Nametag removes the recovery policy rules that name it. See groups used in recovery policies.

Step 5 — Verify and start provisioning

  1. Provision a test user on demand. Confirm that the account appears in your Nametag directory and that its externalId is the user’s Entra object ID.
  2. Run a Nametag recovery operation for the test user to confirm the recovery identifier.
  3. Start provisioning and follow the first cycle in the Entra provisioning logs.

See the Microsoft on-demand provisioning guide.

Switching an existing directory from pull provisioning

Confirm the objectId to externalId mapping before the first user is sent. Nametag uses it to match incoming users to existing accounts and keep their identity bindings. If your directory uses custom account mapping, check the identifier with your Nametag representative first.

Switching clears group-based recovery policy rules. Reconfigure them once Entra has provisioned the groups. See groups used in recovery policies.

Optional: Map a birthdate

To use birthdates during identity verification, add a custom target attribute of type String with this name to the user mapping, and map the Entra attribute that holds the birthdate to it:

urn:ietf:params:scim:schemas:extension:nametag:2.0:User:birthDate

See the Microsoft custom SCIM attribute instructions. Nametag accepts a date in YYYY-MM-DD format or a supported hash; see Birth date hashes.