Setting up SCIM with Azure Active Directory

Setting up SCIM with Azure Active Directory

Step 3. Integrate the provisioning app with Informatica Intelligent Cloud Services

Step 3. Integrate the provisioning app with Informatica Intelligent Cloud Services

To integrate the provisioning app with
Informatica Intelligent Cloud Services
, configure the provisioning mode, map the required attributes, and create the app roles.
  1. In Azure AD, open the provisioning app and select
    Manage
    Provisioning
    .
  2. Set the
    Provisioning Mode
    to
    Automatic
    .
  3. In the Admin Credentials area, enter the tenant URL, for example,
    https://dm-us.informaticacloud.com/scim-service
    , and paste the SCIM token that you generated when you enabled SCIM in
    Informatica Intelligent Cloud Services
    .
  4. Click
    Test Connection
    and verify that the connection is successful.
  5. In the Mappings area, click
    Azure Active Directory Users
    and map only the following attributes:
    • externalId
    • username
    • displayName
    • title
    • preferredLanguage
    • locale
    • timezone
    • active
    • addresses[type eq "work"].streetAddress
    • addresses[type eq "work"].locality
    • addresses[type eq "work"].region
    • addresses[type eq "work"].postalCode
    • addresses[type eq "work"].country
    • roles
    • employeeNumber
    • organization
    • department
    • emails[type eq "work"]
    • givenName
    • familyName
    • phoneNumbers[type eq "work"]
    The roles attribute must support multiple values.
    The following images show some constant attributes:
  6. If you use role-based access control, add an expression for app roles to pass the roles to
    Informatica Intelligent Cloud Services
    .
  7. In the Settings area, set the scope to
    Sync only assigned users and groups
    .
    Do not set the scope to
    Sync all
    or the SAML response will contain no roles, and users won't be able to sign on to
    Informatica Intelligent Cloud Services
    .
  8. Select
    Manage
    App roles
    and create the app roles that you are mapping on the
    SAML Setup
    page in
    Administrator
    .
    If you don't see this option, contact Microsoft Azure technical support.
  9. If you want to provision groups, create a dummy role, but do not map this role on the
    SAML Setup
    page in
    Administrator
    .
    This role is only used for assigning groups to the provisioning app.
    You need to create the dummy role because a role is required for group provisioning. The dummy role is not used in
    Informatica Intelligent Cloud Services
    . Group to role mapping in
    Informatica Intelligent Cloud Services
    is based on the group external ID on the
    SAML Setup
    page.
  10. Save the configuration.

0 COMMENTS

We’d like to hear from you!