Provision administrator accounts from Entra ID using SCIM
In this topic, you will learn how to create and manage Portnox™ Cloud administrator accounts in Microsoft Entra ID using SCIM.
SCIM (System for Cross-domain Identity Management) is an open standard protocol for managing user identities across applications. With SCIM, you create and manage Portnox Cloud administrator accounts in Entra ID. When you assign Entra ID users to the SCIM application, Portnox Cloud creates administrator accounts for these users. When you change the attributes of these users in Entra ID, Portnox Cloud updates their administrator accounts.
Create an application API integration in Portnox Cloud
In this section, you will create a SCIM application API integration in Portnox Cloud.
Create a new Entra ID enterprise application
In this section, you will access the Microsoft Azure administrative interface and use it to create a new Entra ID enterprise application for SCIM provisioning.
Connect the Entra ID application to Portnox Cloud
In this section, you will copy the values displayed by Portnox Cloud and paste them in the connectivity settings of the Entra ID application.
Map the administrator attributes
In this section, you will map the Entra ID attributes that set the repository and the role of each Portnox Cloud administrator account.
Portnox Cloud uses the following SCIM attributes:
| Target attribute | Purpose | Value | Result |
|---|---|---|---|
| userType | Sets the identity repository of the administrator account. Portnox Cloud uses this repository to authenticate the administrator at login. | Clear | Portnox Cloud repository |
| EntraId | Entra ID repository | ||
| Google Workspace repository | |||
| Okta | Okta repository | ||
| roles[primary eq "True"].value | Sets the administrator type. | FullAdmin | Administrator |
| ReadOnlyAdmin | Read-only Administrator | ||
| GuestAdmin | Guest Administrator | ||
| ReadOnlyGuestAdmin | Guest Administrator + Read-only |
Assign users and start provisioning
In this section, you will select the Entra ID users that become Portnox Cloud administrators and start the provisioning process.
Result: Portnox Cloud creates administrator accounts for the assigned users during the next provisioning cycle. The accounts show in the list.

Entra ID runs automatic provisioning cycles about every 40 minutes. New assignments and attribute changes reach Portnox Cloud during the next cycle. The first cycle after you start provisioning can take longer.
To provision a single user immediately, in the Azure tab, in the left-hand side menu of the application pane, click on the Provision on demand option. Then, select the user and click on the Provision button.


























