Search Results :

×

Setup User Provisioning (SCIM) into Drupal with Azure AD


User Provisioning provides you with the ability to manage all the users at a central user management identity. Azure AD Provisioning service supports SCIM 2.0 protocol for automatic provisioning/de-provisioning. miniOrange User Provisioning and Sync module implement the SCIM endpoints to allow provisioning/de-provisioning of users into the Drupal site as and when any CRUD operation is performed in the central identity i.e. Azure AD.

Installation Steps


  • Download the module:
    composer require 'drupal/user_provisioning'
  • Navigate to Extend menu on your Drupal admin console and search for miniOrange User Provisioning using the search box.
  • Enable the module by checking the checkbox and click on Install button.
  • Configure the module at
    {BaseURL}/admin/config/people/user_provisioning/overview
  • Install the module:
    drush en user_provisioning
  • Clear the cache:
     drush cr
  • Configure the module at
    {BaseURL}/admin/config/people/user_provisioning/overview
  • Navigate to Extend menu on your Drupal admin console and click on Install new module button.
  • Install the Drupal User Provisioning and Sync module either by downloading the zip or from the URL of the package (tar/zip).
  • Click on Enable newly added modules.
  • Enable this module by checking the checkbox and click on Install button.
  • Configure the module at
    {BaseURL}/admin/config/people/user_provisioning/overview

Configure Drupal as SCIM Server:

  • Once the module is installed, navigate to the Configuration tab of the Drupal site and select miniOrange User Provisioning.
  • miniOrang User Provisioning and Sync module installation steps
  • Navigate to the User Provisioning tab of the module and click on the Configure button under the Changes from Provider to Drupal (SCIM Server) section.
  • Azure-AD-click-on-configure-button

Create an Enterprise Application in Azure AD:

  • Log into the Azure Portal.
  • Select Enterprise application under Azure Services.
  • Azure-AD-select-enterprise-application
  • Click on the New application.
  • Azure-AD-Click-Add_application
  • Click on the Create your own application in Browse Azure AD Gallery.
  • centrify-saml-single-sign-on-provide-the-required-information
  • Enter the application name in What's the name of your app?
  • Under What are you looking to do with your application?, select Integrate any other application you don't find in the gallery (Non-gallery) and click on the Create button.
  • Azure-AD-Enter-Application-Name

Configure Azure AD as SCIM Client:

  • Click on the Provision User Accounts.
  • Azure-AD-select-provisioning
  • Click on the Get Started button.
  • Azure-AD-click-get-started
  • Select Provisioning mode as Automatic.
  • zure-AD-select-provisioning-automatic
  • Navigate to the Drupal site.
  • Under Configure Drupal as a SCIM Server section, copy the SCIM Base URL.
  • /Azure-AD-copy-scim-base-url
  • Navigate back to the Azure AD portal and paste the copied SCIM Base URL under the Tenant URL text field.
  • Azure-AD-enter-scim-base-url
  • Navigate to the Drupal site and copy the SCIM Bearer Token.
  • Azure-AD-copy-SCIM-bearer-token
  • Navigate back to the Azure AD portal and paste the copied SCIM Bearer Token under the Secret Token text field.
  • Azure-AD-enter-SCIM-bearer-token
  • Click on the Test Connection button to establish the connection between Azure AD and Drupal.
  • If the connection is successful, a success message will pop up in the top right corner.
  • Azure-AD-test-connection
  • Once the connection is successful, click on the Save button.
  • Azure-AD-click-save-button
  • Navigate to the Provisioning tab from the left navigation panel and scroll down to the Settings section.
  • Under the Settings section, select Sync only assigned users and groups in the Scope dropdown.
  • Azure-AD-select-only-assigned-users
  • Toggle the Provisioning status button to On and click on the Save button.
  • Azure-AD-Provisioning-status-on

Assign users to the Application:

  • Navigate to the Overview tab in the Azure AD application and select Assign users and groups.
  • Azure-AD-click-assign-users
  • Click on the Add users/group.
  • Azure-AD-click-add-users-group
  • Click on the None Selected link under the Users. Search for the user(s) to assign.
  • Azure-AD-search-for-the-user-to-be-assigned
  • Select the user(s) and click on the Select button.
  • Azure-AD-select-user-to-assign
  • Click on the Assign button.
  • Azure-AD-user-selected-to-assigned
  • The user has been successfully assigned.
  • Azure-AD-user-successfully-assigned

On-Demand Provisioning:

  • Navigate to the Provisioning section of the Azure AD Application and select Provision on demand.
  • Azure-AD-click-provisioning-on-demand
  • Search for the user to provision.
  • Azure-AD-search-for-the-user-to-provision
  • Select the user and click on the Provision button.
  • Azure-AD-click-provision-button
  • If the user is successfully provisioned, the following screen will be shown:
  • Azure-AD-user-provisioned
  • Let’s check if the user is provisioned to the Drupal site. Navigate to the Drupal site and navigate to the People tab from the top navigation panel. As per the following screenshot, the user has been successfully created on the Drupal site.
  • Azure-AD-User-Created

Congratulations, you have successfully set up Drupal as the SCIM server and Azure AD as the SCIM client.

If the Provision was not successful, please contact us at drupalsupport@xecurify.com. Please send the screenshot of the error window, and we will assist you in resolving the issue and guiding you through the setup.

Additional Features:

 Case Studies
miniOrange has successfully catered to the use cases of 400+ trusted customers with its highly flexible/customizable Drupal solutions. Feel free to check out some of our unique case studies using this link.
 Other Solutions
Feel free to explore other Drupal solutions that we offer here. The popular solutions used by our trusted customers include 2FA, SSO, Website Security. 
  24*7 Active Support
The Drupal developers at miniOrange offer quick and active support for your queries. We can assist you from choosing the best solution for your use case to deploying and maintaining the solution.
Hello there!

Need Help? We are right here!

support
Contact miniOrange Support
success

Thanks for your inquiry.

If you dont hear from us within 24 hours, please feel free to send a follow up email to info@xecurify.com