Search Results :

×

How to Configure Azure AD User Provisioning (SCIM) in TYPO3

The System for Cross-domain Identity Management (SCIM) is an open-standard, HTTP-based protocol that automates user provisioning and identity management between Azure AD and TYPO3. With SCIM-based provisioning, users created, updated, or deleted in Azure AD are automatically synchronized with TYPO3, eliminating the need for manual user management. The miniOrange User Provisioning & Sync extension enables smooth Azure AD User Provisioning in TYPO3 using the SCIM standard. It also supports Single Sign-On (SSO), allowing users to log in to TYPO3 using their Azure AD credentials. The extension works with Azure AD and any Identity Provider (IdP) that supports SCIM, ensuring consistent user synchronization across systems.

  • Download miniOrange TYPO3 User Provisioning (SCIM) Free plugin zip from here.
  • Run the following commands on command prompt to enable the plugin
  • composer require miniorange/scim
    php vendor/bin/typo3 upgrade:run
    php vendor/bin/typo3 cache:flush
  • Navigate to the SCIM Configuration tab to find the SCIM Base URL and SCIM Bearer Token, which you will keep handy.
TYPO3 User Provisioning | SCIM Configuration Azure AD (Microsoft Entra ID) TYPO3 User Provisioning- Admin Portal
  • Navigate to your Azure Active Directory (Microsoft Entra ID) tenant. From the left-hand menu under the Manage section, click Enterprise applications.
Azure AD (Microsoft Entra ID) TYPO3 User Provisioning- Enterprise applications
  • In the Enterprise Applications page, click the + New application button located at the top of the page.
Azure AD TYPO3 User Provisioning - New Application
  • On the Browse Azure AD Gallery page, click Create your own application. In the panel that opens:
  • Enter a name for your application, such as TYPO3 SCIM Provisioning or TYPO3 SSO.
  • Select Integrate any other application you don't find in the gallery (Non-gallery). This option is used when your application is not available in the Azure AD application gallery and needs to be configured manually.
  • Click Create to add the application.
TYPO3 User Provisioning - Azure AD Create your own application
  • Select the Provisioning tab from the left side menu bar and click the Get started button.
TYPO3 User Provisioning - Provisioning tab
  • Select the Provisioning Mode as Automatic.
  • Paste the Base URL into the Tenant URL field and the Bearer token into the Secret Token field from step 1.
  • Click on the Test Connection button.
Azure AD SCIM TYPO3- Provisioning Mode
  • If the connection is established, it will show a success message.
TYPO3 User Provisioning and Sync -Azure AD Show success message
  • Click on the Save button.
  • Then, go to the Users and Groups menu and add Users that you want to provision into your application.
  • Now, again open the Provisioning menu and set the Provisioning status to On.
TYPO3 Microsoft Azure AD User Provisioning and Sync
  • Select the Scope as per your requirements and click on the Save button.
  • Congratulations, you have successfully configured the miniOrange TYPO3 User Provisioning and Sync extension with Azure Active Directory (AD).
  • In the Sync Configuration tab, configure how users from Azure AD are provisioned and synchronized with TYPO3.
  • Select the Provision Target as either Frontend Users (fe_users) or Backend Users (be_users) based on your requirements.
  • Enter the corresponding Storage Page ID (PID) where user records should be created in TYPO3.
  • Under Sync Actions, choose the operations you want to enable, such as Create Users, Update Users, Delete Users, and Disable/Deactivate Users.
  • Optionally, enable Delete Users upon Deactivation to permanently remove users from TYPO3 when they are deactivated or unassigned in Azure AD.
  • Once all settings are configured, click Save Configuration to apply the changes.
TYPO3 User Sync and Provisioning - Sync Configuration
  • In the Attribute Mapping tab, configure how SCIM attributes from your Identity Provider (IdP) are mapped to TYPO3 user fields.
  • Under Standard SCIM Attributes, review and map the default attributes such as Username, Email, First Name, Last Name, and Group/Role to their corresponding SCIM paths.
  • To map additional attributes for frontend users, click + Add Customer Attributes under Frontend Users — Custom Attributes and specify the TYPO3 field along with the corresponding SCIM attribute path.
  • To map additional attributes for backend users, click + Add Backend Attributes under Backend Users — Custom Attributes and define the required TYPO3 field and SCIM attribute mapping.
  • Verify that all attribute mappings accurately correspond to the attributes provided by your Identity Provider to ensure correct user provisioning and synchronization.
  • Once all mappings are configured, click Save Configuration to apply and store the attribute mapping settings.
TYPO3 User Sync and Provisioning - Sync Configuration
  • Backend Users – This section is used to map SCIM groups from your Identity Provider (IdP) to TYPO3 backend user groups. These mappings determine the backend permissions and administrative access assigned to provisioned users.
  • Update Backend Roles on Provisioning – Enable this option to automatically update a user's backend group assignments whenever the user is created or updated through SCIM provisioning.
  • Group Mapping Rules – Configure mappings between SCIM groups and TYPO3 backend groups. Users will automatically receive the corresponding backend group based on their SCIM group membership.
  • Frontend Users – This section allows you to map SCIM groups to TYPO3 frontend user groups. These mappings help manage access to protected pages, portals, and frontend content.
  • Update Frontend Roles on Provisioning – Enable this setting to automatically synchronize frontend group assignments whenever a user is provisioned or updated through SCIM.
  • Default Fallback Group – Select a frontend group that will be assigned if none of the configured mapping rules match the user's SCIM group information.
  • Group Mapping Rules – Define the relationship between SCIM groups and TYPO3 frontend groups. Matching users are automatically assigned to the appropriate frontend group during provisioning.
  • Mapped Group Example – In the configuration shown above, the SCIM group value sde-2 is mapped to the TYPO3 frontend group grp1. Users belonging to this SCIM group will automatically be assigned to the mapped TYPO3 group.
  • Save Configuration – After configuring the required mappings, click this button to save the settings and apply them during future provisioning operations.
TYPO3 User Sync and Provisioning - Sync Configuration

Please reach out to us at magentosupport@xecurify.com, and our team will assist you with setting up the Extension. Our team will help you to select the best suitable solution/plan as per your requirement.

ADFS_sso ×
Hello there!

Need Help? We are right here!

support