{"id":5164,"date":"2024-09-25T08:49:14","date_gmt":"2024-09-25T15:49:14","guid":{"rendered":"https:\/\/SUMMALAI.COM\/?p=5164"},"modified":"2024-09-25T08:49:16","modified_gmt":"2024-09-25T15:49:16","slug":"how-to-configure-knowbe4-with-microsoft-entra-id-formerly-azure-active-directory","status":"publish","type":"post","link":"https:\/\/SUMMALAI.COM\/?p=5164","title":{"rendered":"How to Configure KnowBe4 with Microsoft Entra ID (Formerly Azure Active Directory)"},"content":{"rendered":"\n<p>In this article, you&#8217;ll learn how to configure SCIM with Microsoft Entra ID (formerly Azure Active Directory). Configuring SCIM for Microsoft Entra ID will allow you to add and manage users and groups in your KSAT console using Microsoft Entra ID.<\/p>\n\n\n\n<p>The instructions in this article are for third-party software. If you experience issues with user provisioning in Microsoft Entra ID, we recommend reaching out to Microsoft Entra for specific instructions. You can also&nbsp;<a href=\"https:\/\/support.knowbe4.com\/hc\/en-us\/requests\/new\" target=\"_blank\" rel=\"noreferrer noopener\">contact our support team<\/a>&nbsp;and we will be happy to assist you.&nbsp;&nbsp;<\/p>\n\n\n\n<p><strong>Note:<\/strong>To sync users and groups with SCIM, you must have a Microsoft Entra subscription. For more information about syncing users and groups through Microsoft Entra, see Microsoft&#8217;s&nbsp;<a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/manage-apps\/assign-user-or-group-access-portal\" target=\"_blank\" rel=\"noreferrer noopener\">Assign users and groups to an application<\/a>&nbsp;article.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h_01HASXESAXS4KED0BRGGK1TA0D\">Configuring SCIM<a href=\"https:\/\/support.knowbe4.com\/hc\/en-us\/articles\/360053851814-Configure-SCIM-for-Microsoft-Entra-ID#h_01HASXESAXS4KED0BRGGK1TA0D\"><\/a><\/h2>\n\n\n\n<p>In this section, you&#8217;ll learn how to configure your SCIM settings with Microsoft Entra. Please note that you should configure these steps after you&#8217;ve configured your settings in your KSAT console. For more information about configuring SCIM in your KSAT console, see our&nbsp;<a href=\"https:\/\/support.knowbe4.com\/hc\/en-us\/articles\/360052380374\">SCIM Configuration Guide<\/a>.<\/p>\n\n\n\n<p>To configure your SCIM settings with Microsoft Entra, follow the steps below:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Log in to your Microsoft Entra portal and navigate to&nbsp;<strong>Microsoft Entra ID<\/strong>.<a><\/a><\/li>\n\n\n\n<li>From the&nbsp;<strong>Applications&nbsp;<\/strong>drop-down menu, click&nbsp;<strong>Enterprise applications.<\/strong><a><\/a><\/li>\n\n\n\n<li>Click&nbsp;<strong>+<\/strong>&nbsp;<strong>New application<\/strong>.<a><\/a><\/li>\n\n\n\n<li>In the search bar, enter &#8220;KnowBe4&#8221; to filter your results.&nbsp;<\/li>\n\n\n\n<li>Click the&nbsp;<strong>KnowBe4 Security Awareness Training<\/strong>&nbsp;tile.&nbsp;&nbsp;<a><\/a><\/li>\n\n\n\n<li>Then, click&nbsp;<strong>Create<\/strong>. After you click&nbsp;<strong>Create<\/strong>, you&#8217;ll be redirected to the&nbsp;<strong>Overview<\/strong>&nbsp;page for the application that you created. If you are not directed to the&nbsp;<strong>Overview<\/strong>&nbsp;page, you&#8217;ll need to open the application from the list of&nbsp;<strong>Enterprise applications<\/strong>.<\/li>\n\n\n\n<li>Select the&nbsp;<strong>Provisioning<\/strong>&nbsp;tab from the menu on the left side of the page.<\/li>\n\n\n\n<li>Click&nbsp;<strong>Get started<\/strong>.<a><\/a><\/li>\n\n\n\n<li>Click the&nbsp;<strong>Provisioning Mode<\/strong>&nbsp;drop-down menu, and then select&nbsp;<strong>Automatic<\/strong>.<a><\/a><\/li>\n\n\n\n<li>Next, you&#8217;ll need to enter the information from your&nbsp;<strong>Account Settings<\/strong>&nbsp;page. For more information about where you can find this information, see our&nbsp;<a href=\"https:\/\/support.knowbe4.com\/hc\/en-us\/articles\/360052380374\">SCIM Configuration Guide<\/a>. In the&nbsp;<strong>Tenant URL<\/strong>&nbsp;field, enter the&nbsp;<strong>Tenant URL<\/strong>, and in the&nbsp;<strong>Secret Token<\/strong>&nbsp;field, enter the&nbsp;<strong>SCIM Token<\/strong>.&nbsp;<strong>Important:<\/strong>This feature does not currently work with on-demand provisioning.<\/li>\n\n\n\n<li>After you\u2019ve entered your information, click the&nbsp;<strong>Test Connection<\/strong>&nbsp;button. Clicking this button will allow you to ensure that you entered the correct information. If the connection is successful, a success banner will display at the top-right corner of your screen.<a><\/a><\/li>\n\n\n\n<li>Click the&nbsp;<strong>Save<\/strong>&nbsp;button at the top of the screen.<\/li>\n<\/ol>\n\n\n\n<p>Next, you&#8217;ll need to define which users and groups you would like Microsoft Entra ID to sync with your KSAT console.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h_01HASXESAXRZ58E2ST0FHR7CXA\">Defining Which Users and Groups to Sync from Microsoft Entra<a href=\"https:\/\/support.knowbe4.com\/hc\/en-us\/articles\/360053851814-Configure-SCIM-for-Microsoft-Entra-ID#h_01HASXESAXRZ58E2ST0FHR7CXA\"><\/a><\/h2>\n\n\n\n<p>After completing the steps in the&nbsp;<a href=\"https:\/\/support.knowbe4.com\/hc\/en-us\/articles\/360053851814-Configure-SCIM-for-Microsoft-Entra-ID#CONFIG\">Configuring SCIM<\/a>&nbsp;section above, you can decide which users and groups you would like to sync. This configuration is required in order to sync users and groups from your identity provider (IdP).<\/p>\n\n\n\n<p><strong>Note:<\/strong>The instructions in this section are for defining specific users and groups to sync. If you would like to sync all your users and groups from Microsoft Entra ID, see the&nbsp;<a href=\"https:\/\/support.knowbe4.com\/hc\/en-us\/articles\/360053851814-Configure-SCIM-for-Microsoft-Entra-ID#FAQ\">Frequently Asked Questions (FAQ)<\/a>&nbsp;section of this article.<\/p>\n\n\n\n<p><strong>Important:<\/strong>Nested groups are not currently supported by SCIM and Microsoft Entra ID provisioning. For more information, see the Scoping section of Microsoft\u2019s&nbsp;<a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/active-directory\/app-provisioning\/how-provisioning-works\">How Application Provisioning works in Azure Active Directory<\/a>&nbsp;article.<\/p>\n\n\n\n<p>To define which users and groups you would like to sync from Microsoft Entra ID, follow the steps below:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>From your&nbsp;<strong>Microsoft Entra ID<\/strong>, navigate to&nbsp;<strong>Enterprise applications.<\/strong><\/li>\n\n\n\n<li>Select the application you created for your KnowBe4 connection.<\/li>\n\n\n\n<li>Click&nbsp;<strong>Users and groups<\/strong>&nbsp;from the menu on the left side of the page.<a><\/a><\/li>\n\n\n\n<li>Click&nbsp;<strong>Add user\/group<\/strong>&nbsp;to select the users or groups that you would like to sync.<\/li>\n\n\n\n<li>Click&nbsp;<strong>Users and groups<\/strong>&nbsp;to search for users or groups that you would like to include in your sync. To add a user or group, click on the name of the user or group. They will now show in the&nbsp;<strong>Selected items<\/strong>&nbsp;category.<strong>Note:<\/strong>We recommend that you only include a few users when you first configure your settings. Starting with a few users allows you to ensure that the connection works properly before you add all the users and groups that you want to include.<a><\/a><\/li>\n\n\n\n<li>After you\u2019ve added the users and groups you want to include to the&nbsp;<strong>Selected items<\/strong>&nbsp;category, click<strong>&nbsp;Select<\/strong>.<\/li>\n\n\n\n<li>Click&nbsp;<strong>Assign<\/strong>.<\/li>\n<\/ol>\n\n\n\n<p>The users and groups that you selected will now display in the table.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h_01HASXESAXTB2BVG04PY91GYQ3\">Starting Your Sync<a href=\"https:\/\/support.knowbe4.com\/hc\/en-us\/articles\/360053851814-Configure-SCIM-for-Microsoft-Entra-ID#h_01HASXESAXTB2BVG04PY91GYQ3\"><\/a><\/h2>\n\n\n\n<p>After you have configured SCIM and have added the users and groups that you want to sync, you&#8217;ll need to start the sync. Once you start the sync, the system will automatically check for changes to your users and groups in Microsoft Entra ID every 40 minutes and will initiate a sync if changes were made.<\/p>\n\n\n\n<p><strong>Note:<\/strong>If you have more than several thousand users in your SCIM provisioning application, it\u2019s likely all of your users won&#8217;t be included in your initial sync. Instead, the users will be synced to your account in stages. We recommend that you keep user provisioning in&nbsp;<strong>Test Mode<\/strong>&nbsp;until you see only a few changes between your sync reports. Waiting until you only see a few changes helps prevents users from being archived in your KSAT console. Additionally, syncing group memberships can take longer than syncing users. If you have a larger account, you can expect to see periodic syncs in your KSAT console.<\/p>\n\n\n\n<p>To start your sync, follow the steps below:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>From your Microsoft Entra ID, navigate to&nbsp;<strong>Enterprise applications<\/strong>.<\/li>\n\n\n\n<li>Select the application that you created for your KnowBe4 connection.<\/li>\n\n\n\n<li>From the menu on the left side of the page, select&nbsp;<strong>Provisioning<\/strong>.<\/li>\n\n\n\n<li>Click&nbsp;<strong>Start provisioning<\/strong>.<a><\/a><\/li>\n<\/ol>\n\n\n\n<p>The sync will be initiated immediately. After your initial sync, the system will check for changes to your Microsoft Entra ID every 40 minutes and will initiate a sync if changes were made.<\/p>\n\n\n\n<p><strong>Important:<\/strong>Once you are satisfied that your users have synced correctly, you\u2019ll need to turn off&nbsp;<strong>Test Mode<\/strong>&nbsp;in your KSAT&nbsp;<strong>Account Settings<\/strong>. Turning off Test Mode will allow users to be added and archived during the next sync. For more information about Test Mode, see our&nbsp;<a href=\"https:\/\/support.knowbe4.com\/hc\/en-us\/articles\/360052380374#CONFIG\">SCIM Configuration Guide<\/a>.<\/p>\n\n\n\n<p>To see the status of these syncs as well as any errors and additional information about your syncs, navigate to&nbsp;<strong>Users<\/strong>&nbsp;&gt;&nbsp;<strong>Provisioning<\/strong>&nbsp;in your KSAT console.<a><\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h_01HASXESAXMA2MVVBSYRXQHF4F\">Advanced Configuration Options<a href=\"https:\/\/support.knowbe4.com\/hc\/en-us\/articles\/360053851814-Configure-SCIM-for-Microsoft-Entra-ID#h_01HASXESAXMA2MVVBSYRXQHF4F\"><\/a><\/h2>\n\n\n\n<p><strong>Note:&nbsp;<\/strong>Location, Phone Number, and Mobile Number fields are not configured by default. To configure these, please follow the instructions in our&nbsp;<a href=\"https:\/\/support.knowbe4.com\/hc\/en-us\/articles\/4404994263699-Update-SCIM-from-a-Legacy-Version#h_01HER2C82HX8DNKXCJ4BBMRT6A\">Update SCIM from a Legacy Version<\/a>&nbsp;article.<\/p>\n\n\n\n<p>By enabling SCIM, the fields in your identity provider are automatically connected to the corresponding fields in your KSAT console. If you want to change the default mapping or add custom fields, you have the option to update these fields in Microsoft Entra.<\/p>\n\n\n\n<p><strong>Important:<\/strong><strong>Email aliases<\/strong>&nbsp;are not currently supported by SCIM provisioning.<\/p>\n\n\n\n<p>To learn more about advanced configuration options for Microsoft Entra, see the subsections below:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h_01G52DA9MJBCN3S1JN7X0JBNFA\">Default Mappings<\/h3>\n\n\n\n<p>The default field mappings are shown below:<\/p>\n\n\n\n<p><a href=\"https:\/\/support.knowbe4.com\/hc\/en-us\/articles\/360053851814-Configure-SCIM-for-Microsoft-Entra-ID#zp-1-0\">Supported Fields<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/support.knowbe4.com\/hc\/en-us\/articles\/360053851814-Configure-SCIM-for-Microsoft-Entra-ID#zp-1-1\">Unsupported Fields<\/a><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Default Azure Active Directory Attribute<\/th><th>KSAT Attribute<\/th><th>KSAT Field<\/th><\/tr><\/thead><tbody><tr><td>userPrincipalName<\/td><td>userName<\/td><td>Email<\/td><\/tr><tr><td>givenName<\/td><td>name.givenName<\/td><td>First Name<\/td><\/tr><tr><td>surname<\/td><td>name.familyName<\/td><td>Last Name<\/td><\/tr><tr><td>employeeId<\/td><td>urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:employeeNumber<\/td><td>Employee Number<\/td><\/tr><tr><td>jobTitle<\/td><td>title<\/td><td>Job Title<\/td><\/tr><tr><td>companyName<\/td><td>urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:organization<\/td><td>Organization<\/td><\/tr><tr><td>department<\/td><td>urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:department<\/td><td>Department<\/td><\/tr><tr><td>manager<\/td><td>urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:manager.value<strong>Note:<\/strong>For manager information to sync, the applicable managers must be included in the sync. To add these managers to the sync, see the&nbsp;<a href=\"https:\/\/support.knowbe4.com\/hc\/en-us\/articles\/360053851814-Configure-SCIM-for-Microsoft-Entra-ID#DEFINE\">Defining Which Users and Groups to Sync from Microsoft Entra<\/a>&nbsp;section above.<\/td><td>Manager Email<\/td><\/tr><tr><td>displayName from the manager&#8217;s Entra ID profile<\/td><td>displayName<strong>Note:<\/strong>The displayName for a user comes from their manager&#8217;s Entra ID profile. As a result, a user&#8217;s displayName will not display on their user profile in KSAT since their name is synced using other attributes. But it will display on their direct reports&#8217; user profiles.<\/td><td>Manager Name<\/td><\/tr><tr><td>physicalDeliveryOfficeName<\/td><td>addresses[type eq &#8220;work&#8221;].formatted<\/td><td>Location<\/td><\/tr><tr><td>telephoneNumber<\/td><td>phoneNumbers[type eq &#8220;work&#8221;].value<\/td><td>Phone Number<\/td><\/tr><tr><td>mobile<\/td><td>phoneNumbers[type eq &#8220;mobile&#8221;].value<\/td><td>Mobile Phone Number<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>Note:<\/strong>The&nbsp;<strong>Division<\/strong>&nbsp;and&nbsp;<strong>Organization&nbsp;<\/strong>fields are unmapped by default. If you plan to use these fields, you&#8217;ll need to add the mapping. You can add these attributes by following the instructions in the&nbsp;<a href=\"https:\/\/support.knowbe4.com\/hc\/en-us\/articles\/360053851814-Configure-SCIM-for-Microsoft-Entra-ID#CUSTOM-FIELDS\">Adding Attribute Mapping for Custom User Fields<\/a>&nbsp;section below.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h_01HASXESAYMMFK9ZA0G3K86S3C\">Changing the Default Mappings<\/h3>\n\n\n\n<p>You can change the default mappings to customize the user information that syncs between Microsoft Entra and your KSAT console.<\/p>\n\n\n\n<p>To change the default mappings, follow the steps below:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>From your Microsoft Entra ID, navigate to&nbsp;<strong>Enterprise applications<\/strong>.<\/li>\n\n\n\n<li>Select the application you created for your KnowBe4 connection.<\/li>\n\n\n\n<li>From the menu on the left side of the page, select&nbsp;<strong>Provisioning<\/strong>.<a><\/a><\/li>\n\n\n\n<li>From the&nbsp;<strong>Provisioning<\/strong>&nbsp;window, click&nbsp;<strong>Edit attribute mappings<\/strong>&nbsp;under&nbsp;<strong>Manage provisioning<\/strong>.<a><\/a><\/li>\n\n\n\n<li>Click the&nbsp;<strong>Mappings<\/strong>&nbsp;drop-down arrow to expand the&nbsp;<strong>Mappings<\/strong>&nbsp;tab.<a><\/a><\/li>\n\n\n\n<li>Click&nbsp;<strong>Provision Azure Active Directory Users<\/strong>.<\/li>\n\n\n\n<li>Scroll down to the&nbsp;<strong>Attribute Mappings&nbsp;<\/strong>section. From this section, you&#8217;ll see a list of all the attributes that have been mapped. The&nbsp;<strong>Azure Active Directory Attribute<\/strong>&nbsp;column displays the name of the attribute in Microsoft Entra. The&nbsp;<strong>KnowBe4&nbsp;Attribute<\/strong>&nbsp;column displays the SCIM standard name for this attribute.&nbsp;<a><\/a><\/li>\n\n\n\n<li>Select the attribute you would like to edit.<\/li>\n\n\n\n<li>In the&nbsp;<strong>Edit Attribute<\/strong>&nbsp;side pane, customize the attribute. For details about the customization options, see the list below:<ol type=\"a\"><li><strong>Mapping type<\/strong>: Select&nbsp;<strong>Direct<\/strong>&nbsp;from the drop-down menu.<\/li><li><strong>Source attribute<\/strong>: Select the Azure field that you want to map to this custom field.<strong>Note:<\/strong>If you&#8217;re using SSO for Microsoft Entra ID, this attribute should be the same as the SSO&nbsp;<strong>Source attribute<\/strong>. By default, the SSO&nbsp;<strong>Source attribute<\/strong>&nbsp;is&nbsp;<strong>user.userprincipalname<\/strong>. For more information, see&nbsp;<a href=\"https:\/\/support.knowbe4.com\/hc\/en-us\/articles\/229661667#ADD\">Add the KnowBe4 Application to Azure AD<\/a>&nbsp;section of our&nbsp;<a href=\"https:\/\/support.knowbe4.com\/hc\/en-us\/articles\/229661667\">How Do I Configure SSO\/SAML with Azure Active Directory (AD)?<\/a>&nbsp;article.<\/li><li><strong>Default value if null<\/strong>: This field is optional, and we recommend that you leave it blank.<\/li><li><strong>Target attribute<\/strong>: Select the custom field that you want to map to the Azure field you selected.<\/li><li><strong>Match objects using this attribute<\/strong>: We recommend you select&nbsp;<strong>No<\/strong>.<\/li><li><strong>Apply this mapping<\/strong>: We recommend you select&nbsp;<strong>Always<\/strong>.<strong>Note:<\/strong>If there is an attribute you don\u2019t want to sync, you can click the&nbsp;<strong>Delete<\/strong>&nbsp;button next to that attribute to disable syncing. This action will only remove the connection between this attribute and the corresponding field in your KSAT console. No data will be deleted from Azure.<\/li><\/ol><a><\/a><\/li>\n\n\n\n<li>Once you have made the changes you would like to make, click&nbsp;<strong>Ok<\/strong>.<strong>Note:<\/strong>We recommend that you only change the&nbsp;<strong>Source attribute<\/strong>&nbsp;field. Changing the other settings on the attribute may break the connection between Microsoft Entra and your KSAT console.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h_01HASXESAY2D92C27C011A1PF1\">Adding Attribute Mapping for Custom User Fields<\/h3>\n\n\n\n<p>You also have the option to add six custom fields. These fields are not mapped by default, but you can add them to Microsoft Entra by following the steps below:<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"1\">\n<li>From your Microsoft Entra ID, navigate to&nbsp;<strong>Enterprise applications<\/strong>.<\/li>\n\n\n\n<li>Select the application you created for your KnowBe4 connection.<\/li>\n\n\n\n<li>From the menu on the left side of the page, select<strong>&nbsp;Provisioning<\/strong>.<a><\/a><\/li>\n\n\n\n<li>From the&nbsp;<strong>Provisioning<\/strong>&nbsp;window, select&nbsp;<strong>Edit attribute mappings&nbsp;<\/strong>under&nbsp;<strong>Manage provisioning<\/strong>.<a><\/a><\/li>\n\n\n\n<li>Click the&nbsp;<strong>Mappings<\/strong>&nbsp;drop-down arrow to expand the&nbsp;<strong>Mappings<\/strong>&nbsp;tab.<a><\/a><\/li>\n\n\n\n<li>Click&nbsp;<strong>Provision Azure Active Directory Users<\/strong>.<\/li>\n\n\n\n<li>Click&nbsp;<strong>Add New Mapping<\/strong>&nbsp;at the bottom of the table.<\/li>\n\n\n\n<li>From the<strong>&nbsp;Edit Attribute<\/strong>&nbsp;window, select the&nbsp;<strong>Source attribute<\/strong>&nbsp;you would like to use.<\/li>\n\n\n\n<li>Then, select the&nbsp;<strong>Target Attribute<\/strong>&nbsp;that you would like to use. We offer the following custom fields:KSAT FieldTarget AttributeCustom Field 1 urn:ietf:params:scim:schemas:extension:knowbe4:kmsat:2.0:User:customField1 Custom Field 2 urn:ietf:params:scim:schemas:extension:knowbe4:kmsat:2.0:User:customField2 Custom Field 3 urn:ietf:params:scim:schemas:extension:knowbe4:kmsat:2.0:User:customField3 Custom Field 4 urn:ietf:params:scim:schemas:extension:knowbe4:kmsat:2.0:User:customField4 Custom Date 1 urn:ietf:params:scim:schemas:extension:knowbe4:kmsat:2.0:User:customDate1 Custom Date 2 urn:ietf:params:scim:schemas:extension:knowbe4:kmsat:2.0:User:customDate2 Division urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:division Organization urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:organization<\/li>\n\n\n\n<li>We recommend leaving the rest of the settings at their default settings.<\/li>\n\n\n\n<li>Repeat step 9 for all of the custom fields you added in step 8.<\/li>\n\n\n\n<li>Click&nbsp;<strong>Save<\/strong>&nbsp;at the top of the screen to save your changes.<\/li>\n<\/ol>\n\n\n\n<p>These custom fields will now sync to your KSAT console.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h_01HASXESAY2744SE4A6RR5C0Z3\">Frequently Asked Questions (FAQs)<a href=\"https:\/\/support.knowbe4.com\/hc\/en-us\/articles\/360053851814-Configure-SCIM-for-Microsoft-Entra-ID#h_01HASXESAY2744SE4A6RR5C0Z3\"><\/a><\/h2>\n\n\n\n<p>Below is a list of frequently asked questions about using SCIM with Microsoft Entra ID.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h_01HWE1PW9SD5034019QRNA5E3Y\">How often do syncs occur?<\/h3>\n\n\n\n<p>The system will check for updates to the users and groups in your Microsoft Entra ID every 40 minutes. If changes are found, a sync will begin automatically. However, you can force a sync at any time by clicking the&nbsp;<strong>Force Sync Now<\/strong>&nbsp;button in the&nbsp;<strong>SCIM Settings<\/strong>&nbsp;section of your KSAT&nbsp;<strong>Account Settings<\/strong>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h_01HWE1Q5DW6FCYJN8QG7K8Q85Q\">How do you restore the default mappings?<\/h3>\n\n\n\n<p>You can restore the default mapping at any time by following the steps below:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Navigate to<strong>&nbsp;Enterprise applications<\/strong>.<\/li>\n\n\n\n<li>Select the application you created for your KnowBe4 connection.<\/li>\n\n\n\n<li>From the menu on the left side of the page, select&nbsp;<strong>Provisioning<\/strong>.<\/li>\n\n\n\n<li>Click&nbsp;<strong>Edit attribute mapping<\/strong>&nbsp;under&nbsp;<strong>Manage provisioning<\/strong>.<\/li>\n\n\n\n<li>Click the&nbsp;<strong>Mappings<\/strong>&nbsp;drop-down arrow to expand the&nbsp;<strong>Mappings<\/strong>&nbsp;drop-down menu.<\/li>\n\n\n\n<li>Select&nbsp;<strong>Restore default mappings<\/strong>.<\/li>\n\n\n\n<li>Click&nbsp;<strong>Save<\/strong>&nbsp;at the top of the screen.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h_01HWE1QRB7NHABYSR9ARZ1T1B3\">How do I sync all my users and groups?<\/h3>\n\n\n\n<p>If you would like to sync all users and groups from your Microsoft Entra ID, follow the steps below:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Navigate to the application you set up for your SCIM connection.<\/li>\n\n\n\n<li>Navigate to&nbsp;<strong>Provisioning<\/strong>.<\/li>\n\n\n\n<li>Select&nbsp;<strong>Edit provisioning<\/strong>&nbsp;at the top of the screen or select<strong>&nbsp;Add scoping filters<\/strong>&nbsp;under&nbsp;<strong>Manage provisioning<\/strong>.<\/li>\n\n\n\n<li>Click the&nbsp;<strong>Settings<\/strong>&nbsp;drop-down menu.<\/li>\n\n\n\n<li>From the&nbsp;<strong>Scope<\/strong>&nbsp;drop-down menu, select&nbsp;<strong>Sync all users and groups<\/strong>.<\/li>\n\n\n\n<li>Click&nbsp;<strong>Save<\/strong>&nbsp;at the top of the page.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h_01HWE1R2C6Q1BVT2ZBMW82R7K4\">I don\u2019t have the ability to assign users to an application by group. How can I limit the users being synced to my KSAT console?<\/h3>\n\n\n\n<p><strong>Answer:<\/strong>\u00a0To limit the users being synced to your KSAT console, you can set up a scoping filter. For more information about making a scoping filter, see Microsofts\u00a0<a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/app-provisioning\/define-conditional-rules-for-provisioning-user-accounts\" target=\"_blank\" rel=\"noreferrer noopener\">Attribute-based application provisioning with scoping filters<\/a>\u00a0article.<\/p>\n\n\n\n<p>Ref: <a href=\"https:\/\/support.knowbe4.com\/hc\/en-us\/articles\/360053851814-Configure-SCIM-for-Microsoft-Entra-ID\">Configure SCIM for Microsoft Entra ID \u2013 Knowledge Base (knowbe4.com)<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this article, you&#8217;ll learn how to configure SCIM with Microsoft Entra ID (formerly Azure Active Directory). Configuring SCIM for Microsoft Entra ID will allow you to add and manage users and groups in your KSAT console using Microsoft Entra ID. The instructions in this article are for third-party software. If you experience issues with <a class=\"read-more\" href=\"https:\/\/SUMMALAI.COM\/?p=5164\">Read More<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_bbp_topic_count":0,"_bbp_reply_count":0,"_bbp_total_topic_count":0,"_bbp_total_reply_count":0,"_bbp_voice_count":0,"_bbp_anonymous_reply_count":0,"_bbp_topic_count_hidden":0,"_bbp_reply_count_hidden":0,"_bbp_forum_subforum_count":0,"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[1249,1818,10,497],"tags":[1819],"class_list":["post-5164","post","type-post","status-publish","format-standard","hentry","category-azure-microsoft","category-knowbe4","category-microsoft","category-solutions","tag-how-to-configure-knowbe4-scim-with-microsoft-entra-id"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts\/5164","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5164"}],"version-history":[{"count":1,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts\/5164\/revisions"}],"predecessor-version":[{"id":5165,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts\/5164\/revisions\/5165"}],"wp:attachment":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5164"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5164"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5164"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}