Azure SCIM Attributes
This page is specific to role attribute mapping in Azure directory sync and SCIM provisioning.
It assumes that the SAML/SCIM app was already added and configured following the steps within your organization on Rollstack.
First, you need to add a new app role
Open your Rollstack SAML app
Click on Users and Groups in the right sidebar
Click on the application registration
Now, you should be on the dedicated App Roles page
Click on Create app role
Set a display name
For the sake of the example rollstack_admins, but you can chose any name
Set a value admin
The value is not important either
Once the app role is created, we will map the user attribute
Click on the Provisioning sidebar option
Under the section Mappings, you can click on Provision Microsoft Entra ID Users
Now you can define a new attribute mapping
At the bottom of the page, click on Add new mapping
Select Expression
Set the following expression
If you chose a different name than rollstack_admins for the role, please update it in the expression below.
Set userType as a target
Now you can assign this new role to Users or Groups.
Click on the section Users and Groups
Assign the new role
You can edit either an assignment using Edit assignment
Or you can add a new user or group with the role using Add user/group