How to Automate User Provisioning and Deprovisioning with Entra ID (Azure AD) and SCIM. Managing user accounts manually is slow, inconsistent, and risky. By automating provisioning and deprovisioning through Microsoft Entra ID and SCIM, organizations can automatically create, update, and deactivate accounts across Microsoft 365, SaaS applications, and connected business systems. In this video, we'll show you how to set up SCIM-based provisioning in Microsoft Entra ID from setup to monitoring. Before we begin, be sure to subscribe to NinjaOne’s IT video hub and our YouTube channel for more tech content like this. Method 1: Setting Up Enterprise Application With SCIM Provisioning in Azure AD. This method leverages Microsoft Entra ID’s provisioning engine to automatically sync user details to SaaS apps via SCIM. Go to Microsoft Entra Admin Center, Microsoft Entra ID, Enterprise Apps. Click + New Application, select a SCIM-compatible app such as GitHub, Dropbox, or ServiceNow. Then, click Create. Navigate to the Provisioning tab under the Manage menu. Set Provisioning Mode to Automatic. Enter the SCIM Endpoint URL and Secret Token provided by your SaaS vendor. Click Authorize, sign in with an admin account on the vendor’s login page to grant Entra access. Click Test Connection to confirm the setup. Under Mappings, define your attribute transformations. This includes userName, emails.value, userPrincipalName. Click Save and set Provisioning Status to On. Method 2: Using Group-based Access for Dynamic Provisioning. This method provisions app access based on group membership, automatically granting or revoking access as users join or leave a group. Create or identify a Security Group or Dynamic Group in Entra ID. Assign the group to your SCIM-connected app via Enterprise App, App Name, Users and Groups, Add Group. Set dynamic membership rules based on attributes like department, job title, or location. An example rule would look like this. Method 3: Automating With PowerShell and Microsoft Graph for Provisioning Tasks. This method uses PowerShell and the Microsoft Graph API to manage users and provisioning tasks programmatically. Open PowerShell as administrator and run: Connect to Microsoft Graph with the required permissions and scopes, then run. Create a New User in Azure AD. To do this, run. Create a new user for provisioning to do this. Disable a User for Deprovisioning. To do this: Remove User From All App Groups. To do this: Method 4: Using CMD and GPO to Control Local Account Behavior After Cloud Deprovisioning. This method restricts local access after a user is deprovisioned from Microsoft Entra ID, reducing potential security risks. Disable Cached Domain Logins. Press Win + S and search for cmd. Right-click Command Prompt and select Run as administrator. Run the following command: Use Group Policy. Press Win + R, type gpedit.msc, and press Enter to open the Group Policy Editor. On domain controllers, use gpmc.msc instead. Navigate to: Computer Configuration, Windows Settings, Security Settings, Local Policies, Security Options Find and modify the setting Interactive logon: Number of previous logons to cache. Then set the value to 0 Schedule a shutdown or lockout script for deprovisioned users. Press Win + S, search for cmd or PowerShell, and press Enter. Run: shutdown -l Automating provisioning and deprovisioning with Microsoft Entra ID and SCIM reduces security risks, supports compliance, and speeds up onboarding and offboarding across cloud apps and connected devices. For more information, check out our official blog post on How to Automate User Provisioning and Deprovisioning with Entra ID and SCIM, linked in the description below.