Skip to content
English
  • There are no suggestions because the search field is empty.

How to Connect Okta or Microsoft Entra to Tiled via SCIM

This guide explains how to use SCIM 2.0 to connect your identity provider — Okta or Microsoft Entra — to Tiled for automated user provisioning and deprovisioning.


Overview

SCIM (System for Cross-domain Identity Management) lets your identity provider automatically manage Tiled user accounts based on your directory. When SCIM is configured:

  • New employees added to the Tiled application in your IdP are automatically provisioned in Tiled.
  • User attributes (name, email) updated in your IdP are automatically synced to Tiled.
  • Users removed from the Tiled application in your IdP — or who leave your organization — are automatically deprovisioned in Tiled.

This eliminates the need to manually create, update, or remove Tiled accounts as your organization changes.

Note: SCIM configuration is handled entirely in your IdP admin console. There is no end-user interface change in Tiled for this feature — it operates at the IT administration level.


Supported Identity Providers

  • Okta
  • Microsoft Entra (formerly Azure Active Directory)

Prerequisites

  • An Enterprise Tiled account.
  • Administrator access to your Okta or Microsoft Entra tenant.
  • Your Tiled SCIM endpoint URL and bearer token — contact Tiled Support to obtain these credentials before beginning configuration.

Configuration Overview

SCIM provisioning is configured from your identity provider's admin console using the Tiled SCIM endpoint URL and bearer token provided by Tiled Support.

Okta

  1. In your Okta admin console, locate the Tiled application (or add it if not already configured).
  2. Navigate to the Provisioning tab for the Tiled app.
  3. Enable SCIM provisioning and enter the Tiled SCIM endpoint URL and bearer token when prompted.
  4. Configure the provisioning actions you want to enable: Create Users, Update User Attributes, Deactivate Users.
  5. Save and test the connection.

Microsoft Entra

  1. In the Microsoft Entra admin center, locate the Tiled enterprise application.
  2. Navigate to Provisioning and set the provisioning mode to Automatic.
  3. Enter the Tiled SCIM endpoint URL as the Tenant URL and the bearer token as the Secret Token.
  4. Click Test Connection to verify, then configure your attribute mappings.
  5. Set the provisioning scope and save.

Tip: After enabling SCIM, run a provisioning cycle in test mode before enabling live provisioning to confirm your attribute mappings are correct.


What SCIM Manages

Event What happens in Tiled
User added to Tiled app in IdP Tiled account is automatically created
User attributes updated in IdP Tiled account attributes are synced
User removed from Tiled app in IdP Tiled account is automatically deprovisioned

Common Questions

Do end users notice anything different when SCIM is enabled?
No — SCIM operates at the IT administration level. End users are provisioned and deprovisioned automatically based on your IdP configuration, but there is no change to the Tiled interface they see.

How do I get my SCIM endpoint URL and bearer token?
Contact Tiled Support to request your SCIM credentials before beginning configuration.

Is SCIM available on all Tiled plans?
SCIM provisioning is available for Enterprise accounts. Contact your Tiled account team if you're unsure whether your plan includes SCIM.

What happens to content owned by a deprovisioned user?
Contact Tiled Support for guidance on content ownership and reassignment before deprovisioning users who own microapps or library assets.