Azure Active Directory
Last updated December 3, 2018
Organizations that use Azure Active Directory user provisioning (Azure AD) for user management can integrate it with their StarLeaf account. Azure AD integration is an additional option on your StarLeaf Enterprise account.
We encourage you to sign up to a free Azure AD account to explore and exercise the features made available to you with StarLeaf before integrating it with your production Azure AD environment. To get your free trial account, go to https://azure.microsoft.com
- Push new users from Azure AD to StarLeaf
- Push user updates from Azure AD to StarLeaf
- Push user deactivation from Azure AD to StarLeaf
- Ensure that Azure AD integration is activated on your StarLeaf account. To activate Azure AD integration on your StarLeaf account, contact StarLeaf technical support at firstname.lastname@example.org.
- Complete StarLeaf Portal configuration (described below).
- Add StarLeaf in Azure AD (described below).
Before you can configure StarLeaf provisioning in Azure AD, you need to know the Tenant URL and Secret Token.
- Log in to portal.starleaf.com .
- Go to Integrations > Add integration.
- Select Microsoft Azure Active Directory and select Apply.
- You see the SCIM server URI and Access token:
- Make a note of the SCIM base URL and Access token. You will need these when you configure Azure AD.
- Log in to the Azure portal https://portal.azure.com .
- Go to Azure Active Directory > Enterprise applications.
- Select New application.
- Under Add from the gallery type ‘StarLeaf’.
- Select the StarLeaf application and select the blue Add button. You see the configuration page of the StarLeaf application.
- On the configuration page:
- Set Provisioning Status to On.
- Ensure that Scope is set to ‘Sync only assigned users and groups’.
- Ensure that the box is ticked where it says ‘Clear current state and synchronization’.
- Select Save.
Users added in Azure AD take a minimum of 20 minutes to appear in the StarLeaf Portal. This may take longer if there are a lot of users / user groups.
If you add a user to Azure AD and this user already exists in the StarLeaf Portal with an identical email address, the user will be managed in Azure AD from that point on.
For reference, the attribute mappings look like this:
|Azure AD attribute||Customapp attribute||matching precedence|
|userPrincipalName||emails[type eq “work”].value|
|The following attributes are dependent on your AD configuration, but will include some of:|
|mobile||phoneNumbers[type eq “mobile”]|
|telephoneNumber||phoneNumbers[type eq “work”]|
If you think your access token has been compromised, you must create a new token. In the StarLeaf Portal, go to the Azure Active Directory Integration and select Regenerate access token and select Apply. You must enter the new token in Azure AD as the Secret Token.