Category

How to Configure Microsoft Entra ID User Provisioning in BoldDesk

Updated:

Microsoft Entra ID user provisioning allows you to create, update, and deactivate BoldDesk users based on the users managed in Microsoft Entra ID. Before proceeding, complete the steps to Setup the Microsoft Entra ID in BoldDesk, and then configure the enterprise application, connection credentials, attribute mappings, and provisioning scope.

Add BoldDesk from the Microsoft Entra application gallery

  1. Log into the Microsoft Entra Admin Portal.

  2. Go to Identity > Applications > Enterprise applications > New application.

    azure-ad-create-app-1.png

  3. Click the “Create Your Own Application” button.

  4. Enter a name for the application.

  5. Select the option Integrate any other application you don’t find in the gallery (Non-gallery).

  6. Click the Create button. Once the application is created, you will be redirected to the application’s home page.

    azure-ad-create-app-2.png

Connect with BoldDesk account

  1. In application page, select Provisioning in the left sidebar menu.

    azure-ad-provisioning-1.png

  2. Choose the Automatic option from the Provisioning Mode menu.

  3. Under the Admin Credentials section, enter your Tenant URL and Secret Token Click on this link to create an API token.

    Tenant URL: https://{your-domain}.bolddesk.com/api/v1/scim

  4. Click the Test Connection button to confirm Microsoft Entra ID connects with BoldDesk. Click Save when finished.

    azure-ad-provisioning-2.png

Attribute mapping

  1. In application page, select Provisioning in the left sidebar menu and then click on Edit attribute mappings.

  2. Choose the option to Provision Azure Active Directory Groups and then turn off this feature.

  3. Choose the Provision Azure Active Directory Users and then turn on this feature.

    azure-ad-mapping-1.png

  4. Choose the Target Object Action (Create, Update, and Delete).

    azure-ad-mapping-3.png

  5. In Attribute mappings section, add the user attributes and delete all default attributes not included in the following list.

    Azure Active Directory Attribute Customappsso attribute Matching precedence Apply this mapping Mapping type Notes
    userPrincipalName userName 1 Always Direct Mandatory
    Switch([IsSoftDeleted], , "False", "True", "True", "False") active - Always Expression Mandatory
    displayName displayName - Always Direct Mandatory
    jobTitle title - Always Direct -
    mail emails[type eq "work"].value - Always Direct -
    Switch(Join(" ", [givenName], [surname]), Join(" ", [givenName], [surname]), "", [mailNickname]) name.formatted - Always Expression Mandatory
    telephoneNumber phoneNumbers[type eq "work"].value - Always Direct -
    mobile phoneNumbers[type eq "mobile"].value - Always Direct -
    objectId externalId - Always Direct Mandatory
    SingleAppRoleAssignment([appRoleAssignments]) roles[primary eq "True"].value - Always Expression Mandatory
    physicalDeliveryOfficeName addresses[type eq “work”].formatted - Always Direct or Expression We can also bind expression like this Join(",", [streetAddress], [city], [state], [postalCode], [country])
    preferredLanguage preferredLanguage - Always Direct -
  6. The attributes selected as matching properties are used to match the user accounts in BoldDesk for update operations. To save any changes, select Save.

    sshot-1.png

Provisioning setting

  1. Check the box labeled Send an email notification when a failure occurs and enter the email address to receive the provisioning error notifications.

  2. In the settings section, choose Scope to specify which users should be provisioned for BoldDesk.

    • Sync all users and groups: This option will synchronize all users from Microsoft Entra ID to BoldDesk.
    • Sync only assigned users and groups: This option will synchronize only the users assigned to the enterprise application.

Start provisioning

  1. In application page, select Provisioning in the left sidebar menu.

  2. Click Start provisioning.

    azure-ad-start-provisioning.png

Troubleshooting

Microsoft Entra ID Groups Are Provisioned Unexpectedly

Go to Provisioning > Edit attribute mappings, select Provision Azure Active Directory Groups, and disable group provisioning.

Confirm that Provision Azure Active Directory Users remains enabled.

User Updates Are Not Applied to the Correct BoldDesk Account

Confirm that userPrincipalName is mapped to userName and has a matching precedence of 1.

Matching properties are used to identify the corresponding BoldDesk user account during update operations.

Provisioning Failure Notifications Are Not Received

Confirm that:

  • Send an email notification when a failure occurs is selected.
  • A valid email address is entered for provisioning failure notifications.
  • The provisioning settings have been saved.

Provisioning Does Not Include All Users

Review the selected provisioning scope:

  • Select Sync all users and groups to synchronize all users from Microsoft Entra ID to BoldDesk.
  • Select Sync only assigned users and groups to synchronize only users assigned to the enterprise application.

Ensure that the selected scope matches the provisioning requirement.

Frequently Asked Questions

  1. What must be completed before configuring user provisioning?
    Complete the Microsoft Entra ID setup in BoldDesk before configuring user provisioning.

  2. What Tenant URL should be used for BoldDesk provisioning?
    Use the following URL and replace {your-domain} with the applicable BoldDesk domain:

    https://{your-domain}.bolddesk.com/api/v1/scim
    
  3. How can I verify the connection between Microsoft Entra ID and BoldDesk?
    Enter the Tenant URL and Secret Token, and then click Test Connection.

  4. Which attribute is used to match users during update operations?
    userPrincipalName is mapped to userName with a matching precedence of 1.

Was this article useful?
Like
Dislike
Help us improve this page
Please provide feedback or comments
Comments (0)
Access denied
Access denied
Access denied
Access denied

No articles or sections found
No articles or sections found