Uniqkey EN Get started with Uniqkey Technical setup Search SCIM integration You can sync users and groups to Uniqkey via SCIM 2.0 and a standard Enterprise Application created in your Azure AD (Microsoft Entra ID).Hybrid environments are supported as long as the intergration to Uniqkey is managed via Azure AD. You can manage your Azure AD here.You also need access to the Uniqkey Admin Portal here. Create the Enterprise AppCreate a new Enterprise Application.Use the option to Create your own application.Give the app a name."What are you looking to do with your application" needs to be Non-gallery.Create the app. Setup provisioning Go to Manage -> Provisioning -> Create configuration -> Connect your application.Leave the authentication method as Bearer Authentication.Find the Tenant URL in your Uniqkey Admin Portal -> Settings -> Integrations -> SCIM.Click here to open the Uniqkey Admin Portal.Generate the Secret Token by clicking the arrow.Enter the Tenant URL and Secret Token in Azure and click Test connection.After the test is successful, click Create at the bottom of the screen. By default, SCIM will use the userPrincipalName attribute as the Uniqkey username. It's possible to change this via the Provisioning -> Attribute mapping settings in Azure.By editing this, you can use a different value as the Uniqkey username, as long as it's in an email format. The attribute mail is often used as an alternative by companies that don't use userPrincipalName to sync. Add users and groups Users can be added via the Uniqkey Enterprise App -> Users and Groups.Users will be synced to Uniqkey without any group memberships. Once they appear in the Uniqkey admin portal, you can add them to groups if you wish. Groups can be added via the Uniqkey Enterprise App -> Users and Groups.Supported group type is Global Security.Group assignment type can be either assigned or dynamic.Nested groups are not supported.The groups will be synced to Uniqkey with their assigned members. Employees who are members of multiple groups will not be provisioned to Uniqkey twice (no duplicate accounts).Once the groups have been synced to Uniqkey, you can add additional members even if they aren't part of the group in Azure. Settings Define the settings for SCIM users via the Uniqkey Admin Portal -> Settings -> Integrations -> SCIM.Automatic invitation: Enabled = When users are synced to Uniqkey, they will automatically receive an invitation email, and can activate their account.Note: emails are sent once a Uniqkey admin opens their mobile app to process the invitation.Require mobile authentication for groups provisioned via SCIM: Are groups synced via SCIM only accessible to employees using the Uniqkey mobile app?Enabled = employees who don't use a Uniqkey mobile app can't access group data.Require mobile authentication for individuals provisioned via SCIM: Are employees synced to Uniqkey via SCIM required to use the Uniqkey mobile app?Enabled = employees are required to use the Uniqkey mobile app.Note: If the two settings above can't be managed, it means that the Uniqkey mobile app is currently required for your organisation. Change this first via Settings -> Security settings -> Governance -> disable the require mobile authentication setting.Individual settings can be enabled for specific users and groups. Define the settings for SCIM groups via the Uniqkey Admin Portal -> Organisation -> Groups -> each individual group -> Settings.Allow secure data management:Enabled = Members can save data in this group. If you wish to use the group only to provision users from Azure to Uniqkey and hide it from view, disable this.Allow trusted browser:Enabled = When members activate trusted browser, data from this group is included.If you want to force users to approve in their Uniqkey mobile app when they access data, disable this.Allow export of logins:Enabled = Members can export group logins via their browser extension.Note: If this option is greyed out, it means that export is currently disabled for your organisation. Go to Settings -> Security settings -> enable the "allow export" setting.Allow custom name:Enabled = Give the group a different name.Require mobile authentication:Enabled/disabled = Overrides the default organisation setting.Allow view and copy:Enabled = Members can view and copy data from this group. If disabled, members can still use Uniqkey to fill in the data in login/payment forms on websites.Allow add and edit:Enabled = Members can add new data and edit existing data within the group. Enabling this also enables "view and copy"Allow delete:Enabled = Members can delete data from the group. Deleted data will be removed from the group, but still exist in "all secured data" as "unmanaged". Only admins can delete data completely. Start the syncStart the sync via Overview -> click Start provisioning.If necessary, you can stop and restart the provisioning from here. Provision on demandThe sync to Uniqkey runs every 40 minutes, and will provision new events to Uniqkey (users added/removed, group memberships, etc.). If your Azure settings/permissions support this, you can force this sync via the menu on the left -> Provision on demand. You can provision a single user at a time by selecting the user -> click Provision. You can provision a group and up to five members by selecting the group -> select the members you wish to provision with it -> click Provision.