Microsoft Entra API-Driven Provisioning

แชร์
ฝัง
  • เผยแพร่เมื่อ 22 ก.ค. 2024
  • A look at the ability to POST a SCIM workload from ANY application to provision users to Entra or Active Directory Domain Services using the API-driven inbound provisioning capability of Microsoft Entra.
    🔎 Looking for content on a particular topic? Search the channel. If I have something it will be there!
    ▬▬▬▬▬▬ C H A P T E R S ⏰ ▬▬▬▬▬▬
    00:00 - Introduction
    00:07 - Entra tenant and ADDS
    01:21 - HR source of truth
    04:56 - API-driven provisioning
    08:01 - Creating the inbound API endpoint app
    09:03 - ADDS vs Azure AD/Entra option
    10:46 - Getting started and mapping
    14:01 - Scoping
    15:17 - Start provisioning
    15:47 - Permissions for the sending app
    19:58 - Demo
    26:39 - Checking provisioning logs
    29:15 - Portal provisioning logs
    31:51 - How you would read user info from app
    32:48 - Licensing
    33:04 - Summary
    ▬▬▬▬▬▬ K E Y L I N K S 🔗 ▬▬▬▬▬▬
    ► Whiteboard:
    🔗 github.com/johnthebrit/Random...
    ► My example SCIM file:
    🔗 github.com/johnthebrit/Random...
    ► Microsoft documentation:
    🔗 learn.microsoft.com/azure/act...
    ► CSV to PowerShell script:
    🔗 github.com/MicrosoftDocs/azur...
    ► Multiple ADDS and Forest scenarios:
    🔗 learn.microsoft.com/azure/act...
    ▬▬▬▬▬▬ Want to learn more? 🚀 ▬▬▬▬▬▬
    📖 Recommended Learning Path for Azure
    🔗 learn.onboardtoazure.com
    🥇 Certification Content Repository
    🔗 github.com/johnthebrit/Certif...
    📅 Weekly Azure Update
    🔗 • Azure Infrastructure U...
    ☁ Azure Master Class
    🔗 • Microsoft Azure Master...
    ⚙ DevOps Master Class
    🔗 • DevOps Master Class
    💻 PowerShell Master Class
    🔗 • PowerShell Master Class
    🎓 Certification Cram Videos
    🔗 • Microsoft Certificatio...
    🧠 Mentoring Content
    🔗 • Virtual Mentoring
    ❔ Questions? Maybe I answered it in my FAQ
    🔗 savilltech.com/faq.html
    👕 Cure Childhood Cancer Charity T-Shirt Channel Store
    🔗 johns-t-shirts-store.creator-...
    👂 Enable the subtitles and from there you can translate to your native language via the auto-translate feature in settings! • TH-cam Captions and A... for a demo of using this feature.
    SUBSCRIBE ✅ / @ntfaqguy
    #microsoft #azure #johnsavillstechnicaltraining #onboardtoazure #cloud

ความคิดเห็น • 28

  • @willwallguy
    @willwallguy 10 หลายเดือนก่อน +2

    We've been using Microsoft Identity Manager for years and it's EOL in extended support. This looks like a good option for us to start investigating. Great video as always!

  • @calummaclean309
    @calummaclean309 10 หลายเดือนก่อน +1

    I was just looking for a way to automate creation and management of some of the identity management practices I've implemented for our org after watching your videos 👍. I'm not sure if we are an oddity as an organisation, but we dont have any on-premise ADDS or servers - cloud only is much easier to maintain for a small business. Thanks for all your videos, John.

  • @m0n3ysh0t
    @m0n3ysh0t 10 หลายเดือนก่อน

    YES! Been waiting for this to automate our user flows. Thanks John!

    • @NTFAQGuy
      @NTFAQGuy  10 หลายเดือนก่อน

      You're welcome!

  • @kimagran4071
    @kimagran4071 10 หลายเดือนก่อน

    Thanks John! Great content and explanations, as always 🙂. Will try this out

    • @NTFAQGuy
      @NTFAQGuy  10 หลายเดือนก่อน

      Awesome, thank you!

  • @geroffmilan3328
    @geroffmilan3328 หลายเดือนก่อน

    This is very interesting: we benefit from the cloud HR SCIM provisioning covered in your other video, bit it's great to know there is a "generic" option for those not using one pf those cloud HR platforms.
    I also need to test Lifecycle workflows in our test tenant, as we currently use UIPath Orchestrator to wrap around the Joiners & Leavers workflow, but the native Lifecycle workflows could better cover a large amount of it, though perhaps not all - one element of onboarding is ensuring we have adequate licenses available for new starts, and procuring those dynamically if we don't.

  • @vincentpicard9596
    @vincentpicard9596 10 หลายเดือนก่อน

    Hi John ! I'm Vincent from France. I've watched a lot of technical videos on the Internet but yours is by far the best! Everything is clear and your explanations are very complete. And what a presentation! I need the same touch panel (and info on the sports you do to keep fit 🙂). I'm discovering SCIM and it's all very clear. Thank you so much for your time and the quality of the information.

    • @NTFAQGuy
      @NTFAQGuy  10 หลายเดือนก่อน +1

      Glad you enjoyed the content! I have videos on my channel around setup etc.

  • @GavinPeters
    @GavinPeters 10 หลายเดือนก่อน +2

    Thank you once again John. `

    • @NTFAQGuy
      @NTFAQGuy  10 หลายเดือนก่อน

      My pleasure!

  • @sonaliika
    @sonaliika 10 หลายเดือนก่อน

    Very informative video. I will try. Thank you

    • @NTFAQGuy
      @NTFAQGuy  10 หลายเดือนก่อน

      Most welcome 😊

  • @joshuaeuceda4635
    @joshuaeuceda4635 10 หลายเดือนก่อน

    Thanks John, nice job.

    • @NTFAQGuy
      @NTFAQGuy  10 หลายเดือนก่อน

      Thanks!

  • @markdriver8511
    @markdriver8511 10 หลายเดือนก่อน

    Great content as always 🙂

    • @NTFAQGuy
      @NTFAQGuy  10 หลายเดือนก่อน

      Appreciate it!

  • @VanakkamTamilMakkale
    @VanakkamTamilMakkale 10 หลายเดือนก่อน

    that was informative thanks

    • @NTFAQGuy
      @NTFAQGuy  10 หลายเดือนก่อน

      Glad it was helpful!

  • @Spike01000
    @Spike01000 10 หลายเดือนก่อน +1

    This is very cool and I will be testing out the AD provision flow when I get time. Not entirely sure how it's going to handle hybrid Exchange but it will be fun finding out.

  • @ru54623
    @ru54623 10 หลายเดือนก่อน

    👍

  • @rvconde89
    @rvconde89 10 หลายเดือนก่อน +1

    first video after my certification haha keeping the pace

    • @NTFAQGuy
      @NTFAQGuy  10 หลายเดือนก่อน

      Nice work!

  • @jakubniedzielski2060
    @jakubniedzielski2060 4 หลายเดือนก่อน

    Hey, Can this create guest accounts?

    • @NTFAQGuy
      @NTFAQGuy  4 หลายเดือนก่อน +1

      Guest accounts are external references to an identity in another IDP. They are not accounts in your tenant. There are other ways to enable onboarding of guests like entitlement management etc etc

  • @JFish922
    @JFish922 10 หลายเดือนก่อน

    Are you able to do this with the Azure AD free license?

    • @NTFAQGuy
      @NTFAQGuy  10 หลายเดือนก่อน

      licensing is covered in the video.

    • @JFish922
      @JFish922 10 หลายเดือนก่อน +1

      Ah, I see now. P1 for now for preview. Thanks!