Skip to main content

Set up automatic user provisioning (SCIM) for Lucen Timeline

Set up automatic user provisioning (SCIM 2.0) with Microsoft Entra ID for Lucen Timeline, so members of an Entra security group are licensed automatically and deprovisioned when they leave.

Overview

Automatic user provisioning (SCIM 2.0) connects your identity provider to Lucen Timeline. At launch this supports Microsoft Entra ID (formerly Azure AD). Once set up, members of a designated group are automatically licensed in your Timeline subscription, and lose access when they leave the group or your tenant.

What this gives you: hands-off licensing (add a user to your group, they get a Timeline seat within minutes); automatic offboarding (remove them, the seat is revoked); and one source of truth for who is licensed, managed entirely from your identity provider.

Before you begin

You will need:

  • An active Lucen Timeline subscription with seats to manage.

  • An Account Center login that is the Billing Owner or a Workspace Admin of the subscription (the purchaser, or someone they assigned as Workspace Admin).

  • A Microsoft Entra ID tenant with permission to create Enterprise Applications (Application Administrator, Cloud Application Administrator, or Global Administrator).

  • An Entra security group containing the users you want licensed.

  • About 15 minutes.

Don't see Integrations in Account Center? SCIM may not be enabled for your subscription yet. Contact [email protected] to have it turned on.

One-way sync. Provisioning flows from your identity provider to Lucen Timeline only. Changes made directly in Account Center are overwritten on the next sync cycle.

Step 1: Get your SCIM endpoint and token from Account Center

  1. Sign in to Account Center at app.lucensoftware.com and turn on Admin Mode (toggle at the bottom of the left menu).

  2. In the left navigation, open Integrations, then Manage settings under SCIM Provisioning.

  3. Under Subscription, choose the subscription SCIM should manage seats for.

  4. Copy the SCIM endpoint URL. It is https://api.lucensoftware.com/admin/scim/v2 (the same for every customer; your subscription is tied to the token, not the URL). You will paste it into Entra in Step 4.

  5. Under Bearer token, click Generate token and confirm, then copy it before leaving the page (it is shown only once). If a token already exists, use Regenerate token instead, which invalidates the old one. Generating a token sets the SCIM Provisioning status to SCIM active, shown with "Complete the setup in your identity provider to activate"; provisioning only starts once you finish the connection in Entra (Steps 2 to 6). You will paste the token into Entra in Step 4.

Store the bearer token securely. It is shown only once. Anyone with it can provision or deprovision users in your subscription. Regenerating it invalidates the previous token, and revoking it removes the token entirely and switches SCIM provisioning off. Each SCIM token corresponds to a single admin and a single subscription, so generate a separate token for each subscription you provision.

Step 2: Create an Enterprise Application in Entra

  1. Sign in to the Microsoft Entra admin center at entra.microsoft.com.

  2. Go to Identity > Applications > Enterprise applications.

  3. Click + New application, then + Create your own application.

  4. Name it Lucen Timeline, choose Integrate any other application you don't find in the gallery (Non-gallery), and click Create.

SCIM vs. single sign-on (SSO). This app handles provisioning only, who gets a Timeline seat. It is not part of the sign-in path, so leave its Single sign-on set to Disabled and do not configure SAML on it. On Microsoft Entra, sign-in is already supported separately: a Global Administrator grants admin consent to the Lucen Timeline sign-in app once, and your users then sign in with Login with Microsoft. The two apps do not reference each other, SCIM assigns the seat by email and sign-in matches on that same email. Many admins rename this provisioning app to Lucen Timeline - Provisioning so each app's purpose is clear. See the enterprise deployment guide for the sign-in and admin-consent setup.

Step 3: Assign the user group

  1. From the application, go to Users and groups > + Add user/group.

  2. Select your Entra security group, then click Assign.

Group assignment requires Entra ID P1 or higher. On the free tier, assign individual users instead. The rest of the guide is the same.

Step 4: Configure provisioning

  1. In the app, click Provisioning, then set Provisioning Mode to Automatic.

  2. Under Admin Credentials: paste the SCIM endpoint URL into Tenant URL, and the Bearer token into Secret Token.

  3. Click Test Connection (you should see "The supplied credentials are authorized..."), then Save.

Step 5: Review attribute mappings

After you save, Entra reveals the Mappings section. Make one change here: turn group provisioning off.

  1. Under Mappings, click Provision Microsoft Entra ID Groups, set Enabled to No, and click Save.

  2. Leave Provision Microsoft Entra ID Users enabled with its default mappings.

Lucen Timeline licenses individual people and does not store groups, so the Entra group you assigned in Step 3 still works (Entra provisions each member as a user). If group provisioning stays on, Entra tries to push the group object itself and logs an error on every sync cycle.

Timeline only needs the user's email to license them (mail -> emails[type eq "work"].value); userPrincipalName -> userName is the identifier and displayName is accepted but not used. Everything else Entra sends is accepted and ignored, so leave the other defaults alone.

If mail is empty for some accounts in your tenant (common for guest or unlicensed accounts), edit that mapping to source from userPrincipalName so an address is always present.

Step 6: Start provisioning

  1. Set Scope to Sync only assigned users and groups.

  2. Set Provisioning Status to On, then Save.

Entra runs an initial cycle within a few minutes, then syncs roughly every 40 minutes. Watch progress on the Provisioning logs tab.

Step 7: Verify in Account Center

  1. After the first cycle completes, go to Subscriptions and open the subscription you selected in Step 1 (match the Subscription Reference, for example sub_XXXXXXXX).

  2. On the Seats tab you should see the users from your Entra group, each with an Assigned date. The Integrations page adds the last sync time once syncing begins (the status already reads SCIM active from the moment you generated a token).

  3. Test the lifecycle by adding or removing a member of the Entra group; the change reflects in Timeline within about 40 minutes.

The Integrations page shows SCIM active as soon as a token exists (with "Complete the setup in your identity provider to activate" until Entra is connected), and adds the last sync time once provisioning runs. For per-user sync detail and errors, use the Provisioning logs tab in Entra (Step 6); the Account Center seat list shows the result of a sync, not its live progress.

Troubleshooting

  • "Credentials not authorized" on Test Connection: the token is wrong or was regenerated. Re-copy it from Admin Mode > Integrations > Manage settings.

  • Test passes but no users appear: confirm the group is assigned, Scope = "Sync only assigned users and groups," and Provisioning Status = On. Use Provision on demand on a test user.

  • User skipped, "Not effectively entitled": the user is not in the assigned group. Add them.

  • The logs show a failure for the group itself, not for users: group provisioning is still enabled. Open Provisioning > Mappings > Provision Microsoft Entra ID Groups, set Enabled to No, and save (Step 5). Users keep provisioning normally.

  • Wrong or missing email in Timeline: check the Entra mail attribute; if empty, source the mapping from userPrincipalName.

  • A user removed from the group still appears licensed: deprovisioning can lag one sync cycle (about 40 minutes). Deprovisioning failures do not always appear in the Entra provisioning logs; if a seat is not revoked after a couple of cycles, contact support.

  • An Entra provisioning error shows a vague reason: Entra reports a generic failure reason regardless of the underlying cause. Re-check the token, the group assignment, and Scope first; if it persists, send the Provisioning logs to support.

Need help?

Contact [email protected] with the symptom, a Provisioning logs screenshot (PII redacted), and your subscription reference (for example sub_XXXXXXXX, shown in the Subscription picker on the Integrations page).

Did this answer your question?