> For the complete documentation index, see [llms.txt](https://docs.guardware.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.guardware.com/documentation/protect/azure-configurations/configure-azure-provisioning-in-guardware.md).

# Configure Azure Provisioning in GuardWare

Azure Provisioning allows you to synchronise users and groups from Microsoft Entra ID with GuardWare. This lets you manage user and group assignments in Microsoft Entra ID and automatically provision them in GuardWare.

This guide explains how to configure Azure Provisioning, set up the required attribute mappings, assign users and groups, and start provisioning.

{% hint style="info" %}
**Before you begin:** Make sure you have administrator access to Microsoft Azure/Microsoft Entra ID.
{% endhint %}

{% hint style="warning" %}
The Microsoft Entra ID interface may change over time. The names or locations of some options may differ slightly from those shown in the steps and images.
{% endhint %}

## 1. Get the GuardWare provisioning details

Before configuring Azure, get the provisioning credentials from the GuardWare Management Console.

1. Log in to the **GuardWare Management Console**.
2. Navigate to **Integrations**.
3. Select **Azure Provisioning Authentication**.<br>

   <figure><img src="https://2233655803-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi6thNYq9Il6WA2mTbj6X%2Fuploads%2FagLic9sodjBcWZBuqNk2%2Fimage.png?alt=media&amp;token=fbaa9431-d4ab-4a11-a6e6-18b30a39f752" alt=""><figcaption></figcaption></figure>
4. Copy the following values:

   * **Azure Provisioning Token**
   * **Azure Provisioning API Endpoint**

   You will need these values when configuring the provisioning connection in Microsoft Entra ID.

> **Important:** Keep the **Azure Provisioning Token** secure. Do not share it with unauthorised users.

## 2. Create the GuardWare enterprise application

1. Log in to the **Azure Portal**.
2. Navigate to **Enterprise applications**.
3. Click **+ New application**.<br>

   <figure><img src="https://2233655803-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi6thNYq9Il6WA2mTbj6X%2Fuploads%2FVChgHyY5Pes0xxDrtVXI%2Fimage.png?alt=media&amp;token=3510481c-c0ff-48cf-9e55-47491dd4aae6" alt=""><figcaption></figcaption></figure>
4. Click **Create your own application**.<br>

   <figure><img src="https://2233655803-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi6thNYq9Il6WA2mTbj6X%2Fuploads%2Fo6nROkniFfYtSrj5kwmM%2Fimage.png?alt=media&amp;token=a47320ad-a25b-4981-b7f2-e525e4d76b27" alt=""><figcaption></figcaption></figure>
5. Enter a name for the application, such as **GuardWare**.
6. Select **Integrate any other application you don't find in the gallery (Non-gallery)**.\
   ![](https://2233655803-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi6thNYq9Il6WA2mTbj6X%2Fuploads%2F2N3txDCkovAK8qApGo13%2Fimage.png?alt=media\&token=0aaf8049-67ad-4a98-b522-4d17b69d8cf0)
7. Click **Create.**&#x20;

After creating the application:

8. In Overview, click **Connect your application**.<br>

   <figure><img src="https://2233655803-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi6thNYq9Il6WA2mTbj6X%2Fuploads%2FRakSeDZBfysuHeu0PefA%2Fimage.png?alt=media&amp;token=de10c8c7-34ce-4020-8315-f7713f53d208" alt=""><figcaption></figcaption></figure>
9. Under **Select authentication method**, select **Bearer authentication**.
10. In **Tenant URL**, enter the **Azure Provisioning API Endpoint** copied from the GuardWare Management Console.
11. In **Secret token**, enter the **Azure Provisioning Token** copied from the GuardWare Management Console.
12. Click **Test connection**.<br>

    <figure><img src="https://2233655803-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi6thNYq9Il6WA2mTbj6X%2Fuploads%2Fpd3xpqJR2ASArL3IFB2O%2Fimage.png?alt=media&amp;token=31d612c4-7aa3-4b1f-8847-33b3393e806e" alt=""><figcaption></figcaption></figure>
13. After the connection is successfully tested, click **Create**.<br>

    <figure><img src="https://2233655803-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi6thNYq9Il6WA2mTbj6X%2Fuploads%2FYQaeBmborfiwtcAK1o4M%2Fimage.png?alt=media&amp;token=4fd4ecc9-80d6-4c8d-9556-7ff66c541170" alt=""><figcaption></figcaption></figure>

## 3. Configure attribute mappings

Attribute mappings define how information from Microsoft Entra ID is sent to GuardWare.

After creating the provisioning configuration:

1. Under **Manage**, select **Attribute mapping**.

First, add the GuardWare-specific group attribute to the provisioning schema.

2. In **Attribute mapping**, select the **Groups** tab.
3. Click **Advanced options**.
4. Select **Edit customappsso group attributes**.<br>

   <figure><img src="https://2233655803-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi6thNYq9Il6WA2mTbj6X%2Fuploads%2FwvpC7lHSG6SsGbkBcbdV%2Fimage.png?alt=media&amp;token=1961eb3f-2e5b-492b-814c-33fe45d75765" alt=""><figcaption></figcaption></figure>
5. Click **+ Add new attribute**.<br>

   <figure><img src="https://2233655803-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi6thNYq9Il6WA2mTbj6X%2Fuploads%2F90sBQVzH0zyr3B3VQ4sM%2Fimage.png?alt=media&amp;token=18a34c6d-766c-4429-88c5-bdbc846e1bd5" alt=""><figcaption></figcaption></figure>
6. In **Name**, enter:

```
urn:ietf:params:scim:schemas:extension:guardware:2.0:Group
```

7. Set **Type** to **String**.<br>

<figure><img src="https://2233655803-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi6thNYq9Il6WA2mTbj6X%2Fuploads%2FexWEUqXBL6502LWdlmvu%2Fimage.png?alt=media&amp;token=879e3a22-ad8c-4242-9321-2da4dddddb2c" alt=""><figcaption></figcaption></figure>

8. Leave the other options at their default values.
9. Click **Save**.
10. Return to **Attribute mapping**.
11. Select **Groups**.
12. Click **Add attribute mapping**.<br>

    <figure><img src="https://2233655803-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi6thNYq9Il6WA2mTbj6X%2Fuploads%2F8EnZQjw5vACJe0rJnVGr%2Fimage.png?alt=media&amp;token=7e3eb9fa-b880-4975-8630-f2929f51d008" alt=""><figcaption></figcaption></figure>
13. For **Mapping type**, select **Direct**.
14. For **Source attribute (Microsoft Entra ID)**, select **mail**.
15. For **Target attribute (customappsso)**, select:

```
urn:ietf:params:scim:schemas:extension:guardware:2.0:Group
```

16. Leave **Apply this mapping** set to **Always**.<br>

<figure><img src="https://2233655803-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi6thNYq9Il6WA2mTbj6X%2Fuploads%2FP9mIOOpIXm4mp7uEPQSO%2Fimage.png?alt=media&amp;token=62ebe369-1472-448a-a83b-e73c0b3ee949" alt=""><figcaption></figcaption></figure>

17. Click **Add**.

The resulting group mappings should include the GuardWare-specific attribute:

| Microsoft Entra ID attribute | GuardWare attribute                                          |
| ---------------------------- | ------------------------------------------------------------ |
| `displayName`                | `displayName`                                                |
| `members`                    | `members`                                                    |
| `objectId`                   | `externalId`                                                 |
| `mail`                       | `urn:ietf:params:scim:schemas:extension:guardware:2.0:Group` |

Next, update the user mapping so that GuardWare uses the user's original Microsoft Entra user principal name as the username.

18. Select the **Users** tab.
19. Locate the existing **userName** mapping and edit the existing `userName` mapping.<br>

<figure><img src="https://2233655803-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi6thNYq9Il6WA2mTbj6X%2Fuploads%2FlxmY7rsTLaIlMtoX65Gg%2Fimage.png?alt=media&amp;token=91f97b83-9406-429a-929d-fad899d988da" alt=""><figcaption></figcaption></figure>

20. For **Mapping type**, select **Direct**.
21. For **Source attribute (Microsoft Entra ID)**, select **originalUserPrincipalName**.
22. For **Target attribute (customappsso)**, select **userName**.<br>

    <figure><img src="https://2233655803-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi6thNYq9Il6WA2mTbj6X%2Fuploads%2FqtLqJPUma0aIy4OYaV3S%2Fimage.png?alt=media&amp;token=30ab6b94-a045-4359-958f-d549ffbbaf03" alt=""><figcaption></figcaption></figure>
23. Under **Match objects using this attribute**, select **Yes** and set **Matching precedence** to **1**.
24. Click **Apply** and **Save**.

Next, configure which actions Microsoft Entra ID can perform in GuardWare.

25. Under **Manage**, select **Provisioning**.
26. Expand **Mappings** and select **Provision Microsoft Entra ID Groups**.

<figure><img src="https://2233655803-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi6thNYq9Il6WA2mTbj6X%2Fuploads%2F0FuzgaGdJwM7Zuu4Xhvw%2Fimage.png?alt=media&amp;token=a38da99c-8a6e-44b1-9709-096f2d9308e3" alt=""><figcaption></figcaption></figure>

27. Under **Target Object Actions**, enable **Create** and disable **Update** and **Delete**.

<figure><img src="https://2233655803-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi6thNYq9Il6WA2mTbj6X%2Fuploads%2Fv2hcooLbLcW6tC9JBr6p%2Fimage.png?alt=media&amp;token=2a495f1b-f60d-43ee-b592-86586c9a5f2a" alt=""><figcaption></figcaption></figure>

28. Click **Save**.
29. Return to **Mappings**.
30. Select **Provision Microsoft Entra ID Users**.
31. Under **Target Object Actions**, enable **Create** and disable **Update** and **Delete**.<br>

    <figure><img src="https://2233655803-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi6thNYq9Il6WA2mTbj6X%2Fuploads%2FYXj60GyUPgZheHcOzJDX%2Fimage.png?alt=media&amp;token=d700c477-d1af-4389-b3b2-033f0a9197fb" alt=""><figcaption></figcaption></figure>
32. Click **Save**.

## 4. Assign users and groups and start provisioning

You must assign the users or groups that you want to provision to GuardWare.

1. Under **Manage**, select **Users and groups**.
2. Click **+ Add user/group**.<br>

   <figure><img src="https://2233655803-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi6thNYq9Il6WA2mTbj6X%2Fuploads%2FIpD9lpbLcQ19MSSjI5kx%2Fimage.png?alt=media&amp;token=d335b38a-72b9-4ba6-b5fb-8a1a6c2edeaf" alt=""><figcaption></figcaption></figure>
3. Under **Users and groups**, click **None Selected**.
4. Search for and select the users or groups that should be provisioned. The group **GuardWare Protect All User** should be selected mandatorily. \
   \
   If the required GuardWare group does not exist, create the group from **Groups > New group**.&#x20;

   In **Group type**, select **Microsoft 365,** and in **Group name,** enter **Guardware Protect All Users,** leave the remaining group details as they are.<br>

   <figure><img src="https://2233655803-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi6thNYq9Il6WA2mTbj6X%2Fuploads%2Fv2V5o5GB9Og9UblyoVHE%2Fimage.png?alt=media&amp;token=d15256ca-3b27-404a-8d27-176321e5dcfc" alt=""><figcaption></figcaption></figure>
5. Click **Assign**.\
   ![](https://2233655803-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi6thNYq9Il6WA2mTbj6X%2Fuploads%2F4rGXxEKv6bp0gUCfoisv%2Fimage.png?alt=media\&token=15e7549d-bd25-4f68-83ec-634871b25d74)

After completing the configuration and assigning the required users or groups:

6. Navigate to **Overview**.
7. Click **Start provisioning**.\ <br>

   <figure><img src="https://2233655803-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi6thNYq9Il6WA2mTbj6X%2Fuploads%2FLrW2LjOxYtK5E4N6rkQ7%2Fimage.png?alt=media&amp;token=d26d5f0f-48a4-47d3-a635-f422f4bca7e0" alt=""><figcaption></figcaption></figure>

Azure will begin provisioning the assigned users and groups to GuardWare.

## 5. Generate the GuardWare Proxy Key

After provisioning has completed, generate the Proxy Key in the GuardWare Management Console.

1. Log in to the **GuardWare Management Console**.
2. Navigate to **Security Groups**.
3. If a Proxy Key does not already exist, click the notification at the top of the page.<br>

   <figure><img src="https://2233655803-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fi6thNYq9Il6WA2mTbj6X%2Fuploads%2FLibNFAjTL1og2thiBqH2%2Fimage.png?alt=media&amp;token=2b8e05ad-efdc-4619-aed5-adc2a6562f15" alt=""><figcaption></figcaption></figure>
4. In **Actions**, click **Create Key**.

The Proxy Key is now generated for the GuardWare security groups.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.guardware.com/documentation/protect/azure-configurations/configure-azure-provisioning-in-guardware.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
