Folio
FeaturesFor teachersFor institutionsPricing
Resources
About
Back to Help Center
Technicalv1.0

Connect Microsoft Entra ID with SCIM

Provision and deactivate institution students and staff from Entra ID, Okta, or Google Workspace.

F

Folio Team

September 4, 2026 2 min read

On this page

  • Before you start
  • Microsoft Entra ID setup
  • Groups
  • Safe dry runs
  • Deactivation and audit

Connect Microsoft Entra ID with SCIM

Folio exposes a tenant-scoped SCIM 2.0 service for institution provisioning. A token can act only for the institution that issued it, and Folio stores only its hash.

Before you start

In Institution โ†’ Integrations, create a key with only the scim.write scope. Copy it when it appears; Folio cannot show it again. Keep ordinary read-only integration scopes on separate keys so each credential has one job.

Your tenant URL is shown in the SCIM section. It ends in /scim/v2.

Microsoft Entra ID setup

  1. In Entra ID, open your enterprise application and choose Provisioning.
  2. Choose Automatic provisioning.
  3. Paste Folio's tenant URL into Tenant URL.
  4. Paste the one-time Folio key into Secret Token, then test the connection.
  5. Map userName to the person's email address. Map active, displayName, and externalId normally.
  6. Map userType to either student or staff. For staff, roles[primary eq true].value may be staff, department_head, program_head, secretary, or coordinator. Folio deliberately refuses SCIM-created admin, registrar, and helpdesk privilege.
  7. Start with a small assigned group and review the institution audit log before widening scope.

Okta and Google Workspace use the same base URL and bearer token fields.

Groups

Folio publishes existing departments and programs as SCIM groups. Department names begin with Department: and program names begin with Program:. Change group membership in your identity provider; Folio does not let SCIM create or rename academic structures.

Student users may join program groups. Staff users may join department or program groups. Folio rejects cross-institution and unknown resource IDs.

Safe dry runs

For a manual validation that must not change membership, add the request header X-Folio-SCIM-Dry-Run: true or the query parameter dryRun=true. Folio returns the account, membership, or group changes it would make. Entra's normal provisioning job should not use dry-run mode.

Deactivation and audit

Setting active to false removes the SCIM-managed institution membership and revokes the user's active sessions. It does not delete the Folio account or course/grade records. Every SCIM create, update, deactivation, and group change is written to the institution audit log with the issuing key ID.

Revoke the key immediately from Integrations if it is exposed. A revoked key cannot authenticate to any SCIM endpoint.

Was this helpful?

Discussion

Sign in to join the discussion โ†’

No comments yet. Be the first to share your thoughts.

Folio

The integrated research workspace: discover, read, write, cite, and prove your work.

Built for academic integrityGDPR compliant

Product

  • Features
  • For PhD students
  • For teachers
  • For institutions
  • Literature reviews
  • Discovery
  • Research Radar
  • Integrity
  • Surveyor
  • Classroom
  • Browser extension
  • Pricing

Resources

  • Free tools
  • Folio Studio
  • Citation generator
  • Reference checker
  • Word counter
  • How to cite
  • Validated scales
  • Guides
  • Templates
  • Compare
  • Blog
  • Changelog
  • Help center
  • All resources

Company

  • About
  • Careers
  • Sign up
  • Log in
  • Contact

Legal

  • Terms
  • Privacy
  • Trust & security
  • GDPR & data rights
  • Refund policy
  • Academic integrity

ยฉ 2026 Folio. All rights reserved.

Made for researchers.