Setting up automatic user provisioning for Microsoft Azure

2026-07-07Last updated

To synchronize user management in Security Center SaaS with Microsoft Entra ID, you can set up automatic user provisioning with help from the Genetec™ Technical Assistance Center (GTAC).

Before you begin

What you should know

Invitation emails aren’t sent to automatically provisioned users.

Procedure

  1. Your integrator creates a new case with GTAC and includes the necessary information:
    • Email contact for the Microsoft Entra ID administrator with sufficient privileges and expertise to set up an application integration for their identity provider.
    • Domains used by the users during login. For example, for users who log in with myuser@company.com, the domain is company.com.
    • Security Center SaaS system name.

      The system name can be found in user preferences under the user name, or from the Select a system page in Security Center SaaS.

    • Security Center SaaS system ID. For example, SCC-200012-345678.

      This ID can be found in the License section of the About page in Genetec™ Configuration desktop.

    • Microsoft Entra ID Tenant ID.
    • Groups to be included in the synchronization scope.
      Note:
      Only direct-group membership is supported. Group nesting, indirect user membership, or automatic provisioning for guests or external Entra ID users is not supported.
  2. Genetec verifies the information in the case and schedules a call with the IT administrator to configure the setup together.
  3. Attend the setup call.
    Genetec helps you configure the following Provisioning settings in a new Microsoft Entra ID Enterprise application:
    • SCIM connection information.
    • Users and Groups attributes mapping required by Security Center SaaS.
  4. Define the scope of the automatic user provisioning by adding the required user groups to your Microsoft Entra ID Enterprise application.
    Best Practice:
    Only place user groups in the scope. Group nesting isn’t supported.
  5. After Microsoft Entra ID has completed initial provisioning of your groups, go to https://securitycentersaas.genetec.cloud and use the Configuration task to assign roles to your groups.
    Tip:
    Microsoft Entra ID pushes users and groups data to Security Center SaaS periodically, which might cause a delay in reflecting changes. To trigger an immediate update, see Forcing a synchronization in Microsoft Azure.

After you finish

Assign roles to users and groups imported from Microsoft Entra ID.