---
language: en
title: Set up provisioning for Microsoft Entra ID
category: Single Sign-On und Bereitstellungen
summary: Learn how to enable provisioning in TuCalendi and Microsoft Entra ID to automatically sync users and groups.
---

# Set up provisioning for Microsoft Entra ID

With **Microsoft Entra ID** (formerly Azure Active Directory), you can provision user data and sync it with your TuCalendi users. In this article, you'll learn how to use the **provisioning feature** of Microsoft Entra ID. **This setup requires that you've already created an [SSO connection in TuCalendi](https://www.tucalendi.com/de/s/single-sign-on-und-bereitstellungen/single-sign-on-fuer-microsoft-entra-id-einrichten). If you haven't done this yet, you need to do it first before you can use provisioning.**

> [!WARNING]
> This feature is only available with a **TuCalendi Pro account**.

## The user provisioning feature

User data and groups set up in Entra ID can be **synced with TuCalendi**. For example, when a new user is added to Entra ID, a new user can **automatically be added to TuCalendi** and can then start working with TuCalendi.

You can use the provisioning feature with the following actions:

1. **Add, update and deactivate users**
2. **Add, update and remove groups**

**Note:**

Provisioning **can't remove users** from your TuCalendi account, but it **can deactivate** them.

To sync groups, you need a **paid license** for your Microsoft Entra account.

## Enable provisioning in TuCalendi

**1.** Open the SSO connection you already created ([set up SSO connection](https://www.tucalendi.com/de/s/single-sign-on-und-bereitstellungen/single-sign-on-fuer-microsoft-entra-id-einrichten)) and click **"Provision settings"**.

![TuCalendi provisioning settings](https://www.tucalendi.com/images/content/scim/de/tucalendi-bereitstellungs-einstellungen.png)

**2.** **Create a new secret token**, which you'll need to set up provisioning in the Entra ID application. To do this, click **"Create"**.

![Create token](https://www.tucalendi.com/images/content/scim/de/token-erstellen.png)

![Save token](https://www.tucalendi.com/images/content/scim/de/token-speichern.png)

**3.** Then **save everything** and you're done.

![Save provisioning](https://www.tucalendi.com/images/content/scim/de/bereitstellung-speichern.png)

## Enable provisioning in the Entra ID application

**1.** In the menu, click **"Provisioning"** to configure provisioning.

![Provisioning menu](https://www.tucalendi.com/images/content/scim/de/menu-bereitstellung.png)

**2.** Click **"Provisioning"** and select **"Automatic"** as the provisioning mode.

![Select automatic provisioning](https://www.tucalendi.com/images/content/scim/de/automatisch-auswaehlen.png)

**3.** **Click "Admin Credentials"**. Now you need to enter the data from TuCalendi into the Entra ID application. The following shows which data goes where.

![Enter provisioning data](https://www.tucalendi.com/images/content/scim/de/bereitstellungsdaten-eintragen.png)

After entering the data, click **"Test Connection"**. Once the connection has been tested, save it.

**4.** In the next option, **"Mappings"**, you can choose which areas should be provisioned. You can provision **users and groups** (see the note above).

If you provision users, the following attributes must be mapped:

- **userPrincipalName**
- **softDelete**
- **givenName**
- **surname**

See the image for the exact mapping. The **"userName" attribute maps to "userPrincipalName"**, which is usually the user's email address. If that's not the case, the **"userName"** attribute should be **mapped to the user's email address**. **It's very important** that the "userName" attribute is an email address, because it's needed for **matching**.

![User attributes](https://www.tucalendi.com/images/content/scim/de/benutzer-attribute.png)

All other attributes should be **removed**.

If you provision groups, the following attributes must be mapped:

- **displayName**
- **members**

See the image for the exact mapping. The attributes **"displayName"** and **"members" are required**. **"displayName" is very important** and is **needed for matching**.

![Group attributes](https://www.tucalendi.com/images/content/scim/de/gruppen-attribute.png)

All other attributes should be **removed**.

**5.** Once everything is set up, you can **start provisioning**.

![Start provisioning](https://www.tucalendi.com/images/content/scim/de/bereitstellung-starten.png)

If everything is set up correctly, the assigned users and/or groups will now be **automatically provisioned and synced**.

If you run into any problems or difficulties during setup, our **support team** (support@tucalendi.com) will be happy to help and will assist you with the setup as best they can.