Before you begin
You’ll need:- A Windmill enterprise application in Entra ID with SSO active in Windmill. See Set up SAML SSO.
- The Tenant URL and Secret token from Windmill. In Settings > Security, select Set up SCIM, then Generate token. See Set up SCIM provisioning.
- Application Administrator or Cloud Application Administrator access in Entra ID.
Turn on provisioning
Open the Windmill app
Start automatic provisioning
Enter the Windmill credentials
Review the standard attribute mappings
Under Mappings, open Provision Microsoft Entra ID Users. The default mappings already cover most of the fields Windmill supports. Confirm these rows are present.Add the Windmill extension attributes
Job level, start date, pronouns, and gender live in the Windmill extension schema. Add them to the app’s attribute list, then map a source attribute to each one.Open the attribute list
Add the attributes
Map a source attribute to each one
extensionAttribute1 or a custom directory extension, and choose the new Target attribute. Set Apply this mapping to Always, then select Ok.Repeat for each attribute, then select Save on the mappings page.extensionAttribute1 to extensionAttribute15 fields, or a directory extension synced from your HR system. For start date, use the YYYY-MM-DD format. Windmill skips dates in other formats.Map the manager
Keep the defaultmanager mapping. Entra ID resolves it to the manager’s SCIM ID in Windmill automatically, as long as both the manager and the report are in the app’s provisioning scope. If the manager isn’t provisioned yet, Windmill keeps the reference and applies it once the manager exists.
See Manager references for how Windmill resolves the value.
Assign users and groups
Entra ID provisions the people and groups in the app’s scope.Set the scope
Assign users and groups
Turn provisioning on
Set the field sources in Windmill
Windmill stores every value Entra ID sends. It writes a value to an employee’s profile only when SCIM is the source for that field. Fields with no source are claimed by SCIM automatically. Fields owned by another system, like job level from your HRIS (Human Resources Information System), keep the other system’s value until you switch the source. To have Entra ID manage a field, open Settings > Org Chart, open Company defaults, and set the field’s source to SCIM. Windmill applies the latest values Entra ID sent within a few minutes. See How SCIM works with field sources.Verify the setup
- In Windmill, the SCIM card in Settings > Security shows Active and a recent Last sync time.
- Open a provisioned employee in Settings > Org Chart. The Sources tab shows SCIM for the fields Entra ID manages, and the Info tab shows the values.
- In Entra ID, Provisioning > Provisioning logs shows each user and group operation and any errors.
FAQs
Test Connection fails.
Test Connection fails.
The provisioning log shows an error that says SCIM provisioning is paused.
The provisioning log shows an error that says SCIM provisioning is paused.
Job level, start date, pronouns, or gender aren't reaching Windmill.
Job level, start date, pronouns, or gender aren't reaching Windmill.
urn:ietf:params:scim:schemas:extension:gowindmill:2.0:User: and that the mapping is saved with Apply this mapping set to Always. Then check the field’s source in Windmill under Settings > Org Chart. If another system owns the field, switch it to SCIM.The manager isn't set in Windmill.
The manager isn't set in Windmill.
How long do changes take to reach Windmill?
How long do changes take to reach Windmill?
Do assigned people get an invite email or Slack message?
Do assigned people get an invite email or Slack message?