Connect Entra ID or Okta
Let Microsoft Entra ID or Okta push users and groups to Surface over SCIM.
These work the other way round from Google: your identity provider pushes users to Surface. Surface gives you an endpoint URL and a secret token to paste into Entra or Okta.
Before you begin
- Admin access to Entra ID or Okta.
- A Surface app registered in your identity provider. In Entra: an Enterprise application. In Okta: an app integration with provisioning support. Create it first if it does not exist.
- The Owner or Admin role in Surface.
Generate the token
Open Integrations, Apps tab. On the Microsoft Entra ID or Okta card, click Connect, then Generate token.
Copy both values now
Surface shows a SCIM endpoint (Tenant URL) and a Secret token. The token is shown only once.
Paste them into your identity provider
Open your Surface app, go to Provisioning, and choose Automatic. Paste the endpoint as the Tenant URL and the token as the Secret token. Click Test connection.
Assign and start
Assign the users or groups that should have access, then click Start provisioning.
What happens next
Users arrive in Surface as your identity provider pushes them. The card shows Connected once the first ones land. The Users page stays in sync from then on.
Lost the token?
Click Connect again and Regenerate token. The old token stops working; paste the new one into your identity provider.