---
title: Connect Entra ID or Okta
description: Let Microsoft Entra ID or Okta push users and groups to Surface over SCIM.
---

These work the other way round from Google: your identity provider **pushes** users to Surface. Surface gives you an endpoint URL and a secret token to paste into Entra or Okta.

## Before you begin

- Admin access to Entra ID or Okta.
- A Surface app registered in your identity provider. In Entra: an Enterprise application. In Okta: an app integration with provisioning support. Create it first if it does not exist.
- The Owner or Admin role in Surface.

1. **Generate the token**

    Open **Integrations**, **Apps** tab. On the **Microsoft Entra ID** or **Okta** card, click **Connect**, then **Generate token**.

2. **Copy both values now**

    Surface shows a **SCIM endpoint (Tenant URL)** and a **Secret token**. The token is shown only once.

3. **Paste them into your identity provider**

    Open your Surface app, go to **Provisioning**, and choose **Automatic**. Paste the endpoint as the Tenant URL and the token as the Secret token. Click **Test connection**.

4. **Assign and start**

    Assign the users or groups that should have access, then click **Start provisioning**.

## What happens next

Users arrive in Surface as your identity provider pushes them. The card shows **Connected** once the first ones land. The [Users](/surface/admin/users-and-roles) page stays in sync from then on.

## Lost the token?

Click **Connect** again and **Regenerate token**. The old token stops working; paste the new one into your identity provider.
