Prerequisites
Before configuring Directory Sync, make sure:- Microsoft SSO is configured for your Dema organization.
- You have at least the Application Administrator role in Microsoft Entra ID.
- You can access the enterprise application used for Dema SSO.
- You have selected a test user and decided which users or groups should have access to Dema.
- You have received the SCIM endpoint URL and secret token from your Dema representative.
Configure automatic provisioning
Step 1: Open the Dema enterprise application
- Sign in to the Microsoft Entra admin center.
- Go to Entra ID → Enterprise applications.
- Select the enterprise application already used for Dema SSO.
- Select Provisioning.
Step 2: Connect Entra ID to Dema
- Set Provisioning Mode to Automatic.
- Under Admin Credentials, enter the values provided by Dema:
- Tenant URL — enter the SCIM endpoint URL exactly as provided.
- Secret Token — enter the SCIM secret token.
- Select Test Connection.
- After the connection succeeds, select Save.
The SCIM endpoint and token are separate from the SAML values used for SSO. Do not enter the SSO Reply URL, Entity ID, or federation metadata URL here.
Step 3: Verify user attribute mappings
Open Mappings → Provision Microsoft Entra ID Users and confirm that the following SCIM attributes are mapped:Step 4: Set the provisioning scope
- Under Settings, set Scope to Sync only assigned users and groups.
- Review the users and groups already assigned to the enterprise application.
- Assign the test user if they are not already assigned.
- Keep automatic provisioning stopped until the test user has been verified.
Test with one user
Test the connection before enabling scheduled provisioning for everyone:- In the enterprise application, open Provisioning.
- Select Provision on demand.
- Search for and select the test user.
- Select Provision and review the result for each provisioning step.
- Ask your Dema representative to confirm that the user is active and that their name and email address are correct.
- If needed, update the test user’s name in Entra ID and provision them again to confirm that changes are synchronized.
Enable Directory Sync
After the test succeeds:- Reconfirm the users and groups assigned to the enterprise application.
- Return to the application’s Provisioning page.
- Start provisioning.
- Monitor Provisioning logs while Entra ID completes the initial cycle.
- Confirm in Dema that the expected users are active.
User lifecycle behavior
Directory Sync deactivates users instead of deleting them. This makes offboarding reversible and preserves the user’s existing Dema account if they are assigned again later.
Troubleshooting
If the issue continues, contact your Dema representative with the affected user’s email address, the provisioning timestamp, and the result shown in Entra ID. Do not include the secret token.
For more information, see Microsoft’s guides to automatic SCIM provisioning and on-demand provisioning.

