SCIM configuration
SCIM is how Microsoft Entra copies people and groups into AuthCop automatically. You set up provisioning in Microsoft Entra, using the URLs and tokens on this page. Once it's running, new students, staff and group changes reach AuthCop without you doing anything.
Who can use this page: Global Administrator.

Two separate connections
| Section | What it syncs | Used for |
|---|---|---|
| Users | Students (and other users who sign in through AuthCop) and their groups. | The Users and Groups pages, and the sign-in check. |
| Administrators | Staff who use the admin portal, and their groups. | Admin Users and Admin Groups. |
Set up each one as its own provisioning app in Microsoft Entra.
Set up provisioning in Microsoft Entra
- Copy the SCIM User URL (or SCIM Administrator URL) from this page.
- Select Regenerate Token, confirm, and copy the new SCIM Bearer Token. It is only shown once.
- In Microsoft Entra, open the provisioning settings for your AuthCop enterprise application.
- Paste the URL into Tenant URL and the token into Secret Token.
- Test the connection, choose which users and groups to sync, and start provisioning.

Tokens are hidden after you leave the page. They show as ********. If you lose a token, regenerate it and update Microsoft Entra.
Regenerate a token
Select Regenerate Token and confirm.
The old token stops working straight away. Syncing from Microsoft Entra stops until you paste the new token into the provisioning settings. Only regenerate a token if it may have leaked, or if you are setting up provisioning.
How this affects the rest of AuthCop
- New users can only use AuthCop once they have synced. A student who isn't synced yet can't pass the sign-in check.
- Removed users stop being able to sign in through AuthCop after the next sync.
- Synced groups and their members can only be changed in Microsoft Entra. In AuthCop you can still mark a synced group as a Student Group.
- Administrators must be synced before they can sign in to the admin portal.