Brief Overview
WalkMe supports SCIM (System for Cross-domain Identity Management) provisioning through Microsoft Entra ID (formerly Azure AD). Entra ID acts as the identity source, and WalkMe automatically creates, updates, and removes assigned users and groups based on your provisioning settings.
Note:
You must be a WalkMe admin to turn on SCIM for your organization.
Access
Access SCIM Integration in the console:
- Open the WalkMe Console:
- Go to the Admin category
- Select Security & Audit
- Choose SCIM Integration
How It Works
Setting up SCIM with Entra ID takes four steps:
- Create a non-gallery enterprise application in Entra ID
- Connect Entra ID to WalkMe with your SCIM credentials
- Review the attribute mappings
- Assign users and groups, and start provisioning
Before you start
Create a SCIM integration in the WalkMe Console (see Access) and copy the SCIM base URL and credentials. Learn more.
Step 1: Create the application in Entra ID
- Sign in to the Microsoft Entra admin center
- Go to Entra ID > Enterprise applications > All applications
- Select New application
- Select Create your own application
- Add a descriptive name, for example: WalkMe SCIM Integration
- Select Integrate any other application you don't find in the gallery (Non-gallery)
- Select Create
Note:
Use a clear name so admins can identify the app's purpose, especially in environments with many enterprise applications.
Step 2: Connect Entra ID to WalkMe
- In the app's left menu, select Provisioning
- Select Get started
- Change Provisioning Mode from Manual to Automatic
- Expand Admin Credentials and add the following:
- Tenant URL: The SCIM base URL for your WalkMe data center
- Secret Token: The authentication value for the authorization type set in WalkMe:
- Basic Authentication: Convert the WalkMe-generated
Username:Password value to Base64 and add it as Basic <your_base64_string>
- Bearer Token: Paste the token generated by WalkMe
- Select Test Connection
- When the test succeeds, select Save
WalkMe data centers:
- US Data Center:
- Tenant URL (SCIM base URL): https://papi.walkme.com/deepui/api/scim/v2
- EU Data Center:
- Tenant URL (SCIM base URL): https://eu-papi.walkme.com/deepui/api/scim/v2
- SAP US Data Center (US01):
- Tenant URL (SCIM base URL): https://papi-us01.walkme.cloud.sap/deepui/api/scim/v2
- SAP EU Data Center (EU01):
- Tenant URL (SCIM base URL): https://papi-eu01.walkme.cloud.sap/deepui/api/scim/v2
- FedRAMP Data Center:
- Tenant URL (SCIM base URL): https://papi.walkmegov.com/deepui/api/scim/v2
- Canada Data Center:
- Tenant URL (SCIM base URL): https://papi-ca1.walkmedap.com/deepui/api/scim/v2
Step 3: Review attribute mappings
- On the Provisioning page, expand Mappings
- Select Provision Microsoft Entra ID Users
- Make sure the required WalkMe attributes are mapped:
- WalkMe attribute:
UserName
-
- Requirement: Must map to a stable, unique identifier, typically
userPrincipalName or mail
-
- Requirement: Must include at least one email address marked primary:
true
To sync groups:
- In Mappings, select Provision Microsoft Entra ID Groups
- Make sure displayName is mapped
- Select Save if you made changes
Step 4: Assign users and start provisioning
- In the app's left menu, go to Users or Groups
- Select Add User or Group
- Select the users or groups to sync to WalkMe
- Go back to the Provisioning tab
- Select Start provisioning
Note:
Provisioning doesn't start until you select Start provisioning.
The first cycle can take around 40 minutes. After it completes, assigned users appear in the WalkMe Console.
Troubleshooting
Connection test fails
- Make sure the Tenant URL matches your WalkMe data center
- Make sure the Secret Token format matches the authorization type set in WalkMe
Users or groups not syncing
- Make sure the app was created as a non-gallery enterprise application
- Make sure Provisioning Mode is set to Automatic
- Make sure the users or groups are assigned to the app
- Wait for the first provisioning cycle to complete before checking results
Attribute mapping issues
- Incorrect mappings can cause failed user creation, incomplete profile data, or group sync issues
- Go to Provisioning > Mappings and make sure userName, emails, and group displayName are mapped correctly
Technical Notes
- Only users and groups assigned to the enterprise application are provisioned. Other Entra ID users don't sync to WalkMe.
- Changes made in Entra ID sync to WalkMe in later provisioning cycles