Skip to content
OnTrackio

Provisioning

OnTrackio + Microsoft Entra ID

OAuth sign-on on every tier, SCIM 2.0 provisioning verified against Entra's own request quirks.

What you get

  • Microsoft sign-in on every tier: users authenticate with their work account, no passwords to manage
  • Optional allowed-domains restriction so only your tenant's domains can authenticate
  • SCIM 2.0 provisioning from Entra: joiners, movers, and leavers flow automatically
  • Entra group membership mapped to roles, with manual assignments protected from sync
  • SAML 2.0 as an alternative sign-on rail if your policy prefers it over OAuth

How it connects

Sign-on uses Microsoft's standard OAuth flow and works on every tier out of the box. Provisioning uses a per-workspace SCIM 2.0 endpoint that you register in Entra as a custom enterprise application; the setup guide covers the exact attribute mappings. The implementation was wire-verified against Entra's real provisioning traffic, including Entra's habit of sending booleans as strings, which we discovered and fixed by testing against the real thing rather than the specification.

What it deliberately does not do

OnTrackio is not in the Entra application gallery, so provisioning setup is the documented manual enterprise-app flow rather than a one-click tile. Intune device data is a separate concern: the endpoint agent covers device inventory, and Entra covers identity.

Plan note. Microsoft SSO is on every tier; SCIM 2.0 and SAML 2.0 are Enterprise-tier features. Pricing is public.

Frequently asked questions

Why is OnTrackio not in the Entra gallery?

Gallery submissions are queued behind Microsoft's process and we chose not to wait for it to ship the integration. The custom enterprise-app route uses exactly the same SCIM standard, takes about 25 minutes with the guide, and behaves identically once connected.

Do we need Entra P1 or P2 licensing?

Automatic SCIM provisioning in Entra requires a plan that includes it, which is Microsoft's licensing question rather than ours. Plain Microsoft sign-in to OnTrackio has no Entra plan requirement at all.

Can we restrict sign-in to our company domains?

Yes. The allowed-domains setting rejects authentication from any domain you have not listed, with a per-user bypass for external collaborators you explicitly invite.

All integrations: the full list. Identity posture, sub-processors, and residency: the security page.

See Microsoft Entra ID connected to a live workspace

A 30-minute demo covers the setup, the day-two behaviour, and the honest boundaries. Public pricing, no discovery-call gauntlet.