About
Users of Azure can integrate with Insightly via SAML & SCIM and once setup has occurred in both Insightly and Azure, users can be provisioned. The process defined in this article will guide Insightly System Admins through the process up SAML & SCIM setup for Azure; this process works in tandem with the setup of SAML and SCIM within Insightly as detailed in the SSO for Azure AD/ Entra ID and Setting Up SAML and SCIM Integrations article.
Step 1: Add a New Enterprise Application in Azure
- Navigate to the Azure Portal: 
 https://portal.azure.com/#view/Microsoft_AAD_IAM/StartboardApplicationsMenuBlade/~/AppAppsPreview/menuId~/null
- Select New Application.
- In the search bar, type Insightly SAML. 
- Choose Insightly SAML from the results and click Create. 
Step 2: Configure SAML Single Sign-On (SSO)
- In the Enterprise Application menu, navigate to Single sign-on. 
- Choose SAML as the single sign-on method. 
Basic SAML Configuration:
- Click Edit next to Basic SAML Configuration. 
- Copy the following SAML login URL from Insightly CRM Application:https://crm.na1.insightly.com/settings/Saml or Within Insightly, go to System Settings > Security > SAML and SCIM, copy the Sign-in page URL field. 
- Paste this URL into both fields: - Identifier (Entity ID) 
- Reply URL (Assertion Consumer Service URL) 
 
SAML Certificate Configuration:
- Download the SAML Certificate from Azure in either Base64 or Federation Metadata XML format. Base64 is recommended. 
- Go to the SAML settings page in Insightly:
- Upload the certificate or the metadata. Only one is needed. 
- Select 'Enforce SAML Login' option 
- Click Save button to apply the changes.(For configuration of SAML within Insightly, the Setting Up SAML & SCIM Integrations article can be reviewed.) 
- Once SAML Login is enforced, log into Insightly through https://myapps.microsoft.com/ 
Step 3. Configure SCIM
Enable SCIM Provisioning in Insightly:
- On the SAML configuration page in Insightly, check the box for Enable SCIM Provisioning and press Save.
- This will generate an auth token and reveal the SCIM endpoint.
Enable SCIM Provisioning in Azure:
- In Azure, navigate to the Provisioning section for the app. 
- Click Get Started.
- From the From the Provisioning Mode dropdown, select Automatic.
- Paste the Tenant URL and Secret Token from Insightly into the corresponding fields. 
- Press Test Connection. 
- If successful, a notification will appear in the top-right corner. 
- Click Save to complete the setup. 
- On the Provisioning screen, click Start Provisioning. 
Step 4: Assign Users and Manage Provisioning
- SAML and SCIM are now set up.
- You can assign users to the app by navigating to the Users and Groups section in Azure.
- User Provisioning occurs on a scheduled basis, so new users may not immediately appear in Insightly. You can manually trigger provisioning via the Provision on demand option if necessary.