SCIM (System for Cross-domain Identity Management) lets your identity provider manage user accounts in other apps for you. When you connect Microsoft Entra ID to Fellow with SCIM, the people you assign to Fellow in Entra ID are created, updated, and deactivated in Fellow automatically. This guide walks you through enabling SCIM in Fellow, connecting it in Entra ID, and testing it before you turn it on.
Note: SCIM provisioning is available on the Enterprise plan and can only be set up by a workspace administrator.
Supported Features
Feature | Description |
Create users | People you assign to the Fellow application in Entra ID are automatically created in Fellow. |
Update user attributes | Changes to a user's name, job title, or manager in Entra ID are synced to Fellow. |
Deactivate users | Removing a user from the Fellow application, or blocking their sign-in in Entra ID, marks their Fellow account as Disabled. |
Reactivate users | Reassigning a user to the Fellow application restores their access and marks their account as Enabled. |
Group provisioning | You can sync Entra ID groups to Fellow as Teams (optional). |
Requirements
A Fellow account on the Enterprise plan
A Fellow workspace administrator account
A Microsoft Entra ID account with at least the Application Administrator role, or help from your IT team
Step 1: Enable SCIM in Fellow
Sign in to Fellow using a workspace administrator account.
Click your workspace logo, then go to Workspace Settings > Integrations > SCIM2 card.
Click the Connect button in the top-right corner of the page.
Click Regenerate SCIM token and confirm when prompted.
Copy the token from the Copy your SCIM token window and store it somewhere secure. You'll need it in Part 2. The token is only shown once, so copy it before you close the window.
Step 2: Configure SCIM in Microsoft Entra ID
2.1 Create the Fellow application
Sign in to the Microsoft Entra admin center at
https://entra.microsoft.com.Go to Identity > Applications > Enterprise applications > New application.
Create your own application.
Enter
Fellowas the name, select Integrate any other application you don't find in the gallery (Non-gallery), and click Create.
2.2 Connect provisioning to Fellow
In the Fellow application, select Provisioning in the left menu, then click Get started.
Set Provisioning Mode to Automatic.
Under Admin Credentials, enter the following:
Tenant URL:
https://fellow.app/scim/v2Secret Token: the SCIM token you copied in Part 1
Click Test Connection and wait for the success message.
Click Create.
2.3 Review attribute mappings
Fellow identifies each user by their email address, so Entra ID needs to send each user's email as their username.
In the "Attribute mapping" section, check that
userPrincipalNameattribute from Entra ID (source) is mapped to theuserNameattribute (it should be a default value)Then, you can check in your workspace users list that the "User principal name" field is the email address:
2.4 Choose who gets provisioned
Under Provisioning → Settings, set Scope to Sync only assigned users and groups.
(Optional) Add an email address under Notification Email to get alerts when provisioning fails.
Select Users and groups in the left menu, click + Add user/group, and assign the users and groups who should have access to Fellow.
Note: Assign groups that contain users directly. Members of nested groups (groups inside other groups) aren't provisioned.
2.5 Test and turn on provisioning
Go to Provisioning → Provision on demand, select one user, and click Provision. Check that the result shows success.
In Fellow, go to Workspace Settings → Users & teams and check that the user now appears in the list.
Back in Entra ID, set Provisioning Status to On and click Save.
You're all set. The first sync runs right away. After that, Entra ID syncs about every 40 minutes, so changes you make in Entra ID can take a little while to appear in Fellow.
Troubleshooting & Tips
Changing email addresses or domains? Contact the Fellow support team before you make the change in Entra ID. This also applies to merging user accounts or moving users between domains, and helps you avoid provisioning errors.
Review your assignments before turning provisioning on. Every provisioned user receives a Fellow welcome email.
Use the provisioning logs to find issues. If a user doesn't appear in Fellow, open Provisioning logs in the Fellow application in Entra ID to see which user failed and why.
Set up sign-in separately. SCIM manages user accounts, while SSO lets users sign in with their Entra ID credentials. To set up SSO, follow the Custom OIDC SSO Integration Guide.
Looking for Microsoft 365 User sync? Fellow's Microsoft 365 User sync is a separate feature, found under Workspace Settings > Integrations > User sync. This guide covers SCIM provisioning only.
If you need help with this process, contact Fellow Support through the Intercom bubble or through [email protected].













