Configure Zscaler ZNet for automatic user provisioning with Microsoft Entra ID
In brief
The guide now consistently refers to the application, tenant, SCIM API, and gallery entry as Zscaler ZNet.
What Entra admins need to know
Administrators following the guide should search for and configure Zscaler ZNet in the Microsoft Entra application gallery. No action is required for existing configurations.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Configure Zscaler ZNet for automatic user provisioning with Microsoft Entra ID
The objective of this article is to demonstrate the steps to be performed in Zscaler ZNet and Microsoft Entra ID to configure Microsoft Entra ID to automatically provision and de-provision users and/or groups to Zscaler.Zscaler ZNet.
The scenario outlined in this article assumes that you already have the following:
[!INCLUDE common-prerequisites.md].
- A Zscaler
tenant.ZNet tenant - A user account in Zscaler ZNet with Admin
permissions.permissions
Step 1: Add Zscaler ZNet from the gallery
Before configuring Zscaler ZNet for automatic user provisioning with Microsoft Entra ID, you need to add Zscaler ZNet from the Microsoft Entra application gallery to your list of managed SaaS applications.
To add Zscaler ZNet from the Microsoft Entra application gallery, perform the following steps:
Sign in to the Microsoft Entra admin center as at least a Cloud Application Administrator.
Browse to Entra ID > Enterprise apps > New application.
In the search box, type Zscaler ZNet, select Zscaler ZNet from result panel then select Add button to add the application.
Step 2: Assign users to Zscaler ZNet
Microsoft Entra ID uses a concept called "assignments" to determine which users should receive access to selected apps. In the context of automatic user provisioning, only the users and/or groups that have been "assigned" to an application in Microsoft Entra ID are synchronized.
Before configuring and enabling automatic user provisioning, you should decide which users and/or groups in Microsoft Entra ID need access to Zscaler.Zscaler ZNet. Once decided, you can assign these users and/or groups to Zscaler ZNet by following the instructions here:
Important tips for assigning users to Zscaler ZNet
It's recommended that a single Microsoft Entra user is assigned to Zscaler ZNet to test the automatic user provisioning configuration. Additional users and/or groups may be assigned later.
When assigning a user to
Zscaler,Zscaler ZNet, you must select any valid application-specific role (if available) in the assignment dialog. Users with the Default Access role are excluded from provisioning.
Step 3: Configure automatic user provisioning to Zscaler ZNet
This section guides you through the steps to configure the Microsoft Entra provisioning service to create, update, and disable users and/or groups in Zscaler ZNet based on user and/or group assignments in Microsoft Entra ID.
Configure automatic user provisioning for Zscaler ZNet in Microsoft Entra ID
Sign in to the Microsoft Entra admin center as at least a Cloud Application Administrator.
Browse to Entra ID > Enterprise apps > Zscaler ZNet.
Select the Provisioning tab.

Select + New configuration.

Under the Admin Credentials section, enter the Tenant URL and Secret Token of your Zscaler ZNet Beta account as described later in this article.
To obtain the Tenant URL and Secret Token, navigate to Administration > Authentication Settings in the Zscaler ZNet portal user interface and select SAML under Authentication Type.

Select Enable SCIM-Based Provisioning to retrieve Base URL and Bearer Token, then save the settings. Copy the Base URL to Tenant URL, and Bearer Token to Secret Token.
Upon populating the fields shown in Step 5, select Test Connection to ensure Microsoft Entra ID can connect to
Zscaler.Zscaler ZNet. If the connection fails, ensure your Zscaler ZNet account has Admin permissions and try again.
Select Attribute Mapping in the left panel and select users.
Review the user attributes that are synchronized from Microsoft Entra ID to Zscaler ZNet in the Attribute Mapping section. The attributes selected as Matching properties are used to match the user accounts in Zscaler ZNet for update operations. Select the Save button to commit any changes.
Attribute Type Supported for filtering Required by Zscaler ZNet userName String ✓ ✓ externalId String ✓ Select Groups.
Review the group attributes that are synchronized from Microsoft Entra ID to Zscaler ZNet in the Attribute Mapping section. The attributes selected as Matching properties are used to match the groups in Zscaler ZNet for update operations. Select the Save button to commit any changes.
Attribute Type Supported for filtering Required by Zscaler ZNet displayName String ✓ ✓ members Reference
@@ -1,15 +1,15 @@ ----title: Configure Zscaler for automatic user provisioning with Microsoft Entra ID-description: Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Zscaler.+title: Configure Zscaler ZNet for automatic user provisioning with Microsoft Entra ID+description: Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Zscaler ZNet. ms.topic: how-to ms.date: 03/30/2026 ms.custom: sfi-image-nochange-# Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Zscaler so that I can streamline the user management process and ensure that users have the appropriate access to Zscaler.+# Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Zscaler ZNet so that I can streamline the user management process and ensure that users have the appropriate access to Zscaler ZNet. --- -# Configure Zscaler for automatic user provisioning with Microsoft Entra ID+# Configure Zscaler ZNet for automatic user provisioning with Microsoft Entra ID -The objective of this article is to demonstrate the steps to be performed in Zscaler and Microsoft Entra ID to configure Microsoft Entra ID to automatically provision and de-provision users and/or groups to Zscaler.+The objective of this article is to demonstrate the steps to be performed in Zscaler ZNet and Microsoft Entra ID to configure Microsoft Entra ID to automatically provision and de-provision users and/or groups to Zscaler ZNet. > [!NOTE] > This article describes a connector built on top of the Microsoft Entra user provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).@@ -19,70 +19,70 @@ The objective of this article is to demonstrate the steps to be performed in Zsc The scenario outlined in this article assumes that you already have the following: -[!INCLUDE [common-prerequisites.md](~/identity/saas-apps/includes/common-prerequisites.md)].-* A Zscaler tenant.-* A user account in Zscaler with Admin permissions.+[!INCLUDE [common-prerequisites.md](~/identity/saas-apps/includes/common-prerequisites.md)]+* A Zscaler ZNet tenant+* A user account in Zscaler ZNet with Admin permissions > [!NOTE]-> The Microsoft Entra provisioning integration relies on the Zscaler SCIM API, which is available to Zscaler developers for accounts with the Enterprise package.+> The Microsoft Entra provisioning integration relies on the Zscaler ZNet SCIM API, which is available to Zscaler ZNet developers for accounts with the Enterprise package. -## Step 1: Add Zscaler from the gallery+## Step 1: Add Zscaler ZNet from the gallery -Before configuring Zscaler for automatic user provisioning with Microsoft Entra ID, you need to add Zscaler from the Microsoft Entra application gallery to your list of managed SaaS applications.+Before configuring Zscaler ZNet for automatic user provisioning with Microsoft Entra ID, you need to add Zscaler ZNet from the Microsoft Entra application gallery to your list of managed SaaS applications. -**To add Zscaler from the Microsoft Entra application gallery, perform the following steps:**+**To add Zscaler ZNet from the Microsoft Entra application gallery, perform the following steps:** 1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator). 1. Browse to **Entra ID** > **Enterprise apps** > **New application**.-1. In the search box, type **Zscaler**, select **Zscaler** from result panel then select **Add** button to add the application.+1. In the search box, type **Zscaler ZNet**, select **Zscaler ZNet** from result panel then select **Add** button to add the application. - +  -## Step 2: Assign users to Zscaler+## Step 2: Assign users to Zscaler ZNet Microsoft Entra ID uses a concept called "assignments" to determine which users should receive access to selected apps. In the context of automatic user provisioning, only the users and/or groups that have been "assigned" to an application in Microsoft Entra ID are synchronized. -Before configuring and enabling automatic user provisioning, you should decide which users and/or groups in Microsoft Entra ID need access to Zscaler. Once decided, you can assign these users and/or groups to Zscaler by following the instructions here:+Before configuring and enabling automatic user provisioning, you should decide which users and/or groups in Microsoft Entra ID need access to Zscaler ZNet. Once decided, you can assign these users and/or groups to Zscaler ZNet by following the instructions here: * [Assign a user or group to an enterprise app](~/identity/enterprise-apps/assign-user-or-group-access-portal.md) -### Important tips for assigning users to Zscaler+### Important tips for assigning users to Zscaler ZNet -* It's recommended that a single Microsoft Entra user is assigned to Zscaler to test the automatic user provisioning configuration. Additional users and/or groups may be assigned later.+* It's recommended that a single Microsoft Entra user is assigned to Zscaler ZNet to test the automatic user provisioning configuration. Additional users and/or groups may be assigned later. -* When assigning a user to Zscaler, you must select any valid application-specific role (if available) in the assignment dialog. Users with the **Default Access** role are excluded from provisioning.+* When assigning a user to Zscaler ZNet, you must select any valid application-specific role (if available) in the assignment dialog. Users with the **Default Access** role are excluded from provisioning. -## Step 3: Configure automatic user provisioning to Zscaler+## Step 3: Configure automatic user provisioning to Zscaler ZNet -This section guides you through the steps to configure the Microsoft Entra provisioning service to create, update, and disable users and/or groups in Zscaler based on user and/or group assignments in Microsoft Entra ID.+This section guides you through the steps to configure the Microsoft Entra provisioning service to create, update, and disable users and/or groups in Zscaler ZNet based on user and/or group assignments in Microsoft Entra ID. > [!NOTE]-> Open a [support ticket](https://help.zscaler.com/) to create a domain on Zscaler.+> Open a [support ticket](https://help.zscaler.com/) to create a domain on Zscaler ZNet. > [!TIP]-> You may also choose to enable SAML-based single sign-on for Zscaler, following the instructions provided in the [Zscaler single sign-on article](zscaler-tutorial.md). Single sign-on can be configured independently of automatic user provisioning, though these two features complement each other.+> You may also choose to enable SAML-based single sign-on for Zscaler ZNet, following the instructions provided in the [Zscaler ZNet single sign-on article](zscaler-tutorial.md). Single sign-on can be configured independently of automatic user provisioning, though these two features complement each other. > [!NOTE] > When users and groups are provisioned or de-provisioned we recommend to periodically restart provisioning to ensure that group memberships are properly updated. Doing a restart will force our service to re-evaluate all the groups and update the memberships. Please be aware that the restart can take time if you're syncing all users and groups in your tenant or have assigned large groups with 50K+ members. -<a name='to-configure-automatic-user-provisioning-for-zscaler-in-azure-ad'></a>+<a name='to-configure-automatic-user-provisioning-for-zscaler-znet-in-azure-ad'></a> -### Configure automatic user provisioning for Zscaler in Microsoft Entra ID+### Configure automatic user provisioning for Zscaler ZNet in Microsoft Entra ID 1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator). -1. Browse to **Entra ID** > **Enterprise apps** > **Zscaler**.+1. Browse to **Entra ID** > **Enterprise apps** > **Zscaler ZNet**. 1. Select the **Provisioning** tab. - +  1. Select **+ New configuration**.  -1. Under the **Admin Credentials** section, enter the **Tenant URL** and **Secret Token** of your Zscaler Beta account as described later in this article.+1. Under the **Admin Credentials** section, enter the **Tenant URL** and **Secret Token** of your Zscaler ZNet Beta account as described later in this article. -1. To obtain the **Tenant URL** and **Secret Token**, navigate to **Administration > Authentication Settings** in the Zscaler portal user interface and select **SAML** under **Authentication Type**.+1. To obtain the **Tenant URL** and **Secret Token**, navigate to **Administration > Authentication Settings** in the Zscaler ZNet portal user interface and select **SAML** under **Authentication Type**.  @@ -92,7 +92,7 @@ This section guides you through the steps to configure the Microsoft Entra provi 1. Select **Enable SCIM-Based Provisioning** to retrieve **Base URL** and **Bearer Token**, then save the settings. Copy the **Base URL** to **Tenant URL**, and **Bearer Token** to **Secret Token**. -1. Upon populating the fields shown in Step 5, select **Test Connection** to ensure Microsoft Entra ID can connect to Zscaler. If the connection fails, ensure your Zscaler account has Admin permissions and try again.+1. Upon populating the fields shown in Step 5, select **Test Connection** to ensure Microsoft Entra ID can connect to Zscaler ZNet. If the connection fails, ensure your Zscaler ZNet account has Admin permissions and try again.  @@ -106,9 +106,9 @@ This section guides you through the steps to configure the Microsoft Entra provi 1. Select **Attribute Mapping** in the left panel and select **users**. -1. Review the user attributes that are synchronized from Microsoft Entra ID to Zscaler in the **Attribute Mapping** section. The attributes selected as **Matching** properties are used to match the user accounts in Zscaler for update operations. Select the **Save** button to commit any changes.+1. Review the user attributes that are synchronized from Microsoft Entra ID to Zscaler ZNet in the **Attribute Mapping** section. The attributes selected as **Matching** properties are used to match the user accounts in Zscaler ZNet for update operations. Select the **Save** button to commit any changes. - |Attribute|Type|Supported for filtering|Required by Zscaler|+ |Attribute|Type|Supported for filtering|Required by Zscaler ZNet| |---|---|---|---| |userName|String|✓|✓ |externalId|String||✓@@ -120,9 +120,9 @@ This section guides you through the steps to configure the Microsoft Entra provi 1. Select **Groups**. -1. Review the group attributes that are synchronized from Microsoft Entra ID to Zscaler in the **Attribute Mapping** section. The attributes selected as **Matching** properties are used to match the groups in Zscaler for update operations. Select the **Save** button to commit any changes.+1. Review the group attributes that are synchronized from Microsoft Entra ID to Zscaler ZNet in the **Attribute Mapping** section. The attributes selected as **Matching** properties are used to match the groups in Zscaler ZNet for update operations. Select the **Save** button to commit any changes. - |Attribute|Type|Supported for filtering|Required by Zscaler|+ |Attribute|Type|Supported for filtering|Required by Zscaler ZNet| |---|---|---|---| |displayName|String|✓|✓ |members|Reference|| 