Microsoft Entra ID
Provisioning

Configure Zscaler ZNet for automatic user provisioning with Microsoft Entra ID

In brief

The guide now consistently refers to the application, tenant, SCIM API, and gallery entry as Zscaler ZNet.

What Entra admins need to know

Administrators following the guide should search for and configure Zscaler ZNet in the Microsoft Entra application gallery. No action is required for existing configurations.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure Zscaler ZNet for automatic user provisioning with Microsoft Entra ID

The objective of this article is to demonstrate the steps to be performed in Zscaler ZNet and Microsoft Entra ID to configure Microsoft Entra ID to automatically provision and de-provision users and/or groups to Zscaler.Zscaler ZNet.

The scenario outlined in this article assumes that you already have the following:

[!INCLUDE common-prerequisites.md].

  • A Zscaler tenant.ZNet tenant
  • A user account in Zscaler ZNet with Admin permissions.permissions

Step 1: Add Zscaler ZNet from the gallery

Before configuring Zscaler ZNet for automatic user provisioning with Microsoft Entra ID, you need to add Zscaler ZNet from the Microsoft Entra application gallery to your list of managed SaaS applications.

To add Zscaler ZNet from the Microsoft Entra application gallery, perform the following steps:

  1. Sign in to the Microsoft Entra admin center as at least a Cloud Application Administrator.

  2. Browse to Entra ID > Enterprise apps > New application.

  3. In the search box, type Zscaler ZNet, select Zscaler ZNet from result panel then select Add button to add the application.

    Screenshot of Zscaler ZNet in the results list.

Step 2: Assign users to Zscaler ZNet

Microsoft Entra ID uses a concept called "assignments" to determine which users should receive access to selected apps. In the context of automatic user provisioning, only the users and/or groups that have been "assigned" to an application in Microsoft Entra ID are synchronized.

Before configuring and enabling automatic user provisioning, you should decide which users and/or groups in Microsoft Entra ID need access to Zscaler.Zscaler ZNet. Once decided, you can assign these users and/or groups to Zscaler ZNet by following the instructions here:

Important tips for assigning users to Zscaler ZNet

  • It's recommended that a single Microsoft Entra user is assigned to Zscaler ZNet to test the automatic user provisioning configuration. Additional users and/or groups may be assigned later.

  • When assigning a user to Zscaler,Zscaler ZNet, you must select any valid application-specific role (if available) in the assignment dialog. Users with the Default Access role are excluded from provisioning.

Step 3: Configure automatic user provisioning to Zscaler ZNet

This section guides you through the steps to configure the Microsoft Entra provisioning service to create, update, and disable users and/or groups in Zscaler ZNet based on user and/or group assignments in Microsoft Entra ID.

Configure automatic user provisioning for Zscaler ZNet in Microsoft Entra ID

  1. Sign in to the Microsoft Entra admin center as at least a Cloud Application Administrator.

  2. Browse to Entra ID > Enterprise apps > Zscaler ZNet.

  3. Select the Provisioning tab.

    Screenshot of the Zscaler ZNet - Provisioning Enterprise Application sidebar with the Provisioning option highlighted.

  4. Select + New configuration.

    Screenshot of New configuration.

  5. Under the Admin Credentials section, enter the Tenant URL and Secret Token of your Zscaler ZNet Beta account as described later in this article.

  6. To obtain the Tenant URL and Secret Token, navigate to Administration > Authentication Settings in the Zscaler ZNet portal user interface and select SAML under Authentication Type.

    Screenshot of the Authentication Settings page.

  7. Select Enable SCIM-Based Provisioning to retrieve Base URL and Bearer Token, then save the settings. Copy the Base URL to Tenant URL, and Bearer Token to Secret Token.

  8. Upon populating the fields shown in Step 5, select Test Connection to ensure Microsoft Entra ID can connect to Zscaler.Zscaler ZNet. If the connection fails, ensure your Zscaler ZNet account has Admin permissions and try again.

    Screenshot of Token.

  9. Select Attribute Mapping in the left panel and select users.

  10. Review the user attributes that are synchronized from Microsoft Entra ID to Zscaler ZNet in the Attribute Mapping section. The attributes selected as Matching properties are used to match the user accounts in Zscaler ZNet for update operations. Select the Save button to commit any changes.

    Attribute Type Supported for filtering Required by Zscaler ZNet
    userName String ✓ ✓
    externalId String ✓
  11. Select Groups.

  12. Review the group attributes that are synchronized from Microsoft Entra ID to Zscaler ZNet in the Attribute Mapping section. The attributes selected as Matching properties are used to match the groups in Zscaler ZNet for update operations. Select the Save button to commit any changes.

    Attribute Type Supported for filtering Required by Zscaler ZNet
    displayName String ✓ ✓
    members Reference
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…