Configure Zscaler ZSNet for automatic user provisioning with Microsoft Entra ID
In brief
The tutorial now consistently refers to Zscaler ZSNet instead of Zscaler ZNet, including the title, prerequisites, gallery search instructions, and provisioning steps.
What Entra admins need to know
Administrators following the tutorial should search for and select Zscaler ZSNet in the Microsoft Entra application gallery.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Configure Zscaler ZNetZSNet for automatic user provisioning with Microsoft Entra ID
The objective of this article is to demonstrate the steps to be performed in Zscaler ZNetZSNet and Microsoft Entra ID to configure Microsoft Entra ID to automatically provision and de-provision users and/or groups to Zscaler ZNet.ZSNet.
The scenario outlined in this article assumes that you already have the following:
[!INCLUDE common-prerequisites.md]
- A Zscaler
ZNetZSNet tenant - A user account in Zscaler
ZNetZSNet with Admin permissions
Step 1: Add Zscaler ZSNet from the gallery
Before configuring Zscaler ZSNet for automatic user provisioning with Microsoft Entra ID, you need to add Zscaler ZSNet from the Microsoft Entra application gallery to your list of managed SaaS applications.
To add Zscaler ZSNet from the Microsoft Entra application gallery, perform the following steps:
Sign in to the Microsoft Entra admin center as at least a Cloud Application Administrator.
Browse to Entra ID > Enterprise apps > New application.
In the search box, type Zscaler
ZNetZSNet, select ZscalerZNetZSNet from result panel then select Add button to add the application.
Step 2: Assign users to Zscaler ZNetZSNet
Microsoft Entra ID uses a concept called "assignments" to determine which users should receive access to selected apps. In the context of automatic user provisioning, only the users and/or groups that have been "assigned" to an application in Microsoft Entra ID are synchronized.
Before configuring and enabling automatic user provisioning, you should decide which users and/or groups in Microsoft Entra ID need access to Zscaler ZNet.ZSNet. Once decided, you can assign these users and/or groups to Zscaler ZNetZSNet by following the instructions here:
Important tips for assigning users to Zscaler ZNetZSNet
It's recommended that a single Microsoft Entra user is assigned to Zscaler
ZNetZSNet to test the automatic user provisioning configuration. Additional users and/or groups may be assigned later.When assigning a user to Zscaler
ZNet,ZSNet, you must select any valid application-specific role (if available) in the assignment dialog. Users with the Default Access role are excluded from provisioning.
Step 3: Configure automatic user provisioning to Zscaler ZNetZSNet
This section guides you through the steps to configure the Microsoft Entra provisioning service to create, update, and disable users and/or groups in Zscaler ZNetZSNet based on user and/or group assignments in Microsoft Entra ID.
Configure automatic user provisioning for Zscaler ZNetZSNet in Microsoft Entra ID
Sign in to the Microsoft Entra admin center as at least a Cloud Application Administrator.
Browse to Entra ID > Enterprise apps > Zscaler
ZNetZSNet.Select the Provisioning tab.

Select + New configuration.

Under the Admin Credentials section, enter the Tenant URL and Secret Token of your Zscaler
ZNetZSNet Beta account as described later in this article.To obtain the Tenant URL and Secret Token, navigate to Administration > Authentication Settings in the Zscaler
ZNetZSNet portal user interface and select SAML under Authentication Type.
Select Enable SCIM-Based Provisioning to retrieve Base URL and Bearer Token, then save the settings. Copy the Base URL to Tenant URL, and Bearer Token to Secret Token.
Upon populating the fields shown in Step 5, select Test Connection to ensure Microsoft Entra ID can connect to Zscaler
ZNet.ZSNet. If the connection fails, ensure your ZscalerZNetZSNet account has Admin permissions and try again.
Select Attribute Mapping in the left panel and select users.
Review the user attributes that are synchronized from Microsoft Entra ID to Zscaler
ZNetZSNet in the Attribute Mapping section. The attributes selected as Matching properties are used to match the user accounts in ZscalerZNetZSNet for update operations. Select the Save button to commit any changes.Attribute Type Supported for filtering Required by Zscaler ZNetZSNetuserName String ✓ ✓ externalId String ✓ Select Groups.
Review the group attributes that are synchronized from Microsoft Entra ID to Zscaler
ZNetZSNet in the Attribute Mapping section. The attributes selected as Matching properties are used to match the groups in ZscalerZNetZSNet for update operations. Select the Save button to commit any changes.Attribute Type Supported for filtering Required by Zscaler ZNetZSNetdisplayName String ✓ ✓ members Reference
@@ -1,15 +1,15 @@ ----title: Configure Zscaler ZNet for automatic user provisioning with Microsoft Entra ID-description: Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Zscaler ZNet.+title: Configure Zscaler ZSNet for automatic user provisioning with Microsoft Entra ID+description: Learn how to configure Microsoft Entra ID to automatically provision and de-provision user accounts to Zscaler ZSNet. ms.topic: how-to ms.date: 03/30/2026 ms.custom: sfi-image-nochange-# Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Zscaler ZNet so that I can streamline the user management process and ensure that users have the appropriate access to Zscaler ZNet.+# Customer intent: As an IT administrator, I want to learn how to automatically provision and deprovision user accounts from Microsoft Entra ID to Zscaler ZSNet so that I can streamline the user management process and ensure that users have the appropriate access to Zscaler ZSNet. --- -# Configure Zscaler ZNet for automatic user provisioning with Microsoft Entra ID+# Configure Zscaler ZSNet for automatic user provisioning with Microsoft Entra ID -The objective of this article is to demonstrate the steps to be performed in Zscaler ZNet and Microsoft Entra ID to configure Microsoft Entra ID to automatically provision and de-provision users and/or groups to Zscaler ZNet.+The objective of this article is to demonstrate the steps to be performed in Zscaler ZSNet and Microsoft Entra ID to configure Microsoft Entra ID to automatically provision and de-provision users and/or groups to Zscaler ZSNet. > [!NOTE] > This article describes a connector built on top of the Microsoft Entra user provisioning service. For important details on what this service does, how it works, and frequently asked questions, see [Automate user provisioning and deprovisioning to SaaS applications with Microsoft Entra ID](~/identity/app-provisioning/user-provisioning.md).@@ -20,69 +20,69 @@ The objective of this article is to demonstrate the steps to be performed in Zsc The scenario outlined in this article assumes that you already have the following: [!INCLUDE [common-prerequisites.md](~/identity/saas-apps/includes/common-prerequisites.md)]-* A Zscaler ZNet tenant-* A user account in Zscaler ZNet with Admin permissions+* A Zscaler ZSNet tenant+* A user account in Zscaler ZSNet with Admin permissions > [!NOTE]-> The Microsoft Entra provisioning integration relies on the Zscaler ZNet SCIM API, which is available to Zscaler ZNet developers for accounts with the Enterprise package.+> The Microsoft Entra provisioning integration relies on the Zscaler ZSNet SCIM API, which is available to Zscaler ZSNet developers for accounts with the Enterprise package. -## Step 1: Add Zscaler ZNet from the gallery+## Step 1: Add Zscaler ZSNet from the gallery -Before configuring Zscaler ZNet for automatic user provisioning with Microsoft Entra ID, you need to add Zscaler ZNet from the Microsoft Entra application gallery to your list of managed SaaS applications.+Before configuring Zscaler ZSNet for automatic user provisioning with Microsoft Entra ID, you need to add Zscaler ZSNet from the Microsoft Entra application gallery to your list of managed SaaS applications. -**To add Zscaler ZNet from the Microsoft Entra application gallery, perform the following steps:**+**To add Zscaler ZSNet from the Microsoft Entra application gallery, perform the following steps:** 1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator). 1. Browse to **Entra ID** > **Enterprise apps** > **New application**.-1. In the search box, type **Zscaler ZNet**, select **Zscaler ZNet** from result panel then select **Add** button to add the application.+1. In the search box, type **Zscaler ZSNet**, select **Zscaler ZSNet** from result panel then select **Add** button to add the application. - +  -## Step 2: Assign users to Zscaler ZNet+## Step 2: Assign users to Zscaler ZSNet Microsoft Entra ID uses a concept called "assignments" to determine which users should receive access to selected apps. In the context of automatic user provisioning, only the users and/or groups that have been "assigned" to an application in Microsoft Entra ID are synchronized. -Before configuring and enabling automatic user provisioning, you should decide which users and/or groups in Microsoft Entra ID need access to Zscaler ZNet. Once decided, you can assign these users and/or groups to Zscaler ZNet by following the instructions here:+Before configuring and enabling automatic user provisioning, you should decide which users and/or groups in Microsoft Entra ID need access to Zscaler ZSNet. Once decided, you can assign these users and/or groups to Zscaler ZSNet by following the instructions here: * [Assign a user or group to an enterprise app](~/identity/enterprise-apps/assign-user-or-group-access-portal.md) -### Important tips for assigning users to Zscaler ZNet+### Important tips for assigning users to Zscaler ZSNet -* It's recommended that a single Microsoft Entra user is assigned to Zscaler ZNet to test the automatic user provisioning configuration. Additional users and/or groups may be assigned later.+* It's recommended that a single Microsoft Entra user is assigned to Zscaler ZSNet to test the automatic user provisioning configuration. Additional users and/or groups may be assigned later. -* When assigning a user to Zscaler ZNet, you must select any valid application-specific role (if available) in the assignment dialog. Users with the **Default Access** role are excluded from provisioning.+* When assigning a user to Zscaler ZSNet, you must select any valid application-specific role (if available) in the assignment dialog. Users with the **Default Access** role are excluded from provisioning. -## Step 3: Configure automatic user provisioning to Zscaler ZNet+## Step 3: Configure automatic user provisioning to Zscaler ZSNet -This section guides you through the steps to configure the Microsoft Entra provisioning service to create, update, and disable users and/or groups in Zscaler ZNet based on user and/or group assignments in Microsoft Entra ID.+This section guides you through the steps to configure the Microsoft Entra provisioning service to create, update, and disable users and/or groups in Zscaler ZSNet based on user and/or group assignments in Microsoft Entra ID. > [!NOTE]-> Open a [support ticket](https://help.zscaler.com/) to create a domain on Zscaler ZNet.+> Open a [support ticket](https://help.zscaler.com/) to create a domain on Zscaler ZSNet. > [!TIP]-> You may also choose to enable SAML-based single sign-on for Zscaler ZNet, following the instructions provided in the [Zscaler ZNet single sign-on article](zscaler-tutorial.md). Single sign-on can be configured independently of automatic user provisioning, though these two features complement each other.+> You may also choose to enable SAML-based single sign-on for Zscaler ZSNet, following the instructions provided in the [Zscaler ZSNet single sign-on article](zscaler-tutorial.md). Single sign-on can be configured independently of automatic user provisioning, though these two features complement each other. > [!NOTE] > When users and groups are provisioned or de-provisioned we recommend to periodically restart provisioning to ensure that group memberships are properly updated. Doing a restart will force our service to re-evaluate all the groups and update the memberships. Please be aware that the restart can take time if you're syncing all users and groups in your tenant or have assigned large groups with 50K+ members. <a name='to-configure-automatic-user-provisioning-for-zscaler-znet-in-azure-ad'></a> -### Configure automatic user provisioning for Zscaler ZNet in Microsoft Entra ID+### Configure automatic user provisioning for Zscaler ZSNet in Microsoft Entra ID 1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator). -1. Browse to **Entra ID** > **Enterprise apps** > **Zscaler ZNet**.+1. Browse to **Entra ID** > **Enterprise apps** > **Zscaler ZSNet**. 1. Select the **Provisioning** tab. - +  1. Select **+ New configuration**.  -1. Under the **Admin Credentials** section, enter the **Tenant URL** and **Secret Token** of your Zscaler ZNet Beta account as described later in this article.+1. Under the **Admin Credentials** section, enter the **Tenant URL** and **Secret Token** of your Zscaler ZSNet Beta account as described later in this article. -1. To obtain the **Tenant URL** and **Secret Token**, navigate to **Administration > Authentication Settings** in the Zscaler ZNet portal user interface and select **SAML** under **Authentication Type**.+1. To obtain the **Tenant URL** and **Secret Token**, navigate to **Administration > Authentication Settings** in the Zscaler ZSNet portal user interface and select **SAML** under **Authentication Type**.  @@ -92,7 +92,7 @@ This section guides you through the steps to configure the Microsoft Entra provi 1. Select **Enable SCIM-Based Provisioning** to retrieve **Base URL** and **Bearer Token**, then save the settings. Copy the **Base URL** to **Tenant URL**, and **Bearer Token** to **Secret Token**. -1. Upon populating the fields shown in Step 5, select **Test Connection** to ensure Microsoft Entra ID can connect to Zscaler ZNet. If the connection fails, ensure your Zscaler ZNet account has Admin permissions and try again.+1. Upon populating the fields shown in Step 5, select **Test Connection** to ensure Microsoft Entra ID can connect to Zscaler ZSNet. If the connection fails, ensure your Zscaler ZSNet account has Admin permissions and try again.  @@ -106,9 +106,9 @@ This section guides you through the steps to configure the Microsoft Entra provi 1. Select **Attribute Mapping** in the left panel and select **users**. -1. Review the user attributes that are synchronized from Microsoft Entra ID to Zscaler ZNet in the **Attribute Mapping** section. The attributes selected as **Matching** properties are used to match the user accounts in Zscaler ZNet for update operations. Select the **Save** button to commit any changes.+1. Review the user attributes that are synchronized from Microsoft Entra ID to Zscaler ZSNet in the **Attribute Mapping** section. The attributes selected as **Matching** properties are used to match the user accounts in Zscaler ZSNet for update operations. Select the **Save** button to commit any changes. - |Attribute|Type|Supported for filtering|Required by Zscaler ZNet|+ |Attribute|Type|Supported for filtering|Required by Zscaler ZSNet| |---|---|---|---| |userName|String|✓|✓ |externalId|String||✓@@ -120,9 +120,9 @@ This section guides you through the steps to configure the Microsoft Entra provi 1. Select **Groups**. -1. Review the group attributes that are synchronized from Microsoft Entra ID to Zscaler ZNet in the **Attribute Mapping** section. The attributes selected as **Matching** properties are used to match the groups in Zscaler ZNet for update operations. Select the **Save** button to commit any changes.+1. Review the group attributes that are synchronized from Microsoft Entra ID to Zscaler ZSNet in the **Attribute Mapping** section. The attributes selected as **Matching** properties are used to match the groups in Zscaler ZSNet for update operations. Select the **Save** button to commit any changes. - |Attribute|Type|Supported for filtering|Required by Zscaler ZNet|+ |Attribute|Type|Supported for filtering|Required by Zscaler ZSNet| |---|---|---|---| |displayName|String|✓|✓ |members|Reference|| 