

Open Settings (⚙️) and select Directory sync (SCIM) from the sidebar.
Turn on the Enable SCIM toggle. This generates your SCIM base URL and bearer token.
Copy the bearer token now — it's only shown once. You'll paste this into your identity provider's SCIM configuration.

Login to your company's Azure Portal.
If you have already created a Knowby Enterprise App as part of Enabling Single Sign-On (SSO) for Knowby with Microsoft Entra ID then skip directly to step 8.
If you need to create an enterprise app in Entra ID, then click Enterprise applications

Then click New application

Then click Create your own application

Under What's the name of your app? enter Knowby
Select Integrate any other application you don't find in the gallery (Non-gallery)
Then click Create.

In your Knowby enterprise application click Get started in the Provision User Accounts box.

Then click Connect your application

Ensure Bearer authentication is selected.
Paste the bearer token you copied in Step 3 into the Secret token field.
Navigate back to Knowby Pro and copy the SCIM base URL — this is the endpoint your identity provider will sync against.

Paste the SCIM base URL into the Tenant URL field, then click Test Connection — it should return success if the URL and token are correct.
If you ever need to revoke access, use Rotate token to generate a new bearer token — the old one stops working immediately.
You will need to update your Knowby enterprise application in your Azure Portal to get SCIM provisioning working again.
To turn off user provisioning at any time, switch Enable SCIM off.