You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: Workload-Identity-Federation-for-SCIM-Provisioning.md
+30-27Lines changed: 30 additions & 27 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -82,20 +82,20 @@ After selecting **Workload Identity Federation**, the administrator chooses **Se
82
82
|---|---|
83
83
|||
84
84
85
-
After the access app is configured, the UX displays the following values to be **copied to the ISV Portal**:
85
+
After the workload identity app is configured, the UX displays the following values to be **copied to the ISV Portal**:
|**Authorized Party (azp)**|`<Provisioning Client 1P app ID>`|
93
93
94
94

95
95
96
96
### Step 2: Set up SCIM Client with JWKS in ISV Portal
97
97
98
-
In the ISV portal, the administrator sets up a client for the ISV's SCIM endpoint. As part of setting up the auth integration, the administrator copies the values from Step 1 (issuer, JWKS URL, subject, audience) into the ISV portal.
98
+
In the ISV portal, the administrator sets up a client for the ISV's SCIM endpoint. As part of setting up the auth integration, the administrator copies the values from Step 1 (issuer, JWKS URL, audience, and authorized party) into the ISV portal.
99
99
100
100
The ISV portal will then display the following values, needed for Step 3:
101
101
@@ -146,7 +146,7 @@ Back in the Entra App Gallery:
146
146
147
147
2.**ISV's Token Endpoint** validates the JWT assertion:
148
148
- Verifies the JWT signature using Microsoft's public OIDC keys
149
-
- Validates the `issuer`, `audience`, and `subject` claims
149
+
- Validates the `iss`, `aud`, and `azp` claims and the token timestamps
150
150
- Issues an **access token** back to the Entra provisioning service
151
151
152
152
3.**Entra Provisioning Service** uses the issued access token as a **Bearer token** in SCIM API calls (GET, POST, PATCH, DELETE) to the ISV's SCIM endpoint
@@ -161,18 +161,19 @@ When Entra ID sends the JWT bearer assertion request, the **JWT assertion (clien
161
161
162
162
### JWT Claims in the Entra-Issued Assertion
163
163
164
-
| Claim | Description | Example Value |
165
-
|---|---|---|
166
-
|`aud` (Audience) | Workload Identity App ID |`api://b5ba7a93-4452-4522-aeb4-a2b5da870c16`|
| Claim | Description | Should Validate? | Example Value |
165
+
|---|---|---|---|
166
+
|`aud` (Audience) | Workload Identity App ID | Yes, Identifies the client app for this integration |`api://b5ba7a93-4452-4522-aeb4-a2b5da870c16`|
167
+
|`iss` (Issuer) | Customer tenant v2 issuer endpoint | Yes, Identifies the tenant in Entra for this integration |`https://login.microsoftonline.com/ce5f061f-abe6-4e40-9615-301f87bcb7f0/v2.0`|
168
+
|`sub` (Subject) | Sync Fabric Workload Identity 1P app object ID | May be, already covered by iss. sub will have same value for all integrations in a tenant |`<Sync Fabric Workload Identity 1P app object ID>`|
169
+
|`oid` (Object ID) | Workload Identity Object ID ||`d2f8ee76-c549-45b8-a143-f5b640669704`|
170
+
|`azp` (Authorized Party) | Provisioning Client 1P App ID | Yes, Unique Id for Provisioning Client, proves that this token was requested by Provisioning Client |`cb1d50fe-8ed0-4944-9e7d-5981aad3bc4b`|
171
+
|`azpacr`| Authentication method used for the Workload Identity ||`2`|
172
+
|`tid` (Tenant ID) | Customer Tenant ID ||`ce5f061f-abe6-4e40-9615-301f87bcb7f0`|
@@ -194,7 +194,7 @@ When Entra ID sends the JWT bearer assertion request, the **JWT assertion (clien
194
194
```
195
195
196
196
> [!NOTE]
197
-
> The `iss` and `sub` claims in the Entra-issued token identify the **customer's tenant** and the **Sync Fabric Workload Identity 1P app object**, respectively. The ISV validates these against the values provided during the 3-step configuration.
197
+
> The ISV validates `aud`, `iss`, and `azp` against the values provided during the 3-step configuration. The `sub` claim identifies the **Sync Fabric Workload Identity 1P app object**, but validating it is optional because its value is shared by all integrations in the tenant.
198
198
199
199
### Additional Context Provided
200
200
@@ -223,7 +223,8 @@ ISVs must validate the Entra-issued JWT assertion using Microsoft's published JW
223
223
The ISV portal must allow administrators to configure the expected claim values for each integration:
224
224
225
225
-**`aud` (Audience)** — the audience value the ISV expects in incoming JWTs
226
-
-**`sub` (Subject)** — the subject identifier for the Sync Fabric Workload Identity 1P app
226
+
-**`azp` (Authorized Party)** — the ID of the Provisioning Client 1P app
227
+
-**`iss` (Issuer)** — the customer tenant v2 issuer endpoint
227
228
-**JWKS URL** — the endpoint to fetch Microsoft's signing keys
228
229
229
230
These values are provided by the Entra portal during Step 1 of the configuration flow and entered by the administrator in Step 2.
@@ -275,7 +276,7 @@ SAP SuccessFactors is the first application to support this new authentication m
275
276
2.**Selects "Provisioning"** and chooses **Workload Identity Federation** as the authentication method (instead of basic auth or bearer token)
276
277
3.**Entra ID automatically**:
277
278
- Creates a federated identity credential on the provisioning app's service principal
3.**Issuer Validation**: Confirm the `iss` claim matches the expected Microsoft Entra ID v2 issuer format: `https://login.microsoftonline.com/{tenantId}/v2.0`
373
374
374
-
4.**Token Expiry**: Always check `exp` and `nbf` claims. Reject expired or not-yet-valid tokens.
375
+
4.**Authorized Party Validation**: Verify the `azp` claim matches the Provisioning Client 1P app ID. Reject tokens requested by an unexpected client.
376
+
377
+
5.**Token Lifetime Validation**: Check the `iat`, `nbf`, and `exp` claims. Reject tokens issued unexpectedly far in the past or future, expired tokens, and tokens that are not yet valid.
375
378
376
-
5.**Tenant Isolation**: Use the `tid` claim to ensure provisioning operations are scoped to the correct customer tenant. Cross-tenant data leaks are a critical risk if this is not enforced.
379
+
6.**Tenant Isolation**: Validate the complete tenant-specific `iss` value to ensure provisioning operations are scoped to the correct customer tenant. Do not rely on an unvalidated `tid` claim for tenant isolation.
377
380
378
-
6.**Rate Limiting**: Implement rate limiting on the token endpoint to prevent abuse.
381
+
7.**Rate Limiting**: Implement rate limiting on the token endpoint to prevent abuse.
379
382
380
-
7.**TLS Requirement**: All JWT assertion and SCIM communications MUST use TLS 1.2 or higher.
383
+
8.**TLS Requirement**: All JWT assertion and SCIM communications MUST use TLS 1.2 or higher.
0 commit comments