Choose what you are enabling
SSO and SCIM solve different problems. SSO lets existing AvdControl users sign in with Entra. SCIM creates, disables, and groups users from Entra or Okta. You can use either one on its own, but most organisations use both.
SSO does not grant access by itself. The first Entra sign-in links by email to an existing AvdControl user. That user must be active from a manual invite or SCIM provisioning, and the identity provider must send an email claim.
A typical rollout order is Azure connection, host-pool selection, SCIM token, first user and group sync, group mappings, SSO, then Go live. That order gives test users access before they try the Entra sign-in button.
Configure Entra SSO
Create or reuse an Entra app registration for AvdControl portal sign-in. Add a Web redirect URI for the AvdControl OIDC callback: https://avdcontrol.com/api/auth/oidc/callback for the hosted service, or your deployment APP_URL followed by /api/auth/oidc/callback for a private deployment.
Create a client secret and copy the value immediately. In AvdControl, open Settings, Sign-in and provisioning, then enter the issuer, client ID, and client secret. The issuer is usually https://login.microsoftonline.com/{tenant-id}/v2.0.
Use the Application (client) ID, not the Directory tenant ID, in the Client ID field. Keep the tenant ID only for the issuer URL. If you rotate the Entra secret later, enter only the new secret in Settings; the old saved value is never displayed.
- 1
Create the appIn Entra admin center, create an app registration for AvdControl portal sign-in. Supported account type should normally be Single tenant.
- 2
Add the redirect URIAuthentication -> Platform configurations -> Web -> add /api/auth/oidc/callback on the AvdControl app origin. The redirect URI must exactly match the one AvdControl sends.
- 3
Create the secretCertificates & secrets -> New client secret. Copy the secret value, not the secret ID.
- 4
Save in AvdControlSettings -> Sign-in and provisioning -> Entra SSO. Paste issuer, client ID, and secret, then save.
- 5
Test with one userInvite or provision a test user, sign out, use Sign in with Entra, and confirm the account lands in the expected organisation and role.
Configure SCIM provisioning
In AvdControl, open Settings, Sign-in and provisioning, copy the Provisioning URL, and mint a token. The token is shown once, replaces any active token, and expires after 90 days.
In Entra Enterprise applications, add automatic provisioning for the AvdControl application. Use the AvdControl Provisioning URL as the Tenant URL and the minted token as the Secret Token, then test the connection before turning provisioning on.
Provision users and groups. AvdControl accepts SCIM Users and Groups, matches users by userName/email or externalId, disables users when SCIM sends active: false, and creates groups from displayName and externalId.
- 1
Copy the endpointUse the Provisioning URL shown in AvdControl Settings. It ends with /api/scim/v2 and is tenant-specific through the portal you are using.
- 2
Mint the tokenClick Mint token and paste the shown-once bearer token into Entra or Okta. Store it in your password manager because AvdControl will not show it again.
- 3
Test credentialsUse the identity provider's Test Connection button. A 401 usually means an old or mistyped token; a 404 usually means the wrong endpoint URL.
- 4
Scope assignmentsAssign only the users and groups that should become AvdControl operators. Start with a small pilot group before enabling all help-desk staff.
- 5
Start provisioningRun a manual provisioning cycle and check Settings. Groups appear in AvdControl after the first successful group push.
Map groups to access
After SCIM has pushed groups, map each group in Settings to Viewer, Help desk, Session admin, or Admin. Viewer, Help desk, and Session admin can be limited to selected host pools. Admin always applies to the whole organisation.
Groups named AvdControl-Viewer, AvdControl-Helpdesk, AvdControl-SessionAdmin, or AvdControl-Admin are recognised automatically when they are first created. The Avd- prefix is also accepted. Role suffixes may be viewer, helpdesk, help_desk, session_admin, sessionadmin, or admin.
If a user belongs to multiple mapped groups, AvdControl resolves the strongest role and combines the host-pool access that applies. If none of the user's groups are mapped, the user remains provisioned but has no usable console access.
Operate and rotate safely
Rotate SCIM tokens before the 90-day expiry. Mint a new token in AvdControl, update the identity provider secret token, test the connection, then revoke the old active token if it is still listed.
For SSO secret rotation, create a new Entra client secret, paste it into AvdControl Settings, save, then test Entra sign-in before deleting the old Entra secret.
When troubleshooting, check Activity for sso.configured, scim.token_created, scim.user_created, scim.group_created, and scim.group_mapped events. If SSO says the user is not provisioned, verify the SCIM sync or manual invite and make sure the Entra token includes the same email address.