Monday, October 5, 2026·4 min read
Setup guide (TextUnited SCIM in Microsoft Entra ID)

You need: TextUnited admin access, and an Entra role of Application Administrator or Cloud Application Administrator (or higher)
Step 1: Enable SCIM in TextUnited
- Sign in to TextUnited → Account → Security & access.
- Under Company → User provisioning (SCIM), choose the default role for synced users (Client User or Client Power User).
- Click Enable SCIM & generate token.
- Copy the Tenant URL and the Secret Token. The token is shown only once and does not expire. Store it in a password manager, and never show it on screen or in recordings.
Step 2: Create the Enterprise Application in Entra
- Go to the Microsoft Entra admin center → Enterprise apps → New application.
- Click Create your own application. TextUnited is not in the app gallery.
- Enter a name (e.g. TextUnited) and select Integrate any other application you don't find in the gallery (Non-gallery) → Create.
Step 3: Configure provisioning
- Open the app → Provisioning → New configuration.
- Authentication method: Bearer authentication.
- Tenant URL: https://apinew.textunited.com/accounts/scim/v2/
- Secret token: <SCIM_SECRET_TOKEN>
- Click Test connection, and when it succeeds, Create.
Step 4: Adjust attribute mappings (important)
Open Attribute mapping → Users. Click Save after each change.
- Edit userPrincipalName → userName and change Matching precedence from 1 to 2. Save.
- Delete the default mailNickname → externalId mapping. Save. This frees up externalId for the next step.
- Add attribute mapping: Mapping type Direct, Source objectId, Target externalId, Match objects using this attribute = Yes, Matching precedence 1. Save.
The result should look like this:
| Source (Entra) | Target (TextUnited) | Matching precedence |
|---|---|---|
| objectId | externalId | 1 |
| userPrincipalName | userName | 2 |
Leave the other default mappings as they are. Make sure every user has givenName and surname filled in Entra. Otherwise TextUnited guesses the names from displayName.
Step 5: Create and assign a security group
- Go to Groups → New group → Group type Security, not Microsoft 365. Add the users as direct members. Nested groups are not synced.
- Go to the app → Users and groups → Add user/group → select the group → Assign.
- If any of these users already have a TextUnited account with the same email, sort that out with TextUnited first, or provisioning will report a conflict.
Step 6: Test with one user
- Go to Provision on demand → select the group → select one user → Provision.
- All four steps (Import, Scope, Match, Perform action) should show Success.
- In TextUnited → Users / Manage Users, check that the user exists with the correct first name, last name and email.
Step 7: Turn on automatic provisioning
- Go to Provisioning → Settings: Scope = Sync only assigned users and groups. Optionally, turn on failure email notifications and Prevent accidental deletion.
- Set Provisioning Status = On → Save.
- From then on, users added to the group are created in TextUnited, and users removed from it are blocked. Expect up to about 40 minutes per sync cycle, and logs that lag a few minutes.
Step 8: Let users open TextUnited from their Microsoft 365 apps
Without this step, clicking the app tile shows "App launch failed – not configured for single sign-on".
- Go to the app → Single sign-on → Linked.
- Sign on URL: https://app.textunited.com → Save.
Users then sign in with Continue with Microsoft. Linked mode only adds a link. Real SAML / OIDC single sign-on is configured separately.
Rotating or disconnecting
- Rotate the token: TextUnited → User provisioning (SCIM) → Generate new SCIM token, then paste the new token into Entra → Provisioning → Admin credentials → Test connection → Save.
- Disconnect: TextUnited → User provisioning (SCIM) → Disable, and set Provisioning Status to Off in Entra.
TextUnited SCIM provisioning FAQs
Answers to common questions about connecting TextUnited to Microsoft Entra ID with SCIM.
Related Posts

Wednesday, February 25, 2026
How to use TextUnited API: Instant translation & project creation
A practical guide to the TextUnited API, covering instant translation of text segments, creating translation projects with or without instant translation, and retrieving translated segments via custom project IDs.

Marek Piorkowski

Monday, August 17, 2026
Connecting the TextUnited MCP server to your favorite AI tools
Connect TextUnited's MCP server to Codex, Cursor, Cloud Code, and other AI tools. Learn how to configure authentication and use terminology in your workflow.

Marek Piorkowski
