Microsoft Entra ID
Provisioning

Configure Zscaler ZSNet for automatic user provisioning with Microsoft Entra ID

In brief

The tutorial now consistently refers to Zscaler ZSNet instead of Zscaler ZNet, including the title, prerequisites, gallery search instructions, and provisioning steps.

What Entra admins need to know

Administrators following the tutorial should search for and select Zscaler ZSNet in the Microsoft Entra application gallery.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure Zscaler ZNetZSNet for automatic user provisioning with Microsoft Entra ID

The objective of this article is to demonstrate the steps to be performed in Zscaler ZNetZSNet and Microsoft Entra ID to configure Microsoft Entra ID to automatically provision and de-provision users and/or groups to Zscaler ZNet.ZSNet.

The scenario outlined in this article assumes that you already have the following:

[!INCLUDE common-prerequisites.md]

  • A Zscaler ZNetZSNet tenant
  • A user account in Zscaler ZNetZSNet with Admin permissions

Step 1: Add Zscaler ZSNet from the gallery

Before configuring Zscaler ZSNet for automatic user provisioning with Microsoft Entra ID, you need to add Zscaler ZSNet from the Microsoft Entra application gallery to your list of managed SaaS applications.

To add Zscaler ZSNet from the Microsoft Entra application gallery, perform the following steps:

  1. Sign in to the Microsoft Entra admin center as at least a Cloud Application Administrator.

  2. Browse to Entra ID > Enterprise apps > New application.

  3. In the search box, type Zscaler ZNetZSNet, select Zscaler ZNetZSNet from result panel then select Add button to add the application.

    Screenshot of Zscaler ZSNet in the results list.

Step 2: Assign users to Zscaler ZNetZSNet

Microsoft Entra ID uses a concept called "assignments" to determine which users should receive access to selected apps. In the context of automatic user provisioning, only the users and/or groups that have been "assigned" to an application in Microsoft Entra ID are synchronized.

Before configuring and enabling automatic user provisioning, you should decide which users and/or groups in Microsoft Entra ID need access to Zscaler ZNet.ZSNet. Once decided, you can assign these users and/or groups to Zscaler ZNetZSNet by following the instructions here:

Important tips for assigning users to Zscaler ZNetZSNet

  • It's recommended that a single Microsoft Entra user is assigned to Zscaler ZNetZSNet to test the automatic user provisioning configuration. Additional users and/or groups may be assigned later.

  • When assigning a user to Zscaler ZNet,ZSNet, you must select any valid application-specific role (if available) in the assignment dialog. Users with the Default Access role are excluded from provisioning.

Step 3: Configure automatic user provisioning to Zscaler ZNetZSNet

This section guides you through the steps to configure the Microsoft Entra provisioning service to create, update, and disable users and/or groups in Zscaler ZNetZSNet based on user and/or group assignments in Microsoft Entra ID.

Configure automatic user provisioning for Zscaler ZNetZSNet in Microsoft Entra ID

  1. Sign in to the Microsoft Entra admin center as at least a Cloud Application Administrator.

  2. Browse to Entra ID > Enterprise apps > Zscaler ZNetZSNet.

  3. Select the Provisioning tab.

    Screenshot of the Zscaler ZSNet - Provisioning Enterprise Application sidebar with the Provisioning option highlighted.

  4. Select + New configuration.

    Screenshot of New configuration.

  5. Under the Admin Credentials section, enter the Tenant URL and Secret Token of your Zscaler ZNetZSNet Beta account as described later in this article.

  6. To obtain the Tenant URL and Secret Token, navigate to Administration > Authentication Settings in the Zscaler ZNetZSNet portal user interface and select SAML under Authentication Type.

    Screenshot of the Authentication Settings page.

  7. Select Enable SCIM-Based Provisioning to retrieve Base URL and Bearer Token, then save the settings. Copy the Base URL to Tenant URL, and Bearer Token to Secret Token.

  8. Upon populating the fields shown in Step 5, select Test Connection to ensure Microsoft Entra ID can connect to Zscaler ZNet.ZSNet. If the connection fails, ensure your Zscaler ZNetZSNet account has Admin permissions and try again.

    Screenshot of Token.

  9. Select Attribute Mapping in the left panel and select users.

  10. Review the user attributes that are synchronized from Microsoft Entra ID to Zscaler ZNetZSNet in the Attribute Mapping section. The attributes selected as Matching properties are used to match the user accounts in Zscaler ZNetZSNet for update operations. Select the Save button to commit any changes.

    Attribute Type Supported for filtering Required by Zscaler ZNetZSNet
    userName String ✓ ✓
    externalId String ✓
  11. Select Groups.

  12. Review the group attributes that are synchronized from Microsoft Entra ID to Zscaler ZNetZSNet in the Attribute Mapping section. The attributes selected as Matching properties are used to match the groups in Zscaler ZNetZSNet for update operations. Select the Save button to commit any changes.

    Attribute Type Supported for filtering Required by Zscaler ZNetZSNet
    displayName String ✓ ✓
    members Reference
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…