Manual User Sync
Manual User Sync provisions users from Microsoft Entra ID groups without a separate SCIM Enterprise Application — it reuses your existing SSO app registration’s Graph permissions. Users are admitted and assigned roles from your group mappings when they sign in, according to the enforcement mode you choose.Group-to-role mapping now lives in Role Provisioning.
That single section replaces the old Role mapping, User provisioning, SCIM, and
Trust identity provider screens. This page covers the Entra-specific prerequisites and
how manual (non-SCIM) provisioning behaves.
When to use it
Prerequisites
- Microsoft Entra ID SSO is configured and working
- At least one verified email domain
- Your app registration has these Application Graph permissions, with admin consent:
User.Read.AllGroupMember.Read.AllGroup.Read.All
Without
Group.Read.All (and consent), no groups appear in the Role Provisioning picker.Configure it in Role Provisioning
- Log in as Owner or Admin → Platform settings → Role Provisioning
- Turn on User provisioning & role mapping
- Set a Default Access role for users who match no mapped group (or No NeuralTrust access)
- Choose an Enforcement mode:
- Under Role Mapping, add a row per Entra group and choose its platform role:
What manual provisioning does not do
- It does not auto-deprovision. Removing a user from an Entra group does not remove them from NeuralTrust — remove them in Users & groups, or use SCIM for automatic offboarding.
Verify
- Open Platform settings → Users & groups
- Confirm the expected members appear with the correct roles
- The Groups tab shows each synced group with its source and member count
Related documentation
- Role Provisioning — Group-to-role mapping and enforcement
- Microsoft Entra ID SSO — Connect Entra ID
- SCIM Provisioning — Fully automated user lifecycle
- Audit Logs — Monitor sync and access events