Skip to content
Renew SCIM Token in Apple Business Manager to Sync Microsoft Entra ID

Renew SCIM Token in Apple Business Manager to Sync Microsoft Entra ID

Written By Malepati Naren
Last Updated April 22, 2024
Posted In Entra
SHARE

Hello Everyone! We are back with a new topic: Renew SCIM token from the Apple Business Manager. In this article, we will discuss the SCIM token, its requirements, and the renewal process. I hope you are doing great at work and looking for interesting technical topics.

SCIM stands for System for Cross-Domain Identity Management. It is a standardised protocol for organisations to automatically exchange user identity data between IT systems or identity domains or from one entity to another without any human intervention.

SCIM creates a common format for securely exchanging identity data, communicating identity data across platforms, and automating the flow of information between an Identity provider, Identity and Access Management(IAM), or any cloud-based applications.

The identity provider or IDP is the client, and a service provider is usually a SaaS Application. In our case, Apple Business Manager is the SaaS application, and Azure AD is the IDP. To exchange user information between Azure and Apple Business Manager, we must create a SCIM token and upload it in Azure AD so that users’ information will be synced to ABM to create managed Apple IDs.

Patch My PC

Renew SCIM Token in Apple Business Manager

Enabling Sync between Apple Business Manager and Azure AD is the first step in creating Managed Apple IDs. Managed Apple IDs are required to access apps from the App Store using corporate credentials. Users can use the same password as the corporate password to access iCloud, the app store, and all Apple services allowed by admins.

Accounts created, updated, or deleted on the IDP are simultaneously created, updated, or deleted on the service provider. The system can also identify and alert you if any incorrect values could compromise security. End users have correct, current profiles and permissions and can use applications without interruption.

We have discussed how to integrate Azure AD with Apple Business Manager here. For more information on the steps, refer to the article. The SCIM Token expires in one year. Apple sends a notification to the registered ABM email before 60 days of expiry.

Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 1
Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 1

Many organizations plan to renew it at least a month prior to the expiry. Now let’s see how we can renew the SCIM to token without breaking the Sync in the steps below.

Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 2
Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 2

It will usually be an SMS received on your registered mobile number. To access it, click on your admin account option, select Preference at the bottom of the screen, and then click on Directory Sync.

Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 3
Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 3

You can view that we have enabled Directory sync with Microsoft Entra ID. You can also view the last Last synced with your Microsoft EntraID. Now click on Edit

Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 4
Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 4

Now you can view the Tenant URL and Token Expiry dates, and you will have another option, “Generate Token”. Click on Generate Token.

Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 5
Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 5

Once you click on Generate Token, you will be presented with a Token and Tenant URL. Copy the details; we will need them to update them in Microsoft Entra ID.

Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 6
Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 6

Now let’s log in to the Microsoft Entra portal, click on Application then click on Enterprise applications under Applications. Click on All Applications, search for Apple Business, and select the application.

Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 7
Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 7

Now click on the Apple Business Manager application, and you can view all the details of the application. Now click on Provisioning and click on Eidt Provisioning

Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 8
Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 8

We must add the token we generated and the Tenant URL copied from the Apple Business Manager Portal. The tenant URL will usually be the same. Click on Secret Token and paste the token we saved.

Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 9
Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 9

If you want to check the connection status, click on Test Connection. This will take a while and provide notification that the supplied credentials are authorized to enable provisioning. Now click on Save, which will enable the Sync between the Apple Business Manager and Microsoft Entra ID.

Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 10
Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 10

Now we can sync the users who are scoped to Apple Business Manager without any issues. Once saved, you can also view the Current Cycle status and statistics to date.

Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 11
Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 11

Now let’s see the SCIM token’s status in the Apple Business Manager portal. Navigate back to the ABM portal and click on Directory Sync. You can see that Token 3 is generated and active with a new expiration date.

Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 12
Renew SCIM Token in Apple Business Manager to Sync Entra ID Fig. 12

Thus we can renew the SCIM Token to continue the Sync between the ABM portal and Azure Entra ID. This is a once-in-a-year Housekeeping activity, just like the APNS MDM certificate. While generating or renewing the SCIM, I would suggest using a Common account for the project instead of an account linked to the user.

We are on WhatsApp. To get the latest step-by-step guides and news updates, Join our Channel. Click here – HTMD WhatsApp.

Conclusion

SCIM token ensures that there’s a single source of truth, rather than multiple versions of the truth, for each identity and group and we always scope the user groups to be synced to the Apple Business Manager portal. Hope you like the article and we will meet again in another article.

Author

About Author – Narendra Kumar Malepati (Naren) has 11+ years of experience in IT, working on different MDM tools. Over the last seven years, Naren has been working on various features of Intune, including migration from different MDMs to Intune. Naren mainly focuses on Android, iOS, and MacOS.

Written by

Narendra Kumar Malepati (Naren) has 11+ years of experience in IT, working on different MDM tools. Over the last seven years, Naren has been working on various features of Intune, including migration from different MDMs to Intune. Naren mainly focuses on Android, iOS, and MacOS.

Discussion · 4 comments

  1. Straight to the point, thank you! Now, assuming we are safe to just remove the old token in ABM once the new is setup then? Or should we let the old one expire?

  2. Thank you, Anoop. I accidentally generated another token before token 1 expired. Will we need to follow the same steps again?

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Entra

Entra ID SSPR Improves Security with Registered Authentication Methods | Impact on Unregistered Users Starting September 2026

Key Takeaway Entra ID SSPR Improves Security with Registered Authentication Methods! Starting September 7, 2026, Microsoft Entra ID Self-Service Password Reset (SSPR) will require users to verify their identity using explicitly registered authentication methods. Directory-sourced contact information, such as mobile phone numbers, business phone numbers, and alternate email addresses, will no longer be accepted for […]

AC Anoop C Nair 4 min read
Entra

Explicit Forward Proxy in Microsoft Entra Internet Access Helps Secure VDI BYOD and Clientless Browsing

Key Takeaways Explicit Forward Proxy in Microsoft Entra Internet Access! This feature allows organizations to use secure web and AI gateway capabilities without deploying the Global Secure Access client, making it useful for browser-based and lightly managed environments. It works with browsers that support Proxy Auto-Configuration (PAC) files. Since this is a prerelease feature, Microsoft […]

AC Anoop C Nair 3 min read
Cloud

Microsoft Enables Entra Writeback for Cloud-Managed Remote Mailboxes to Help Remove Last Exchange Server

Key Takeaways: Let’s discuss about Microsoft Unlocks Entra Writeback for Cloud-Managed Remote Mailboxes to Help Remove Last Exchange Server. For customers with no remaining dependency on their last Exchange Server, a guide for decommissioning your last Exchange Server. Microsoft announced the Public Preview of Cloud-Managed Remote Mailboxes. Microsoft is excited to share these two new milestones […]

AC Anoop C Nair 3 min read