Skip to main content
No Result Found
Get your setup working faster. Join our Discord for optimisation tips from elite testers. Join our DiscordJoin our Discord

BrowserStack user provisioning with Azure AD (aka Microsoft Entra ID)

Connect Azure Active Directory with BrowserStack.

Azure Active Directory integration with BrowserStack allows you to automatically provision and de-provision users from Azure AD.

If you’re a new BrowserStack customer, to assign roles and products, see Assign roles using Automated User Provisioning and Assign product access using Automated User Provisioning.

Prerequisites

  • Enterprise plan on BrowserStack.
  • A user account in Azure AD with permission to configure provisioning (for example, Application Administrator, Cloud Application administrator, Application Owner, or Global Administrator).
  • Single Sign-on integration with BrowserStack (mandatory).
  • User with Owner permissions can setup user provisioning on BrowserStack.
Note: Owner can also allow user provisioning setup access to one of the Admin(s). For more information, see the Authentication & Security Settings section.

Supported features

Azure AD & BrowserStack user provisioning integration currently supports the following features:

  • User provisioning & de-provisioning
  • Attribute assignment for users on BrowserStack:
    • Role assignment
    • Product access
    • Team assignment

BrowserStack provisions individual users only and does not support group provisioning. Assign each user’s team, role, and product access using the custom attributes on this page.

Step 1: Initiate provisioning setup

Follow the steps below to setup user provisioning with Azure AD:

  1. Log in to BrowserStack as a user with Owner permissions.
  2. Go to Account > Security and select Authentication from the side-nav menu.
  3. Under Auto User Provisioning, click Configure. For configuring click Configure under Auto User Provisioning section
  4. Select the user attributes that you want to control from Azure AD and click Confirm. Select attributes to be controlled via Azure AD
  5. Copy the Tenant URL and Secret Token. These values will be entered in the Tenant URL and Secret Token fields in the Provisioning tab of your BrowserStack application in the Azure portal. Click Done. Provisioning tab of your BrowserStack application in the Azure portal
  6. Your provisioning configuration has been saved on BrowserStack. Enable user provisioning in BrowserStack once the provisioning setup on Azure AD is completed, to prevent blocking of inviting new users from BrowserStack Account.

Step 2: Configure app on Azure AD

  1. Sign in to the Azure portal. Select Enterprise Applications, then select All applications. Select Applications inside enterprise applications
  2. In the applications list, select BrowserStack Single Sign-on. The BrowserStack Single Sign-on link in the Applications list
  3. Select the Provisioning tab.
    Provisioning tab
  4. Set the Provisioning Mode to Automatic. Azure Provisioning Mode automatic
  5. Under the Admin Credentials section, input your BrowserStack Tenant URL and Secret Token. Click Test Connection to ensure Azure AD can connect to BrowserStack. If the connection fails, ensure your BrowserStack account has Admin permissions and try again. Test connection to browserstack with provided credentials
  6. Once the connection is successful, turn the Provisioning Status to ON. Test provisioning status ON
  7. In the Notification Email field, enter the email address of a person who should receive the provisioning error notifications and select the Send an email notification when a failure occurs check box.
  8. Select Save.

Step 3: Custom attribute mappings

  1. Under the Mappings section, click Provision Azure Active Directory Users.
  2. There will be default attributes visible under Attribute Mappings. These attribute-mappings are mandatory ( e.g. userName,name.givenName, name.familyName ) for application to function correctly. For these required attributes, the Delete feature is unavailable in Azure. Attribute Mapping Focused Section in BrowserStack SSO Provisioning
  3. For the userPrincipalName mapping, click Edit. Under Apply this mapping dropdown, you need to select Always as the value.
    Select Always for userPrincipalName mapping
  4. Apart from required attributes, you will need to configure the custom attributes in order to configure role, team and product-access for any users on BrowserStack: Configure custom attributes
  5. In order to configure the custom attribute, click Add New Mapping.
  6. Under Edit Attribute, select the Mapping type. Under Edit Attribute section, select the Mapping type from the dropdown

Mapping types

Mapping type allows you to define how the custom attributes are populated.You can either use Direct, Constant, or Expression mapping type depending on your needs. Details on how to use a particular mapping type:

A. Direct mapping

In case of Direct mapping, the target attribute is populated with the value of an attribute of the linked object in Azure AD.

  1. Click Mapping type dropdown. Select Direct.
  2. Under Edit Attribute, you can click Target attribute dropdown, to view the 3 custom attributes. You need to map each of these target attributes to a source attribute.
  3. When customizing attribute mappings for user provisioning, you can select the attribute you want to map to any of the target attribute. You can either use existing available source attributes or you can also create and add new source attributes:
Users in Azure AD Cloud For users only in Azure AD, you can use Microsoft Graph or PowerShell to extend the user schema for users in Azure AD.
Users in on-premise Active Directory For users in on-premise Active Directory, you must sync the users to Azure AD cloud. You can sync users and attributes using Azure AD Connect. Azure AD Connect automatically synchronizes certain attributes to Azure AD, but not all attributes.

B. Expression mapping

If you don’t want to create a Source attribute, you can make use of Expression mapping. In this case, the target attribute is populated based on the result of a script-like expression.

  1. Click Mapping type dropdown. Select Expression.
  2. Define the Expression for populating target attribute. For expressions, you can use the user resource type attributes that are supported by the Azure AD directory user profile. Example for expressions:
Target attribute Expression
urn:ietf:params:scim:schemas:extension:Bstack:2.0:User:bstack_product Switch([department], "Live-Testing", "team1", "App-Automate-Testing","team2", "App-Live-Testing")
urn:ietf:params:scim:schemas:extension:Bstack:2.0:User:bstack_role Switch([city], "User", "Mumbai", "Admin", "Delhi", "User")

C. Constant mapping

If you want the target attribute to be populated with a specific string you specified, you can make use of Constant mapping. Example for constants:

Target attribute Constant Value
urn:ietf:params:scim:schemas:extension:Bstack:2.0:User:bstack_role User
urn:ietf:params:scim:schemas:extension:Bstack:2.0:User:bstack_product Live-Testing
Note: For more details on attribute-mappings, see Understanding attribute-mapping types.

BrowserStack attributes description

If you’re a new BrowserStack customer, to assign roles and products, see Assign roles using Automated User Provisioning and Assign product access using Automated User Provisioning.

The details on BrowserStack’s attribute mapping, their possible values and description:

BrowserStack attribute: urn:ietf:params:scim:schemas:extension:Bstack:2.0:User:bstack_role

  1. Default role assigned is User. This is possible in two scenarios:
  2. Supported attribute values (when attribute controlled from Azure AD):
Values Description
User User role will be assigned
Admin Admin role will be assigned
Owner New Owner will be assigned, the current/old owner will be replaced with the new owner. The current/old owner will become an admin.
No Value
Empty or Any other value
The user is created as User by default.

To check the structure of these custom attributes, use the Schemas endpoint.

Step 4: Enable user provisioning

Once you have completed the above steps, go to on BrowserStack and click Enable to enable user provisioning. If you don’t enable it, you will be locked out of inviting new users via BrowserStack UI. Enable user provisioning

Manage users from app on Azure AD

Once auto user provisioning is enabled, the user list is controlled and managed from the IdP.

  1. For your existing users on BrowserStack, we would suggest that as a first step, assign all these users to the BrowserStack application in Azure AD. This would avoid any discrepancies between the user list on BrowserStack and Azure AD.
    • By assigning user(s) to the application, they will get provisioned on BrowserStack.
    • Users will be logged out of the BrowserStack, and will be redirected to log-in via SSO.
  2. To add new users on BrowserStack, add these users in Azure AD and assign them to BrowserStack application via the Assignments tab. Invite modal will no longer be visible in the Account page anymore. If there were any existing invites already sent (before user provisioning was enabled), those invites will become invalid.
  3. Any user can be removed from BrowserStack or their access by revoked by removing the user from the BrowserStack application on Azure AD.
Note: You cannot delete the current Owner from Okta. Assign Owner role to another user, before deleting the current Owner. Updating the owner will log out the current owner as well as the old owner from their current session for security reasons

Monitor your deployment

Once you’ve configured provisioning, use the following resources to monitor your deployment:

  1. Use the provisioning logs to determine which users have been provisioned successfully or unsuccessfully.
  2. Check the progress bar to see the status of the provisioning cycle and how close it is to completion.
  3. If the provisioning configuration seems to be in an unhealthy state, the application will go into quarantine. Learn more about quarantine states in the quarantine status documentation.

BrowserStack SCIM endpoints

Azure AD talks to the BrowserStack SCIM server on the following endpoints. Use them to check which SCIM features BrowserStack supports, look up the structure of the custom attributes, and interpret the responses that appear in your Azure AD provisioning logs.

Service provider configuration

The Service Provider Config endpoint returns the BrowserStack server’s authentication scheme and the optional or configurable SCIM features it supports. Service Provider Config objects are defined by RFC 7643, section 5.

GET https://www.browserstack.com/scim/v2/ServiceProviderConfig

Sample response:

{
  "schemas": ["urn:ietf:params:scim:schemas:core:2.0:ServiceProviderConfig"],
  "documentationUri": "https://www.browserstack.com/docs/enterprise/auto-user-provisioning",
  "patch": { "supported": true },
  "bulk": { "supported": false, "maxOperations": 0, "maxPayloadSize": 0 },
  "filter": { "supported": true, "maxResults": 500 },
  "changePassword": { "supported": false },
  "sort": { "supported": false },
  "etag": { "supported": false },
  "authenticationSchemes": [
    {
      "name": "OAuth Bearer Token",
      "description": "Authentication scheme using the OAuth Bearer Token Standard",
      "specUri": "http://tools.ietf.org/html/rfc6750",
      "type": "oauthbearertoken"
    }
  ],
  "meta": {
    "resourceType": "ServiceProviderConfig",
    "location": "https://www.browserstack.com/scim/v2/ServiceProviderConfig"
  }
}

Resource types

The Resource Types endpoint lists all of the SCIM resource types configured for use on the BrowserStack server. Use the response to determine the endpoint, core schema, and extension schemas of any resource type that the server supports. This endpoint does not provide resource type information about SCIM sub-resources.

The response is formatted as a list response, with one or more resource type objects in the Resources field. Resource type objects are defined by RFC 7643, section 6.

GET https://www.browserstack.com/scim/v2/ResourceTypes

Sample response:

{
  "schemas": ["urn:ietf:params:scim:api:messages:2.0:ListResponse"],
  "totalResults": 1,
  "Resources": [
    {
      "schemas": ["urn:ietf:params:scim:schemas:core:2.0:ResourceType"],
      "id": "Users",
      "name": "Users",
      "endpoint": "/Users",
      "schema": "urn:ietf:params:scim:schemas:core:2.0:User"
    }
  ]
}

User resource type

The Resource Type endpoint retrieves a specific SCIM resource type, specified by its ID. BrowserStack supports the User resource only. Resource type objects are defined by RFC 7643, section 6. This endpoint does not provide resource type information about SCIM sub-resources.

GET https://www.browserstack.com/scim/v2/ResourceTypes/User

Sample response:

{
  "schemas": ["urn:ietf:params:scim:schemas:core:2.0:ResourceType"],
  "id": "Users",
  "name": "Users",
  "endpoint": "/Users",
  "description": "User Account",
  "schema": "urn:ietf:params:scim:schemas:core:2.0:User",
  "meta": {
    "location": "https://www.browserstack.com/scim/v2/ResourceTypes/User",
    "resourceType": "ResourceType"
  }
}
  • To update an existing user resource, use the PUT endpoint.
  • If your IdP does not support the PUT endpoint, use the PATCH /scim/v2/Users/{id} endpoint.

Example request body for a PATCH request:

{
    "schemas": [
        "urn:ietf:params:scim:schemas:core:2.0:User"
    ],
    "Operations":[{"op": "add", "path" : "urn:ietf:params:scim:schemas:extension:Bstack:2.0:User:bstack_product", "value" : "App-Live-Testing,App-Automate-Testing"}]
}

Schemas

The Schemas endpoint lists the SCIM schemas configured for use on the BrowserStack server, which define the attributes available to resource types. Use this endpoint to check the structure of the custom bstack_role, bstack_team, and bstack_product attributes. This endpoint does not provide schema information about SCIM sub-resources.

The response is formatted as a list response, with one or more schema objects in the Resources field. Schema objects are defined by RFC 7643, section 7.

GET https://www.browserstack.com/scim/v2/Schemas

Sample response:

{
  "schemas": ["urn:ietf:params:scim:api:messages:2.0:ListResponse"],
  "totalResults": 1,
  "Resources": [
    {
      "id": "urn:ietf:params:scim:schemas:core:2.0:User",
      "name": "User",
      "description": "User Schema",
      "attributes": [
        {
          "name": "userName",
          "type": "string",
          "multiValued": false,
          "required": true,
          "caseExact": false,
          "mutability": "readWrite",
          "returned": "default",
          "uniqueness": "server",
          "description": "Unique identifier for the User, typically used by the user to directly authenticate to the service provider. Each User MUST include a non-empty userName value. This identifier MUST be unique across the service provider's entire set of Users."
        },
        {
          "name": "name",
          "type": "complex",
          "multiValued": false,
          "required": false,
          "mutability": "readWrite",
          "returned": "default",
          "uniqueness": "none",
          "description": "The components of the user's real name. Providers MAY return just the full name as a single string in the formatted sub-attribute, or they MAY return just the individual component attributes using the other sub-attributes, or they MAY return both.  If both variants are returned, they SHOULD be describing the same name, with the formatted name indicating how the component attributes should be combined.",
          "subAttributes": [
            {
              "name": "familyName",
              "type": "string",
              "multiValued": false,
              "required": false,
              "caseExact": false,
              "mutability": "readWrite",
              "returned": "default",
              "uniqueness": "none",
              "description": "The family name of the User, or last name in most Western languages (e.g., 'Jensen' given the full name 'Ms. Barbara J Jensen, III')."
            },
            {
              "name": "givenName",
              "type": "string",
              "multiValued": false,
              "required": false,
              "caseExact": false,
              "mutability": "readWrite",
              "returned": "default",
              "uniqueness": "none",
              "description": "The given name of the User, or first name in most Western languages (e.g., 'Barbara' given the full name 'Ms. Barbara J Jensen, III')."
            }
          ]
        },
        {
          "name": "active",
          "type": "boolean",
          "multiValued": false,
          "required": true,
          "mutability": "readWrite",
          "returned": "default",
          "uniqueness": "none",
          "description": "A Boolean value indicating the User's status."
        },
        {
          "name": "bstack_team",
          "type": "string",
          "multiValued": false,
          "required": false,
          "mutability": "readWrite",
          "returned": "default",
          "uniqueness": "none",
          "description": "A String value indicating the User's Team in BrowserStack"
        },
        {
          "name": "bstack_role",
          "type": "string",
          "multiValued": false,
          "required": false,
          "mutability": "readWrite",
          "returned": "default",
          "uniqueness": "none",
          "description": "A String value indicating the User's Role in BrowserStack"
        },
        {
          "name": "bstack_product",
          "type": "string",
          "multiValued": true,
          "required": false,
          "mutability": "readWrite",
          "returned": "default",
          "uniqueness": "none",
          "description": "A String value indicating the User's Product accesses in BrowserStack"
        }
      ],
      "meta": {
        "resourceType": "Schema",
        "location": "https://www.browserstack.com/scim/v2/Schemas/urn:ietf:params:scim:schemas:core:2.0:User"
      }
    }
  ]
}

Individual schema

The Schema endpoint retrieves a specific SCIM schema, specified by its ID, which is always a URN. BrowserStack supports the User schema only. Schema objects are defined by RFC 7643, section 7. This endpoint does not provide schema information about SCIM sub-resources.

GET https://www.browserstack.com/scim/v2/Schemas/urn:ietf:params:scim:schemas:core:2.0:User

The response is the same User schema object that the Schemas endpoint returns in its Resources array, returned on its own without the list wrapper. For the full object, see the Schemas sample response.

Replace a user

The Replace User endpoint updates an existing user by replacing the resource with the values in the request body. You can update the name, role, team, and product attributes, and change the email through userName. Attributes that are controlled by the BrowserStack dashboard as per the current configuration cannot be updated through this endpoint.

PUT https://www.browserstack.com/scim/v2/Users/{id}

A successful request returns 200 with the full user resource, including externalId, active, and the custom bstack_* attributes:

{
  "schemas": ["urn:ietf:params:scim:schemas:core:2.0:User"],
  "id": 12345,
  "externalId": "john.doe",
  "userName": "john.doe@example.com",
  "active": true,
  "name": { "givenName": "John", "familyName": "Doe" },
  "emails": [{ "primary": true, "value": "john.doe@example.com" }],
  "bstack_role": "Admin",
  "bstack_team": "Engineering",
  "bstack_product": "Live,Automate",
  "meta": {
    "resourceType": "User",
    "created": "2026-01-10T08:12:33.000Z",
    "lastModified": "2026-07-15T09:00:00.000Z",
    "location": "https://www.browserstack.com/scim/v2/Users/12345"
  }
}

In this response, userName carries the user’s email, and externalId carries the BrowserStack username.

Some fields are returned conditionally based on your SCIM configuration:

  • bstack_role, bstack_team, and bstack_product are returned only when that attribute is controlled by the IdP in your SCIM configuration.
  • meta is returned only for accounts enabled for the SCIM metadata response.
  • id is an integer by default, and a string for accounts enabled for string user IDs.

Update a user

The Update User endpoint applies a partial update to an existing user using a SCIM PatchOp request. A replace operation that sets active to false de-provisions the user.

PATCH https://www.browserstack.com/scim/v2/Users/{id}

A successful request returns 200 with the full user resource, including the conditionally returned fields listed under Replace a user.

{
  "schemas": ["urn:ietf:params:scim:schemas:core:2.0:User"],
  "id": 12345,
  "externalId": "john.doe",
  "userName": "john.doe@example.com",
  "active": true,
  "name": { "givenName": "John", "familyName": "Doe" },
  "emails": [{ "primary": true, "value": "john.doe@example.com" }],
  "bstack_role": "Admin",
  "bstack_team": "Engineering",
  "bstack_product": "Live,Automate",
  "meta": {
    "resourceType": "User",
    "created": "2026-01-10T08:12:33.000Z",
    "lastModified": "2026-07-15T09:00:00.000Z",
    "location": "https://www.browserstack.com/scim/v2/Users/12345"
  }
}

Error responses

When a request fails, all endpoints return the same SCIM error envelope with an HTTP status code such as 400, 403, 404, or 422:

{
  "schemas": ["urn:ietf:params:scim:api:messages:2.0:Error"],
  "detail": "Human-readable error message",
  "status": "404"
}

Common cases include:

  • 403: Missing or invalid credentials.
  • 404: The requested resource is not found.
  • 400 or 422: Invalid request, or an attribute that is controlled by the BrowserStack dashboard as per the current configuration.

Troubleshooting

Below is a list of possible errors that might be encountered and how to resolve them:

Email is already part of a different organization account on BrowserStack

Resolution: User is already present on BrowserStack under a different organization, please reach out to BrowserStack support to get that account deleted before provisioning the user to your current organization account. Error - Email is already part of a different organization account on BrowserStack

Invalid parameter or attribute

Resolution: Role/Product is not a valid use-case, please use the attribute values provided above. Error - Invalid parameter or attribute

Owner deletion

Resolution: Assign ownership to a different user before deletion of this user. Owner cannot be deleted, BrowserStack account needs a user to have Owner role assigned. Error - Owner deletion

Incompatible attributes

Resolution: You are assigning incompatible user attributes, for example Owner cannot have a team assigned. Error - Incompatible attributes

Licenses unavailability

Resolution: You have used up all your licenses for the product, please unassign users or add more licenses. Contact your Account Executive to get information on adding licenses. Error - Licenses not available

Note: When user is deactivated on Azure AD, they will be deleted from your BrowserStack account. Whenever user is activated, a new user will be created on BrowserStack. This would lead to a new id being created.

Escalation/Support

Contact us for any escalations or support.

We're sorry to hear that. Please share your feedback so we can do better

Contact our Support team for immediate help while we work on improving our docs.

We're continuously improving our docs. We'd love to know what you liked





Thank you for your valuable feedback

Is this page helping you?

Yes
No

We're sorry to hear that. Please share your feedback so we can do better

Contact our Support team for immediate help while we work on improving our docs.

We're continuously improving our docs. We'd love to know what you liked





Thank you for your valuable feedback!

Talk to an Expert
Download Copy Check Circle