Azure AD/ Entra ID SCIM provisioning
Set up Azure AD/ Entra ID to provision your team or district’s SCIM (System for Cross-domain Identity Management).
Who can use this feature?
SCIM is only available to Canva Enterprise and Canva for Districts, and it isn’t available for new Canva Teams subscribers.
Limitations: For teams within an organization's structure (both single-team or multi-team), user provisioning and deprovisioning are supported. However, all other functionalities, such as provisioning users directly into specific teams or creating groups, aren’t currently supported.
Supported provisioning features
- Create users - Users in Azure AD/ Entra ID assigned to the Canva App are added as members of the organisation in Canva.
- Update user attributes - Updates made to the user's profile through Azure AD/ Entra ID will be pushed to Canva.
- Deactivate users - Deactivating the user through Azure AD/ Entra ID will lock the user in Canva.
- Create groups - Groups created in Azure AD/ Entra ID can also be created in Canva as a Group under the Canva brand.
- Update group - Updates made to the group’s profile or membership change through Azure AD/ Entra ID will be pushed to Canva.
Step 1: Configure Azure AD/ Entra ID SAML
Azure's built-in Canva application supports SCIM by default. To set up SCIM, complete the setup instructions in Azure AD/ Entra ID SAML configuration for Canva Enterprise or Azure AD/ Entra ID SAML configuration (For Education).
Step 2: Get Canva’s SCIM provisioning API token
- Log in to your Canva account.
- On the homepage, select your account profile to open menu.
- Choose Settings.
- From the side menu, select the SSO and provisioning tab.
- Under Single Single Sign-On (SSO) section, click Manage.
- Choose Configure Provisioning.
- Under Provision Accounts for your team, select Add provisioning method.
- Choose SCIM, then turn on Enable SCIM user provisioning.
- Copy the access token.
Step 3: Configure SCIM provisioning in Azure AD/ Entra ID
- Open the Canva app you’ve set up in Azure AD/ Entra ID.
- From the side menu under Manage, select Provisioning.
- Next to Provisioning Mode, select Automatic from the dropdown.
- Under Admin Credentials, input the following:
- Tenant URL: https://www.canva.com/_scim/v2
- Secret Token: enter Canva’s access token from Step 2
- To verify the connection, click Test Connection.
- On top of the settings window, click Save.
If you need to test automated provisioning for a small number of users before rolling out to everyone, we recommend configuring scoping filters for users and groups first. See Scoping users or groups to be provisioned with scoping filters for instructions.
Configure Attribute Mappings
Users
Canva doesn’t support user account deletion via SCIM.
- Under the Mappings, select Provision Azure Active Directory/ Entra ID Users.
- Under the Target Object Actions, make sure to only select Create and Update.
- Under Attribute Mappings, configure them as follows:
- It’s important that the SAML nameId attribute matches the SCIM userName attribute above. Ensure that in the Single sign-on configuration, the Unique User Identifier is mapped to user.userprincipalname, like below:
- Click Save.
Groups
- Under Mappings, select Provision Azure Active Directory/ Entra ID Groups.
- Under Attribute Mappings, configure them as follows:
- Click Save.
Groups aren’t required and can be disabled if you don't want them. Otherwise, any group assigned to Canva will be created.
Troubleshooting
- From the sidebar, go to the Monitor section.
- Select Provisioning logs to see what SCIM actions have been run.
Azure’s/ Entra ID's provisioning cycle generally runs every 40 minutes. So there may be delays in propagating the changes in your Active Directory to relevant users and groups in Canva.
Error: Missing email in SCIM create user
Ensure that your AD Users have the email property populated in their profiles.
If you’re having trouble configuring your Canva/Azure AD/ Entra ID SCIM integration, contact our Support team for help.
For advanced users, please see our developer documentation on the SCIM endpoint for more information.
Was this helpful?
Helpful
Unhelpful