Scim.json
Cautions¶
- When changing parameters, please refer to "Confirmation When Changing Parameters".
Setting Values¶
The setting values of this parameter file are as follows.
| Parameter name | e.g. | Description |
|---|---|---|
| Enabled | true | Specify whether to enable the integration of user information and group information by "SCIM". The setting of this parameter affects the whole of Pleasanter. Manage whether integration is allowed for each tenant with the SCIM token issued on the tenant management screen. |
| SwaggerEnabled | false | Specify whether to display the screen used to check the operation of the SCIM function and to check during application development. It is not a screen that general users use on a daily basis. In a production environment, set it to false if it is not required. |
| ExtendedAttributes | See below | The setting for storing SCIM attributes in "extended columns" added to the user management screen or the group management screen. For details, see "ExtendedAttributes" below. |
Setting Example¶
{
"Enabled": true,
"SwaggerEnabled": false,
"ExtendedAttributes": {
"Users": [
{
"Schema": "urn:pleasanter:params:scim:schemas:extension:custom:2.0:User",
"Name": "jobTitle",
"ColumnName": "Users_ClassB"
}
],
"Groups": [
{
"Schema": "urn:pleasanter:params:scim:schemas:extension:custom:2.0:Group",
"Name": "groupType",
"ColumnName": "Groups_ClassA"
}
]
}
}
ExtendedAttributes¶
ExtendedAttributes is the setting for linking an "attribute" on the ID provider side to an "extended column" added to the "User Management" screen or the "Group Management" screen of Pleasanter.
For example, to store the attribute "jobTitle" on the ID provider side in the "extended column" "Users_ClassB" on the user management screen, set it as follows.
"ExtendedAttributes": {
"Users": [
{
"Schema": "urn:pleasanter:params:scim:schemas:extension:custom:2.0:User",
"Name": "jobTitle",
"ColumnName": "Users_ClassB"
}
],
"Groups": []
}
ExtendedAttributes.Users¶
Sets the mapping of extended attributes for users.
Example:
"Users": [
{
"Schema": "urn:pleasanter:params:scim:schemas:extension:custom:2.0:User",
"Name": "jobTitle",
"ColumnName": "Users_ClassB"
},
{
"Schema": "urn:pleasanter:params:scim:schemas:extension:custom:2.0:User",
"Name": "officeLocation",
"ColumnName": "Users_DescriptionA"
}
]
In this example, the values are stored as follows.
| SCIM attribute | Storage destination in Pleasanter |
|---|---|
| jobTitle | Users_ClassB |
| officeLocation | Users_DescriptionA |
In the attribute mapping on the Entra ID side, specify the full attribute name including the schema, as follows.
| Storage destination in Pleasanter | SCIM attribute to specify on the Entra ID side |
|---|---|
| Users_ClassB | urn:pleasanter:params:scim:schemas:extension:custom:2.0:User:jobTitle |
| Users_DescriptionA | urn:pleasanter:params:scim:schemas:extension:custom:2.0:User:officeLocation |
ExtendedAttributes.Groups¶
Sets the mapping of extended attributes for groups.
Example:
"Groups": [
{
"Schema": "urn:pleasanter:params:scim:schemas:extension:custom:2.0:Group",
"Name": "groupType",
"ColumnName": "Groups_ClassA"
},
{
"Schema": "urn:pleasanter:params:scim:schemas:extension:custom:2.0:Group",
"Name": "groupNote",
"ColumnName": "Groups_DescriptionA"
}
]
In this example, the values are stored as follows.
| SCIM attribute | Storage destination in Pleasanter |
|---|---|
| groupType | Groups_ClassA |
| groupNote | Groups_DescriptionA |
In the attribute mapping on the Entra ID side, specify the full attribute name including the schema, as follows.
| Storage destination in Pleasanter | SCIM attribute to specify on the Entra ID side |
|---|---|
| Groups_ClassA | urn:pleasanter:params:scim:schemas:extension:custom:2.0:Group:groupType |
| Groups_DescriptionA | urn:pleasanter:params:scim:schemas:extension:custom:2.0:Group:groupNote |
In ExtendedAttributes.Users and ExtendedAttributes.Groups, set the following parameters.
| Item | Content |
|---|---|
| Schema | The extended schema of SCIM |
| Name | The attribute name on the SCIM side |
| ColumnName | The name of the storage destination column on the Pleasanter side |
Schema¶
Sets the extended schema of SCIM.
- The schema setting on the Pleasanter side can be omitted.
- In the attribute mapping on the ID provider side, the full attribute name must be set.
| Type of extended column | Extended schema of SCIM |
|---|---|
| User extended column | urn:pleasanter:params:scim:schemas:extension:custom:2.0:User |
| Group extended column | urn:pleasanter:params:scim:schemas:extension:custom:2.0:Group |
Name¶
Specify the trailing string of the attribute name used in the "attribute mapping" on the ID provider side.
SCIM attribute name on the ID provider side¶
Setting example of Name in Scim.json¶
ColumnName¶
Specify the column name of the "extended column" used as the storage destination on the Pleasanter side.
- To store the value in an "extended column" added to the "User Management" screen, specify the column name of the "extended column" with the prefix Users_.
- To store the value in an "extended column" added to the "Group Management" screen, specify the column name of the "extended column" with the prefix Groups_.
Example:
Columns That Can Be Specified on the Pleasanter Side¶
What can be used as the storage destination of SCIM extended attributes are the "extended columns" of the "User Management" screen or the "Group Management" screen.
Mainly the following columns are specified.
Users_ClassA
Users_ClassB
Users_ClassC
Users_DescriptionA
Users_DescriptionB
Groups_ClassA
Groups_ClassB
Groups_ClassC
Groups_DescriptionA
Groups_DescriptionB
Extended columns of the Class type and the Description type can be used.
To display them on the screen, set the display names and so on separately in CustomDefinitions\Column.json.
Setting the Display Name of an Extended Column¶
To display an extended column on the screen of Pleasanter, set CustomDefinitions\Column.json.
Target folder:
File name:
Setting example:
{
"Users_ClassB": {
"LabelText": "Job Title",
"GridEnabled": "1",
"EditorEnabled": "1"
},
"Groups_ClassA": {
"LabelText": "Group Type",
"GridEnabled": "1",
"EditorEnabled": "1"
}
}
In this example, they are displayed as follows.
| Column name | Display name on the screen |
|---|---|
| Users_ClassB | Job Title |
| Groups_ClassA | Group Type |
Attribute Names to Specify on the Microsoft Entra ID Side¶
In the attribute mapping of Microsoft Entra ID, specify not only Name on the Pleasanter side but the full attribute name including the schema.
As an example, when the following is set in Scim.json:
{
"Schema": "urn:pleasanter:params:scim:schemas:extension:custom:2.0:User",
"Name": "jobTitle",
"ColumnName": "Users_ClassB"
}
On the Entra ID side, specify the following value for the customappsso attribute.
If you specify only jobTitle, the integration may not work as expected.
Be sure to specify the full attribute name on the Entra ID side.
Supported Versions¶
| Supported versions | Body |
|---|---|
| 1.5.8.0 and later | Added Scim.json |