Skip to main content
MichelB
BeyondTrust Employee
BeyondTrust Employee
September 10, 2026

Entra ID - Pathfinder SCIM - Setup guide

  • September 10, 2026
  • 0 replies
  • 7 views

BeyondTrust Pathfinder SCIM API can be used for provisioning into all BT products or modules. It replaces the standalone SCIM API found in Password Safe, Endpoint Privilege Management or EPM Windows & Mac, and Privileged Remote Access or PRA.

 

This guide is a complement to Documentation - SCIM Provisioning

 

The first step is to create a SCIM token as the SCIM service account, and note the Org ID in the upper right corner.  The User must be Administrator in individual BT modules.

 

For an Enterprise Application, add Provisioning configuration and Test Connection.

 

Note:  Url is https://api.beyondtrust.io/api/{organization-id}/platform/auth/scim/v2 and you need to replace {organization-id} with Org ID from Pathfinder.

 

Attribute mappings.

 

Provisioning Settings.

 

Testing
 

Users and groups:  Assign new User to App.

 

Provision on demand:  Provision test user.

 

Provisioning should be a success.

The user should be provisioned into Pathfinder.

 

Create a new Group and assign a different test user.

 

Add the Group to Enterprise App for Pathfinder.

 

Provision on demand:  New Group and test User.

 

Provision on demand: Success for Group (and member).

 

Group is available within modules, e.g. EPM Win & Mac, and it can be added to a role etc.  The members will inherit roles and permissions.