Microsoft Entra ID
Enterprise plan. Owner and Admin. You will also need someone who can edit the Entra enterprise app.
What you set up
- Staff sign in to Bruchim with Entra (SSO).
- Entra provisioning creates, updates, and deactivates people on Users.
- Optional: Entra Office location sets Host locations and Primary location.
Turn on SSO
- Workspace switcher → Manage organization → Security.
- Add and verify your domain (DNS
TXT). - Choose Microsoft Entra, finish SAML, test, then turn the connection on.
You should see SSO with Active and your domain. That tab does not include Directory Sync.
Only Owners and Admins can open Security.
Bruchim Staff (email [email protected]): if Security is missing, ask us to enable enterprise SSO. Include the workspace name.
Staff then use the usual Bruchim sign-in with their work account. See SSO and directory sync.
Turn on Directory Sync
Self-serve UI coming soon. You cannot turn this on from Manage organization.
- Email [email protected] after SSO is Active. Ask Bruchim Staff to enable Directory Sync. Include the workspace name and domain.
- We reply with a provisioning URL (Tenant URL) and a secret token. You only get the token once. Store it like a password.
- If people should appear only from Entra, not on first sign-in, say that in the email.
In Entra
Open the Microsoft Entra admin center → Enterprise applications → the Bruchim app.
- Provisioning → Provisioning Mode: Automatic.
- Admin Credentials: Tenant URL and Secret token from our email.
- Test Connection, then Save.
- Provisioning Status: On, then Save.
- Assign the users or groups who should exist in Bruchim.
- Provision on demand for one person who has a work email, then check Users in Bruchim.
Keep the default mapping from mail to the work email. Entra must send a work email, not only a user name.
People from Directory Sync show a Directory sync badge. They join as Employee unless you already invited them with another role. Entra or organization Member is not the Bruchim role. Change Owner, Admin, Location Manager, or Reception on Users.
If they are in Entra but not on Users
- Confirm they are assigned to the enterprise app and provisioning succeeded.
- Have them sign in to Bruchim once.
- If they still do not appear, email [email protected] with the workspace name and their work email.
Map Office location to a host site
Bruchim maps a short attribute name (usually office), not the Entra field name physicalDeliveryOfficeName.
Bruchim Staff
Email [email protected] and ask to map Office location to host sites. Include the workspace name.
We:
- Create the attribute (name
office). - Send you the target attribute to add in Entra (paste it exactly).
- Finish the mapping on our side after you have provisioned someone who has Office filled in.
You (Entra)
On the app’s Attribute mapping page (Users):
- Open Advanced options (or Show advanced options on the older mapping page).
- Edit attribute list for the app. If that link is missing, ask us; we will send the Azure URL that unlocks the schema editor.
- Add a String attribute whose name is the target we sent.
- Save.
- Add attribute mapping: Direct. Source
physicalDeliveryOfficeName(Office location). Target: that same name. Apply Always. Do not use it as a matching attribute. - Save. Use Refresh if the new target does not appear yet.
You can leave the default row that also maps Office location to the formatted work address. Do not use addresses for host mapping in Bruchim.
Provision on demand a user whose Office location is not blank. An empty Office is not sent, so the mapping cannot be tested.
Then reply to the support thread so we can finish the connection-side map.
If the target we sent never appears, tell us. We can have you map Office location to enterprise organization (already in Entra’s target list) instead.
You (Bruchim)
Settings → General → Host locations for provisioned people:
- From an identity-provider attribute.
- Attribute key:
office(or the name we confirmed). - Add mapping. Attribute value must match Entra exactly (for example
Toronto HQ). - Pick the Bruchim location.
- Set If the value is not mapped to a fallback location, or leave it as All locations.
Directory-synced people get this on every sync. See Host and Admin locations.