How to Provision Users from Microsoft Identity Management to MySQL
Question details
A developer needs to provision user identities directly into a MySQL table using Microsoft identity and access management for an application that lacks SCIM support.

- Product
- Microsoft Identity Management (Entra ID) / MySQL
- Device & OS
- Ubuntu
- Scenario
- Integrating a custom application's MySQL database with Microsoft Identity Management to automate user provisioning without standard SCIM integration.
- Observed behavior
- The user wants to establish a direct provisioning pipeline from Microsoft Entra ID to a MySQL database table, bypassing the unsupported SCIM protocol.
Define your specific MySQL database schema and security requirements, and ensure you have administrative access to both Microsoft Entra ID and the Ubuntu hosting environment.
Implement a Custom API Connector or Middleware
Since the custom application does not support SCIM natively, building or configuring a custom API or middleware is the recommended way to bridge Microsoft Identity Management and the MySQL database.
A direct Microsoft Entra ID provisioning connector for an arbitrary MySQL application is not natively available out of the box. Instead of standard SCIM integration, you must utilize an intermediary service.
This intermediary acts as a translation layer, receiving provisioning payloads from Microsoft Entra ID (via Webhooks, Logic Apps, or Graph API) and executing the corresponding INSERT or UPDATE statements on your MySQL database.
Identify the specific user fields required by your custom application (e.g., username, email, department) and map them to the corresponding attributes in Microsoft Entra ID.
Deploy an API endpoint on your Ubuntu server or use a cloud service like Azure Logic Apps. The service should be capable of accepting HTTP requests from Microsoft Entra ID and executing SQL queries.
In the Microsoft Entra ID portal, configure a custom provisioning application. Set the target endpoint to your newly created middleware API and define the attribute mapping rules.
Ensure the connection between the middleware and the MySQL database is encrypted. Restrict network access to the API endpoint so it only accepts traffic from verified Microsoft IP addresses.

Boost Your Productivity with WPS Office
While integrating complex identity management systems, you need reliable tools for documenting database schemas, API mapping, and project planning. WPS Office provides a fast, lightweight, and highly compatible alternative to Microsoft Office, perfect for developers and IT professionals.
- 1. Download and Install: Visit the official WPS website to download the free installation package for your operating system.
- 2. Document Your Schema: Open WPS Spreadsheet to easily map Microsoft Entra ID attributes to your MySQL columns.
- 3. Save and Share: Save your documentation in .xlsx or .docx formats for full compatibility with team members using Microsoft Office.

Frequently Asked Questions
Does Microsoft Entra ID natively support direct MySQL database provisioning?
No, Microsoft Entra ID typically relies on SCIM (System for Cross-domain Identity Management) for automated provisioning. For a custom MySQL database without SCIM support, you must use a custom connector, API, or middleware.
What is SCIM and why is it important for user provisioning?
SCIM is an open standard designed to simplify managing user identities in cloud-based applications. When an application supports SCIM, Microsoft Entra can automatically provision and deprovision users without requiring custom SQL queries or middleware.
Can I use Azure Logic Apps to sync Entra ID users to MySQL?
Yes, Azure Logic Apps can act as the middleware layer. You can configure a workflow that triggers upon user creation or modification in Entra ID, and then uses the Azure Logic Apps MySQL connector to execute SQL queries directly against your database.




