SCIM guide: Migrate Microsoft Entra ID integration to Lucid organizational groups experience

Written by:  Shanna S
Last updated:  

Lucid has released a new group management experience. This new organizational groups feature offers enhanced flexibility in user management by allowing license settings in Lucid to be configured and applied at the group level. For instance, you can automatically assign licenses to users within your engineering group while requiring users in your sales team to request a license.

Accounts with SCIM enabled weren’t automatically migrated to the new experience as there are required steps to ensure continued functionality with your Microsoft Entra ID (previously Azure Active Directory) SCIM integration. This article walks you through the process of prepping your Entra ID SCIM instance and Lucid account to successfully migrate to the new organizational groups experience.

If you are setting up SCIM for your account for the first time, see our Enable Microsoft Entra ID SAML and SCIM in Lucid article. The migration instructions found in this article are only relevant to accounts that were using SCIM in Lucid prior to October 22nd, 2024.

Plan availability: Enterprise only.

Prepare the Microsoft Entra ID app

Before you can migrate to the new organizational group experience in Lucid, you must ensure that your Entra ID SCIM instance is properly configured. This migration guide is for accounts that:

  • Have previously connected your Microsoft Entra ID environment to Lucid
  • Have been using SCIM to push users and groups
  • Have been using SCIM to license and delicense users in Lucid 

You must be using the Lucid (All Products) application for SCIM provisioning in order to migrate to the Lucid organizational groups experience. Follow the instructions found in our Enable Microsoft Entra ID SAML and SCIM in Lucid article if you aren’t yet using SCIM.

Note: The Lucidchart application is outdated and won’t work. Before continuing with the instructions in this article for migration, you need to follow the instructions in the Enable Microsoft Entra ID SAML and SCIM in Lucid article to set up the Lucid (All Products) app.

Reconfigure the Lucid (All Products) app

Locate the Lucid (All Products) app in Microsoft Entra ID

The majority of the changes that you’ll make are from the Lucid (All Products) app in Entra ID. To locate this app, follow these instructions:

  1. Select Entra ID from the navigation menu on the left-hand side of the Azure home page.
  2. Select Enterprise Applications from the left-hand menu.
  3. Click your Lucid (All Products) app.

Turn off provisioning temporarily

While you are making changes to prepare the integration to migrate to the new organizational groups experience in Lucid, you need to stop provisioning so that no users are affected before the changes have successfully been made. Here’s how:

  1. From the Lucid (All Products) app in Entra ID, select the Manage dropdown from the left-hand menu.
  2. Select Provisioning from the dropdown options.
  3. Click stop-provisioning-icon-in-azure.jpg Stop provisioning from the menu at the top of the page.

Update attribute mappings

Access the attribute mappings and make required changes by following these steps:

  1. From the provisioning page of the Lucid (All Products) app in Entra ID, click edit-provisioning-icon-in-azure.jpg Edit provisioning.
  2. Select the Mappings dropdown.
  3. From the expanded menu, click Provision Microsoft Entra ID Users.
    • Make sure you select the “Users” option, and not the “Groups” option.
  4. From the “Remove” column, select Delete for the following Lucid attribute mappings:
    • urn:ietf:params:scim:schemas:extension:lucid:2.0:User:productLicenses.Lucidchart
    • urn:ietf:params:scim:schemas:extension:lucid:2.0:User:productLicenses.Lucidspark
  5. Click Save.

Customize user groups

To access and customize your user groups to function after the migration, follow these steps:

  1. From the Lucid (All Products) app in Lucid, select the Manage dropdown from the left-hand menu.
  2. Select Users and groups from the dropdown menu.
  3. We recommend assigning the following groups:
    • An “All Users” group: This should be the group to which all current and new users at your company are automatically added. It allows all assigned users to sign into the Lucid application (if SAML has been configured) and is used to provision all users in this group into your default Lucid organizational group.
      • There is no limit on the number of users you can have in this group within Lucid because they are provisioned as limited-access users by default. Users can have membership in this group until they leave the company.
    • Customized licensing groups.
      • These groups will be used to assign a user a license in Lucid based on their membership to the group.
      • Removing users from a licensing group will delicense them to free up licenses for others to use.

Note: You can have as many license user groups as you want, but because a user can only belong to one organizational group, each user can also only belong to one push group at a time across all groups. The only exception to this rule is the “All Users” group which all users will be in alongside their license group.

lucid-all-products-user-groups-for-scim-org-groups.png

Enable SCIM organizational groups in Lucid

For this stage of the migration, you need account owner or account admin access to Lucid. If you aren’t assigned one of those admin roles, reach out to the admin for your Lucid account to be assigned one of these roles before proceeding with the following steps.

To enable SCIM organizational groups:

  1. Log in to Lucid.
  2. Select Admin from the left-hand menu.
  3. Click App integration from the left-hand navigation menu.
  4. From the dropdown menu, click General.
  5. Locate the SCIM tile and click Settings.
  6. You will be prompted by the instructions at the top of the page to enable SCIM for organizational groups.
    • Under action item 1, click Enable SCIM for org group.
    • Then return to this article and continue with the reconfiguration of your Lucid (All Products) app. When you are finished, you will return to the SCIM page in Lucid and under action item 2, click Lucid app reconfigured.
  7. Under “Exclude groups from your identity provider”, click Edit to the far-right.
  8. Type in the name of the “All Users Group” from Entra ID and any other groups you wish to exclude.
    • Your “All Users Group” will most likely be named something different and it must be an exact name match (case isn’t sensitive) with the name of your Microsoft Entra ID group.
  9. Click Save.

Note: The exclude groups setting, covered in steps 7-8 above, allows you to exclude specific identity provider groups via SCIM sync without having to change your IDP while also ensuring that users will be assigned to their specific licensing group in Lucid, instead of the broader group.

Turn provisioning back on

Now that you have successfully completed the migration steps, you can enable provisioning again. To do so:

  1. Navigate back to the “Lucid (All Products)” app in Entra ID.
  2. Open the “Provisioning” page.
  3. Click Start provisioning.
  4. Wait while Entra ID provisions your users, groups, and memberships into Lucid.
    • Once the “Current cycle status” shows as 100% complete, move on to the next section.

View Microsoft Entra ID groups as organizational groups in Lucid

Check that you are seeing the expected Microsoft Entra ID groups as organizational groups in Lucid, which is confirmation that the migration was successful. To access the organizational groups page in Lucid, follow these steps:

  1. Navigate back to the Lucid admin panel.
  2. Select Groups from the left-hand navigation menu.
  3. From the dropdown menu, click Organizational groups.

If the Entra ID provisioning is finished (we recommend ensuring before you move onto this section) you should now see your Microsoft Entra ID groups as organizational groups on this page of the Lucid admin panel. 

lucid-suite-scim-user-groups-visible-as-organizational-groups-in-lucid.png

Note: If you successfully followed the steps to exclude the All Users group (and any other applicable groups) in Entra ID from organizational groups, you won't see that group in the Lucid admin panel. Any users that aren’t added to one of the organizational groups you created to license users will instead be added to the “Default organizational group” automatically.

Configure license settings for each group

You’re now ready to configure the license settings for each of your organizational groups. This ensures that users are licensed or delicensed appropriately when they are added to or removed from one of these licensing groups. 

To access license settings, follow these steps:

  1. Navigate to the Lucid admin panel.
  2. Select License settings from the left-hand navigation menu.
  3. From the dropdown menu, click Lucid Suite settings.
  4. Proceed to the appropriate set of steps below to customize license settings for each organizational group.

example-of-license-settings-for-a-licensing-scim-org-group.png

Configure license setting for licensed users group:

  1. Click Lucid Suite Licensed Users from the list of organizational groups on the left-hand side of the licensing page.
  2. Under the “Access eligibility” section, select Eligible for full access.
  3. Under “Customized eligibility criteria”, select Instant access.
  4. Click Save changes.

Note: These settings make it so any users added to this group via SCIM automatically receive a Lucid Suite license. Removing a user from a license group will delicense the user, which allows you to free up licenses for others to use.

Test provisioning

You have now completed all the steps to reconfigure the Lucid (All Products) app. License settings should now be managed via the organizational groups created via SCIM.

To test provisioning for a user and ensure this has been set up properly, refer to the steps provided in our Enable Microsoft Entra ID SAML and SCIM in Lucid article.

Deactivate users

In some cases, you may want to fully deactivate users via SCIM, rather than just removing them from a licensing group in SCIM. This will ensure that these users can no longer sign into Lucid under this account, even as limited-access users. A deactivation via SCIM will additionally trigger a de-license automatically.

When deactivating a user, you must transfer their documents to another user on your Enterprise account. The document transfer will occur 24 hours after delicensing via SCIM.

By default, the account owner will be the recipient of the documents that are automatically transferred upon delicensing or deleting a user. You can change the recipient of the transferred documents by navigating to the SCIM integration settings in the Lucid admin panel and selecting Modify default owner to the right-hand side of the email address. See the screenshot below for reference.

Clicking Modify default owner redirects you to the “Compliance settings” page of the admin panel where you can change who the default document owner on your account is. Refer to Lucid admin panel: Compliance settings article for additional details.
change-recipient-of-documents-when-deleting-or-delicensing-users-via-SCIM.png

Give feedback on this article

Have feedback about this article? Tell us about your experience here.

Did you find what you were looking for?

Still have a question or want to share what you have learned? Visit our Community   to get help and collaborate with others.