Enable Microsoft Entra ID SAML and SCIM in Lucid

Written by:  Shanna S
Last updated:  

Integrating Lucid with Microsoft Entra ID (previously Azure Active Directory) enables your users to authenticate using SAML single-sign on. Entra ID also offers a SCIM connection that allows you to provision users in your IdP. 

The following tutorial walks through the process of integrating Entra ID with Lucidchart and Lucidspark. You will need admin privileges in both Microsoft Entra ID and Lucid to set up this integration.

Plan availability: Enterprise only.
  • The SAML integration for Lucid is available on FedRAMP accounts, but the SCIM applications are not.
  • Read the Lucid Plans article for more information about what is available on your account or the Upgrade your Lucid account article for instructions to upgrade.

Set up the Lucid for admin management app in Microsoft Entra ID

  1. Log in to Azure.
  2. From the home page, click Entra ID from the navigation menu on the left-hand side.
  3. Select Enterprise Applications from the navigation menu on the left-hand side.
  4. Click +New application at the top-left of the page.
  5. Search “Lucid” and select the Lucid (All Products) tile.
    • We recommend if you are planning to use SCIM, that you label this app in Entra ID as “Lucid for admin management” as if you decide to also leverage SCIM, there are two Lucid apps that we recommend.
  6. Click Create.

The app created here is used for both SAML and SCIM.

Configure the SAML integration for Lucid via Azure Portal

Note: The steps as outlined in this section are done for setting up SAML with the Lucid for admin management app, rather than a Lucid for content access app. If you are using a Lucid for content access group but not using a Lucid for admin management app for user licensing in SCIM, you can follow these instructions for your Lucid for content access app instead. To learn more, refer to the Configure SCIM for the Lucid Suite in Entra ID section below.

To configure the SAML integration for Lucid via Azure Portal, follow these steps:

In Azure:

  1. Select Entra ID from the navigation menu on the left-hand side of the Azure home page.
  2. Select Enterprise Applications from the navigation menu on the left-hand side.
  3. Open the Lucid (All Products) app and rename it to "Lucid for admin management".
  4. In the app, navigate to ”Set up Single Sign-on" .
  5. Under Single Sign-on Mode, select SAML.
  6. Select Edit on your Basic SAML Configuration. 
  7. Change the Entity ID to "lucidchart.com".
    • The default is “lucid.app”, which won’t work.
  8. If you are on a commercial environment, update the Reply URLs and Sign on URL to match the following: 
    • Default Reply URL link: https://lucid.app/saml/sso/<yourdomainnamehere>
    • Secondary Reply URL link: https://www.lucidchart.com/saml/sso/<yourdomainnamehere>
    • Sign on URL link: https://lucid.app/saml/sso/<yourdomainnamehere> 
      basic-saml-configuration-in-azure.png
  9. If you are in the FedRAMP environment, refer to the FedRAMP overview article for your Sign on URL and the Default Reply URL you should use.
  10. Click Save.
  11. Confirm that the User Identifier is “user.userprincipalname”. 
    • All basic attributes and claims should be set up already by default.
  12. Click Save.
  13. Under “Federation Metadata XML” select Download to retrieve the IdP metadata. 
    • Do not open the XML file (metadata). You will upload the saved file into Lucid.

Note: If you have multiple domain names, we recommend choosing the domain that is most recognizable to your users. Then, make sure that the domain you choose to use for your Reply URLs and Sign on URL in steps 7 and 8 above matches what you set as the “Lucidchart Sign in URL” in step 4 of the following instructions.

In Lucid:

  1. Select Admin.
  2. Click Security in the left-hand menu.
  3. From the dropdown options, click Authentication.
  4. Select Configure to the right of the “Allow SAML authentication” option to navigate to your SAML Activation page in Lucid.

    • You will not be able to enable SAML until you have populated your domain and uploaded metadata.

      configure-saml-in-lucid.png
  5. Under “Lucidchart Sign in URL”, enter your Domain name.
    saml-activation-in-lucid.png
  6. Click Save Changes.
  7. Scroll down on the SAML Activation page of Lucidchart and click Add Identity Provider.
  8. Upload the XML file (metadata) that you downloaded from Entra ID.
    • If you already have IdP metadata from Entra ID that was previously uploaded into Lucid and need to update it, follow the instructions in our SAML overview article.
  9. Click Test SAML connection to verify that Lucid is properly communicating with Microsoft Entra ID.
    • The connection will only work if the Lucid  for admin management app has been assigned to your test user in Entra ID. You can assign the app to users in the Assignments section of the app page. To do so, navigate to “Users and Groups” on the left hand side and click Assign
  10. Navigate back to the Security page. 
  11. Check the box next to “Allow SAML authentication”.
  12. Click Save changes.
    check-saml-authentication-box-in-lucid-and-save.png

After enabling SAML in Lucid, a account admin will need to provide a one-time authorization within the Microsoft Entra ID console to finalize the connection. Until this is granted, users attempting to log in may be prompted to contact their administrator.

You have the option to use encrypted assertions for the identity providers you add for SAML to your Lucid account. To learn more, refer to our SAML overview article.

Note: You can select the Default Authentication method in Lucid, after you have checked the methods that you would like to allow as sign in options above. Users will be prompted to sign in using the default authentication you set up in the Security page.

Create users upon login with SAML

Once you have configured SAML with Microsoft Entra ID for your Lucid account, you can set up Just-In-Time provisioning so that users assigned Lucid access in Entra ID who do not have a Lucid account will have an account created for them upon their first log-in.

Note: For JIT provisioning to work as intended, you should have domain control enabled and have the user verification method set to SAML.

To enable new user creation for users assigned to the application:

  1. Navigate to the “Properties” tab in your Lucid  for admin management application page within Entra ID.
  2. Scroll to the bottom of the page and toggle the “User Assignment Required?” to ”No”. 
  3. Click Save.
  4. Select Users and groups from the Manage menu. 
  5. Select and assign users and/or groups to access the Lucid  for admin management application.

You can then customize Just-In-Time provisioning in the License settings section of your Lucid admin panel, depending on the access you want users to have. Here are the options:

  • If you would like all users to come onto your Lucidchart account with full-edit licenses, choose the following settings:
    • Under the “Access eligibility” section, select Eligible for full access.
    • Under “Customized eligibility criteria”, select Instant access.
  • If you want all users to come in as limited-access users, under the “Access eligibility” section select Only eligible for limited access.
    • Your users will still be able to request full-edit licenses. Depending on the “When a user requests a license” setting, you can have licenses be automatically granted to users upon their request, or you can have the requests turn into pending requests in your user list.

Configure SCIM for the Lucid Suite in Entra ID

You can use SCIM to create Lucid users before their first login and use Lucid organizational groups to assign them a Lucid Suite license. To provision users and groups, follow the steps below in the Lucid for admin management app you created. If you haven’t set up the Lucid for admin management app in Entra ID, you can see the steps in the section above.

Note: The instructions in this section for setting up a SCIM app are relevant if you are setting up SCIM for the first time for your Lucid Enterprise account. If you were already using SCIM prior to October 22nd, 2024, you need to migrate to the new organizational groups experience. See our Microsoft Entra ID migration article for instructions.

Before configuring SCIM, complete the following in your Lucid account:

  • Confirm that you are on an Enterprise account with an up-to-date pricing plan. To upgrade, contact sales.
  • Make sure that auto-upgrade is enabled in your Licensing settings. This can be done only by account owners or admins with both the billing admin and account admin roles. 
    • You will be unable to generate bearer tokens to configure SCIM if this setting is not enabled. You may want to turn off auto-upgrade after generating bearer tokens to prevent unwanted licensing during the configuration process.

Once you have followed the pre-configuration steps listed above, you can configure both SCIM for admin management and SCIM for content access for the Lucid Suite in Entra ID by generating separate bearer tokens in Lucid and then using them in Entra ID To learn more about the differences and value of each app, refer to our SCIM overview for Lucid article.

Obtain bearer tokens and configure SCIM settings in Lucid

Before enabling SCIM provisioning in Entra ID, you need to obtain bearer tokens from Lucid. To do this:

  1. Sign in to Lucid as an account owner or account admin.
  2. Select Admin from the menu to the left.
  3. Click App Integration from the left-hand navigation menu.
  4. On the relevant SCIM tile, select Settings (or Install).
    • To set up both apps, you will need to separately follow the remaining steps for SCIM for admin management and SCIM for content access. You will generate a separate bearer token for each app.
  5. Click Enable SCIM.
  6. Click Save.
  7. Click Generate Token.
    • If Generate Token is not clickable, ensure the “Automatically upgrade account when no more licenses are available” option is checked in your License settings and try again.
  8. Copy the bearer token.
  9. Under “Exclude groups from your identity provider”, click Edit to the far-right.
  10. Type in the name of the “All Users Group” from Entra ID and any other groups you wish to exclude.
    • Your “All Users Group” will most likely be named something different and it must be an exact name match (case isn’t sensitive) with the name of your Microsoft Entra ID group.
  11. Click Save.

Note: The exclude groups setting, covered in steps 10-11 above, allows you to exclude specific identity provider groups via SCIM for admin management sync without having to change your IDP while also ensuring that users will be assigned to their specific licensing group in Lucid, instead of the broader group.

Configure integration(s) and use bearer token(s) in Entra ID

Depending on whether you are looking to use SCIM for admin management, SCIM for content access, or both, the steps here will slightly differ.

Configuration for SCIM for admin management

To enable SCIM for admin management provisioning in Microsoft Entra ID, follow these steps:

  1. Open the Lucid for admin management app.
  2. Select Provisioning from the navigation menu on the left-hand side.
  3. Click Get started.
  4. From the “Provisioning Mode” dropdown, select Automatic.
  5. Under “Admin Credentials”, enter https://users.lucid.app/scim/v2/azure under “Tenant URL”.
  6. Enter the bearer token generated by Lucid from the SCIM for admin management under “Secret Token”.
  7. Click Test Connection.
    test-token-connection-in-azure.png
  8. If the connection is successful, click Save.

Configuration for SCIM for content access

  1. Log into Entra ID as an admin.
  2. Select Entra ID from the navigation menu on the left-hand side of the Azure home page.
  3. Select Enterprise Applications from the navigation menu on the left-hand side.
  4. Create a new app from the Lucid (All Products) app and rename it to "Lucid for content access".
    • This will allow you to differentiate this Lucid app in Entra ID from the Lucid SCIM for admin management app that you may be using from the instructions above.
  5. Select Provisioning from the navigation menu on the left-hand side.
  6. Click Get started.
  7. From the “Provisioning Mode” dropdown, select Automatic.
  8. Under “Admin Credentials”, enter https://users.lucid.app/scim/v2/azure under “Tenant URL”.
  9. Enter the bearer token under “Secret Token” using the token you obtained from the Lucid for content access tile in the steps above.
  10. Click Test Connection.
    test-token-connection-in-azure.png
  11. If the connection is successful, click Save.

Set up SCIM for admin management

The groups that you set up for SCIM for admin management will be used to manage licensing and granular admin controls at scale, including attribute management (e.g. cost center, region, etc). These groups can also be used to automatically provision users and Lucid org groups to reflect company hierarchy.

Create user groups

Create new or additional groups by following these steps:

  1. Select Entra ID from the navigation menu on the left-hand side of the Azure home page.
  2. Select Groups from the left-hand menu.
  3. Follow the steps below to create licensing user groups.

Create licensing groups

  1. Click New Group.
  2. Update the following settings:
    • Group name: [input desired name here]
    • Optionally, you can enter a group description.
  3. Click Create.
  4. Repeat these steps for as many licensing groups as you want.

Assign groups to the Lucid for admin management app

Now, you can assign the user groups that you created in the previous section to the Lucid fior admin management app by following these steps:

  1. Navigate to the Lucid for admin management app in Entra ID.
  2. Click Users and Groups.
  3. Follow the remaining instructions in this section to assign both groups appropriately.

Assign your “All Users” group

This should be the group to which all current and new users at your company are automatically added. This allows all assigned users to sign into the Lucid application, assuming SAML has been configured, and it is used to provision all users in this group into your default Lucid organizational group.

Note: There is no limit on the number of users you can have in this group within Lucid because they are provisioned as limited-access users by default. Users can have membership in this group until they leave the company.

To set up this “All Users” group, follow these steps:

  1. Click Add user/group.
  2. Under “Users and groups”, click None Selected.
  3. Search for your “All User” group in Entra ID. 
    • For our example, we will use the name “All Users” but yours will likely be called something different.
  4. Select the group.
  5. Click Select.
  6. Click Assign.
    all-users-group-set-up-in-azure.png

Assign the "Licensed User" group(s)

These groups will be used to assign a user a license in Lucid based on their membership to the group.

Note: You can have multiple different groups used to license users but users can only belong to one license group at a time across all groups. The only exception to this rule is the “All Users” group. Removing a user from a license group will delicense the user, which allows you to free up licenses for others to use.

To set up this “Licensed User” group, follow these steps:

  1. Click Add user/group.
  2. Under “Users and groups”, click None Selected.
  3. Search for your desired license group.
  4. Select the group.
  5. Click Select.
    add-licensed-user-group-assignment-in-azure.png
  6. Click Assign in the bottom-left corner of the page.

Test provisioning

After all the settings detailed above are saved, test the application to ensure it is functioning properly. To do this:

  1. Assign a test user to one of your licensing groups.
  2. Open the Lucid for admin management app.
  3. Select Provisioning from the navigation menu on the left-hand side.
  4. Click Provision on demand from the menu across the top of the page.
  5. Enter the name of the test user you assigned to the licensing group.
  6. Click Provision.

provision-on-demand-tab-in-azure.png

If everything is working as intended, you will see green checkmarks next to all steps. You will also see that the modified attributes were successful in pulling over values like username, email, etc.

provision-on-demand-test-for-azure-scim.png

If you don’t see the checkmark icons, review the configuration steps above. If the user was provisioned successfully in your test, proceed to the next section.

Turn provisioning on in Microsoft Entra ID

Now that you have completed the SCIM configuration steps and successfully ran a provisioning test, you can enable provisioning. To do so:

  1. Navigate back to the Lucid for admin management app in Entra ID.
  2. Open the “Provisioning” page.
  3. Click Start provisioning.
  4. Wait while Entra ID provisions your users, groups, and memberships into Lucid.
    • Once the “Current cycle status” shows as 100% complete, move on to the next section.

View Microsoft Entra ID groups as organizational groups in Lucid

Double-check that you see the expected Microsoft Entra ID for admin management groups as organizational groups in Lucid—this confirms the migration was successful. To access the organizational groups page in Lucid, follow these steps:

  1. Navigate back to the Lucid admin panel.
  2. Select Groups from the left-hand navigation menu.
  3. From the dropdown menu, click Organizational groups.

If the Entra ID provisioning has finished, as we recommend ensuring before you move onto this section, you should now see your Microsoft Entra ID groups from the Lucid SCIM for admin management app as organizational groups on this page of the Lucid admin panel.

lucid-suite-scim-user-groups-visible-as-organizational-groups-in-lucid.png

Note: If you successfully followed the steps to exclude the All Users group (and any other applicable groups) in Entra ID from organizational groups, you won't see that group in the Lucid admin panel. Any users that aren’t added to one of the organizational groups you created to license users will instead be added to the “Default organizational group” automatically.

Configure license settings for each group

You’re now at the stage in the process where you can configure the license settings for each of your organizational groups. This ensures users are licensed or delicensed as intended when they are added to or removed from any of these groups. To access license settings, follow these steps:

  1. Navigate to the Lucid admin panel.
  2. Select License settings from the left-hand navigation menu.
  3. From the dropdown menu, click Lucid Suite settings.
  4. Proceed to the appropriate set of steps below to customize license settings for each organizational group.

lucid-suite-license-settings-for-licensed-users.png

License setting set up for licensed users group:

  1. Select your desired licensing group from the list of organizational groups on the left-hand side of the licensing page.
  2. Under the “Access eligibility” section, select Eligible for full access.
  3. Under “Customized eligibility criteria”, select Instant access.
  4. Click Save changes.
  5. Repeat these steps for any additional licensing groups.

Note: These settings make it so any users added to this group via SCIM automatically receive a Lucid Suite license.

You have now completed all the steps to successfully configure the Lucid for admin management app. License settings will now be managed via the organizational groups created via SCIM.

Set up SCIM for content access

SCIM for content access is ideal for managing collaboration, document sharing, and access to Lucid products. It allows you to provision and deprovisions users and teams directly from your identity provider, but doesn’t manage licensing. To begin set up of a SCIM for content access app in Entra ID, follow the steps from the Configure SCIM for the Lucid Suite in Entra ID section, then return here to continue with the steps to customize your user groups.

We recommend creating these groups for sharing by department, location, etc. depending on your account needs.

Note: SCIM for content access is currently unavailable for accounts with legacy groups (sharing). To learn more about if that applies to your account, refer to our Lucid admin panel: Groups management article.

Add users to push groups in Entra ID

User groups in Entra ID allows admins to push groups from Entra ID to Lucid and manage Lucid groups for sharing through Entra ID.

To create new push groups for content access, follow these steps:

  1. Navigate to the Lucid for admin management app in Entra ID.
  2. Click Users and Groups.
  3. Click Add user/group.
  4. Under “Users and groups”, click None Selected.
  5. Search for for relevant Entra ID user groups that you want to push to Lucid.
    • Add and customize the groups that you want for document sharing, which may look like groups by department, location, etc.
    • Alternatively, you can also use your “All users” group that you may be using for the SCIM for admin management app. 
  6. Select the group.
  7. Click Select.
  8. Click Assign.
  9. Follow these steps to add any additional user groups that you'd like.

Access teams from Lucid admin panel

The groups that you create will be visible in the Lucid admin panel by following these steps:

  1. Navigate to the Lucid admin panel.
  2. Select Groups from the left-hand navigation menu.
  3. From the dropdown menu, click Teams.

FAQ

What is the difference between Microsoft SSO and Microsoft Entra ID SAML Sign-On?
Microsoft SSO and Entra ID SAML Sign-On are both managed from the Azure portal. SAML uses SAML2.0 protocol while MS SSO uses OAuth2.0 OpenID. Generally, SAML set-ups are considered more secure because the encryption is on the transport layer (SSL).

What happens to documents when I delicense a user via SCIM?
When you delicense a user via SCIM, you must transfer their documents to another user on your Enterprise account. The document transfer will occur 24 hours after delicensing via SCIM.

By default, the account owner will be the recipient of the documents that are automatically transferred upon delicensing a user. You can change the recipient of the transferred documents by navigating to the SCIM integration settings in the Admin Panel and selecting Modify default owner to the right-hand side of the email address. See the screenshot below for reference.

Clicking Modify default owner redirects you to the “Compliance settings” page of the Lucid admin panel where you can change the default document owner on your account. Refer to Lucid admin panel: Compliance settings article for additional details.
change-recipient-of-documents-when-deleting-or-delicensing-users-via-SCIM.png

When will users added via SCIM receive welcome emails from Lucid?
Once a user has been added to a Lucid app in Entra ID, they will receive a welcome email from Lucid.

Is a pre-configured SCIM app available for Lucid GovSuite (FedRAMP)?
Microsoft Entra ID Government integration is not currently supported. Lucid is in the process of working with Microsoft to bring a pre-configured SCIM application to FedRAMP environments.

Give feedback on this article

Have feedback about this article? Tell us about your experience here

Did you find what you were looking for?

Still have a question or want to share what you have learned? Visit our Community   to get help and collaborate with others.