We successfully implemented automated user provisioning for our supplier collaboration portal using Azure AD SCIM integration with Aras Innovator 12.0. Previously, onboarding new supplier users was a manual 2-3 day process involving IT tickets, manual identity creation, and role assignments.
Our solution integrates Azure AD as the identity provider with SCIM 2.0 protocol for automatic user lifecycle management. When suppliers are added to our Azure AD supplier group, their accounts are automatically provisioned in Aras with appropriate roles. We configured SSO using SAML 2.0 so suppliers authenticate once through Azure AD and access Aras seamlessly.
The automated role assignment logic maps Azure AD group memberships to Aras identities - supplier engineers get read-only CAD access, supplier managers get approval rights for ECOs. Onboarding time dropped from 2-3 days to under 15 minutes. We’re now managing 200+ supplier users with zero manual intervention.
This is impressive work. How did you handle the SCIM endpoint configuration in Aras 12.0? I know newer versions have better SCIM support, but 12.0 requires custom implementation. Did you build a middleware service or extend Aras directly?
How are you handling SSO session management and token refresh? We implemented Azure AD SSO but faced issues with session timeouts causing users to re-authenticate frequently during long work sessions.
Great use case for supplier management. The automated role assignment based on Azure AD groups is particularly interesting. Can you share more details about how you mapped the group memberships to Aras identities and permissions? We’re struggling with maintaining consistent access controls across our supplier base and this approach could solve that. Also curious about how you handle role changes when suppliers move between projects or their responsibilities change.
This addresses a major pain point we have. Currently managing 150 supplier accounts manually and it’s becoming unsustainable. Quick question about deprovisioning - when a supplier contract ends or user leaves their company, does the Azure AD deletion automatically deactivate their Aras account? We need audit trails showing exactly when access was revoked for compliance reasons.
Did you encounter any challenges with Azure AD SCIM rate limits? We’re planning a similar implementation for our partner ecosystem and worried about provisioning delays during bulk onboarding scenarios. Also interested in your disaster recovery approach - if Azure AD is down, can suppliers still access Aras or do you have a fallback authentication method?