When you need this
SCIM provisioning only pushes groups that are directly assigned to the Brellium SCIM enterprise application. Microsoft Entra ID does not send any other groups, even if provisioned users are members of them.What Brellium can access
Prerequisites
- The Global Administrator or Privileged Role Administrator role. You need one of these roles to grant admin consent for Microsoft Graph application permissions.
- SCIM provisioning configured for Brellium (see the SCIM Provisioning Configuration guide)
- A Brellium account with the can edit org settings permission, with SSO and SCIM turned on for your organization (see Access the Brellium setup portal)
- The client ID of your Brellium SSO application. In Brellium, go to Control Center > Settings. The Client ID under Single sign-on is the Application (client) ID of the app registration in Entra ID.
Access the Brellium setup portal
IT administrators can open the SSO and SCIM setup portal on their own. In Brellium, go to Control Center > Settings. The Single sign-on and Directory sync (SCIM) sections each have an Edit configuration button. Each button opens the setup portal for that connection in a new tab, so you can configure and change settings without a support ticket.
Brellium Control Center > Settings — the Single sign-on and Directory sync (SCIM) sections
- SSO and SCIM are turned on for your organization. If you do not see the Single sign-on and Directory sync (SCIM) sections on the settings page, contact your customer success manager to turn on the feature for your organization. You can open the SSO and SCIM configuration only after the feature is on.
- You have the can edit org settings permission. Your Brellium account must have the can edit org settings permission under Settings. If you do not have it, ask a Brellium administrator in your organization to give it to you.

The can edit org settings permission under Settings
Configuration steps
Find the SSO app registration
- Open the Microsoft Entra admin center.
- Go to Entra ID > App registrations and stay on the All applications tab.
- Search for your Brellium SSO application by name (for example,
BRELLIUM SSO) or by the client ID from Brellium, and select it.

App registrations — search for the Brellium SSO application
Open API permissions
- Go to Manage > API permissions.
- Check the current list under Microsoft Graph. The SSO application already has delegated permissions such as
Directory.Read.All,Group.Read.All,openid, andUser.Read, all Granted for your organization. Do not change them. Sign-in uses them. - Click Add a permission.

API permissions — the existing delegated permissions on the SSO application
Choose Microsoft Graph

Request API permissions — select Microsoft Graph
Choose application permissions

Select Application permissions
Select the two permissions

The Select permissions list
- Type
Groupin the filter box. - Under Group, select
Group.ReadBasic.All(“Read all groups’ basic property”). - Under GroupMember, select
GroupMember.ReadBasic.All(“Read all group memberships”). - Click Add permissions.

Group.ReadBasic.All and GroupMember.ReadBasic.All selected
Grant admin consent
- Wait for the message Successfully saved permissions at the top right.
- Check that the list now shows
Group.ReadBasic.AllandGroupMember.ReadBasic.Allwith type Application and status Not granted for your organization. - Click Grant admin consent for your organization, then click Yes.

The new application permissions before admin consent
Verify that consent was granted
- Wait for the message Grant consent successful. The banner changes to Successfully granted admin consent for the requested permissions.
- Check that all permissions, including the two new Application rows, show Granted for your organization.

All permissions granted
Tell Brellium
Remove access
To remove Brellium’s access to group memberships:- Open API permissions on the same app registration.
- On each of the two Application rows, click … and select Remove permission.
Troubleshoot
Support
If you have questions or encounter issues not covered in this guide, contact the Brellium support team:- Email: sso.support@brellium.com