SSO and automatic provisioning between Entra ID and GitLab
Context
A team answered an IAM/PAM specification for a MedTech SME: risk analysis, a comparison of Entra ID, Okta, BeyondTrust and CyberArk, and an access policy aligned with ISO 27002 (controls 8.2 and 8.4), HDS health-data rules and GDPR.
What I did
- Set up SAML 2.0 federation with Entra ID as identity provider (IdP) and GitLab as service provider (SP).
- Set up SCIM provisioning: accounts are created, updated and deactivated automatically (joiner-mover-leaver lifecycle).
- Designed governance for AI-agent identities: non-human accounts, ABAC with dynamic groups, blocking of legacy authentication.
Note: PAM was covered through the access policy and the vendor comparison, not through a deployment.
See the project card- The user opens GitLab (SP)
- GitLab redirects to Entra ID (IdP)
- Entra ID authenticates and sends a SAML assertion
- GitLab opens the session
- Joiner: the account is created in GitLab
- Mover: attributes and groups are updated
- Leaver: the account is deactivated
- Governance of technical accounts
- ABAC with dynamic groups
- Legacy authentication blocked