Buckets:

HuggingFaceDocBuilder's picture
download
raw
17.9 kB
import{s as me,n as fe,o as he}from"../chunks/scheduler.409792a1.js";import{S as ve,i as Me,e as r,s,c as u,h as $e,a as l,d as i,b as o,f as de,g as c,j as a,l as g,m as be,n,o as p,p as d,q as m,r as f}from"../chunks/index.92d389ff.js";import{C as Ce}from"../chunks/CopyLLMTxtMenu.82b2a8a7.js";import{H as v,E as ye}from"../chunks/MermaidChart.svelte_svelte_type_style_lang.6276245c.js";function Te(zt){let h,it,tt,nt,w,st,I,ot,x,Rt="This guide explains how to set up automatic user and group provisioning between Microsoft Entra ID and your Hugging Face organization using SCIM.",rt,M,jt='<p>This feature is part of the <a href="https://huggingface.co/enterprise">Enterprise</a> and <a href="https://huggingface.co/contact/sales?from=enterprise" target="_blank">Enterprise Plus</a> plans.</p>',lt,P,at,_,Nt="<li>Navigate to your organization’s settings page on Hugging Face.</li> <li>Go to the <strong>SSO</strong> tab, then click on the <strong>SCIM</strong> sub-tab.</li> <li>Copy the <strong>SCIM Tenant URL</strong>. You will need this for the Entra ID configuration.</li> <li>Click <strong>Generate an access token</strong>. A new SCIM token will be generated. Copy this token immediately and store it securely, as you will not be able to see it again.</li>",gt,$,Bt='<img class="block dark:hidden" src="https://huggingface.co/datasets/huggingface/documentation-images/resolve/main/hub/sso/scim-settings.png"/> <img class="hidden dark:block" src="https://huggingface.co/datasets/huggingface/documentation-images/resolve/main/hub/sso/scim-settings-dark.png"/>',ut,q,ct,E,Vt="<li>In the Microsoft Entra admin center, navigate to your Hugging Face Enterprise Application.</li> <li>In the left-hand menu, select <strong>Provisioning</strong>.</li> <li>Click <strong>Get started</strong>.</li> <li>Change the <strong>Provisioning Mode</strong> from “Manual” to <strong>Automatic</strong>.</li>",pt,A,dt,O,Yt="<li>In the <strong>Admin Credentials</strong> section, paste the <strong>SCIM Tenant URL</strong> from Hugging Face into the <strong>Tenant URL</strong> field.</li> <li>Paste the <strong>SCIM token</strong> from Hugging Face into the <strong>Secret Token</strong> field.</li> <li>Click <strong>Test Connection</strong>. You should see a success notification.</li> <li>Click <strong>Save</strong>.</li>",mt,b,Kt='<img class="block dark:hidden" src="https://huggingface.co/datasets/huggingface/documentation-images/resolve/main/hub/sso/scim-entra-creds.png" alt="Entra ID SCIM Admin Credentials"/> <img class="hidden dark:block" src="https://huggingface.co/datasets/huggingface/documentation-images/resolve/main/hub/sso/scim-entra-creds-dark.png" alt="Entra ID SCIM Admin Credentials"/>',ft,D,ht,G,Qt="<li><p>Under the <strong>Mappings</strong> section, click on <strong>Provision Microsoft Entra ID Users</strong>.</p></li> <li><p>The default attribute mappings often require adjustments for robust provisioning. We recommend using the following configuration. You can delete attributes that are not listed here:</p> <table><thead><tr><th><code>customappsso</code> Attribute</th> <th>Microsoft Entra ID Attribute</th> <th>Matching precedence</th></tr></thead> <tbody><tr><td><code>userName</code></td> <td><code>Replace([mailNickname], &quot;.&quot;, &quot;&quot;, &quot;&quot;, &quot;&quot;, &quot;&quot;, &quot;&quot;)</code></td> <td></td></tr> <tr><td><code>active</code></td> <td><code>Switch([IsSoftDeleted], , &quot;False&quot;, &quot;True&quot;, &quot;True&quot;, &quot;False&quot;)</code></td> <td></td></tr> <tr><td><code>emails[type eq &quot;work&quot;].value</code></td> <td><code>userPrincipalName</code></td> <td></td></tr> <tr><td><code>name.givenName</code></td> <td><code>givenName</code></td> <td></td></tr> <tr><td><code>name.familyName</code></td> <td><code>surname</code></td> <td></td></tr> <tr><td><code>externalId</code></td> <td><code>objectId</code></td> <td><code>1</code></td></tr></tbody></table></li> <li><p>The Username needs to comply with the following rules.</p></li>",vt,C,Wt="<ul><li>Only regular characters and `-` are accepted in the Username.</li> <li>`--` (double dash) is forbidden.</li> <li>`-` cannot start or end the name.</li> <li>Digit-only names are not accepted.</li> <li>Minimum length is 2 and maximum length is 42.</li> <li>Username has to be unique within your org.</li></ul>",Mt,y,Jt="<li>After configuring the user mappings, go back to the Provisioning screen and click on <strong>Provision Microsoft Entra ID Groups</strong> to review group mappings. The default settings for groups are usually sufficient.</li>",$t,F,bt,U,Xt="<li>On the main Provisioning screen, set the <strong>Provisioning Status</strong> to <strong>On</strong>.</li> <li>Under <strong>Settings</strong>, you can configure the <strong>Scope</strong> to either “Sync only assigned users and groups” or “Sync all users and groups”. We recommend starting with “Sync only assigned users and groups”.</li> <li>Save your changes.</li>",Ct,z,Zt="The initial synchronization can take up to 40 minutes to start. You can monitor the progress in the <strong>Provisioning logs</strong> tab.",yt,R,Tt,j,te="To control which users and groups are provisioned to your Hugging Face organization, you need to assign them to the Hugging Face Enterprise Application in Microsoft Entra ID. This is done in the <strong>Users and groups</strong> tab of your application.",Lt,N,ee="<li>Navigate to your Hugging Face Enterprise Application in the Microsoft Entra admin center.</li> <li>Go to the <strong>Users and groups</strong> tab.</li> <li>Click <strong>Add user/group</strong>.</li> <li>Select the users and groups you want to provision and click <strong>Assign</strong>.</li>",kt,T,ie='<img class="block dark:hidden" src="https://huggingface.co/datasets/huggingface/documentation-images/resolve/main/hub/sso/scim-entra-users-groups.png" alt="Entra ID SCIM User and Group Assignment"/> <img class="hidden dark:block" src="https://huggingface.co/datasets/huggingface/documentation-images/resolve/main/hub/sso/scim-entra-users-groups-dark.png" alt="Entra ID SCIM User and Group Assignment"/>',Ht,B,ne="Only the users and groups you assign here will be provisioned to Hugging Face if you have set the <strong>Scope</strong> to “Sync only assigned users and groups”.",St,L,se="<p><strong>Active Directory Plan Considerations</strong></p> <ul><li>With <strong>Free, Office 365, and Premium P1/P2 plans</strong>, you can assign individual users to the application for provisioning.</li> <li>With <strong>Premium P1/P2 plans</strong>, you can also assign groups. This is the recommended approach for managing access at scale, as you can manage group membership in AD, and the changes will automatically be reflected in Hugging Face.</li></ul>",wt,V,It,Y,oe="Once the synchronization is complete, navigate back to your Hugging Face organization settings:",xt,K,re='<li>Provisioned users will appear in the <strong>Users Management</strong> tab.</li> <li>Provisioned groups will appear in the <strong>SCIM</strong> tab under <strong>SCIM Groups</strong>. These groups can then be assigned to <a href="./security-resource-groups">Resource Groups</a> for fine-grained access control.</li>',Pt,Q,_t,W,le="Once your groups are provisioned from Entra ID, you can link them to Hugging Face Resource Groups to manage permissions at scale. This allows all members of a SCIM group to automatically receive specific roles (like read or write) for a collection of resources.",qt,k,ae="<p>Before linking, make sure the Resource Group you want to link is <strong>empty</strong> (has no existing members) and does <strong>not</strong> have auto-join enabled. Both conditions are required — linking will fail otherwise.</p>",Et,J,ge="<li>In your Hugging Face organization settings, navigate to the <strong>SSO</strong> -&gt; <strong>SCIM</strong> tab. You will see a list of your provisioned groups under <strong>SCIM Groups</strong>.</li>",At,H,ue='<img class="block dark:hidden" src="https://huggingface.co/datasets/huggingface/documentation-images/resolve/main/hub/sso/scim-provisioned-group.png" alt="Link SCIM group to a resource group"/> <img class="hidden dark:block" src="https://huggingface.co/datasets/huggingface/documentation-images/resolve/main/hub/sso/scim-provisioned-group-dark.png" alt="Link SCIM group to a resource group"/>',Ot,S,ce="<li>Locate the group you wish to configure and click <strong>Link resource groups</strong> in its row.</li> <li>A dialog will appear. Click <strong>Link a Resource Group</strong>.</li> <li>From the dropdown menus, select the <strong>Resource Group</strong> you want to link and the <strong>Role Assignment</strong> you want to grant to the members of the SCIM group.</li> <li>Click <strong>Link to SCIM group</strong> and save the mapping.</li>",Dt,X,pe="Once linked, the Resource Group becomes <strong>SCIM-managed</strong>: any members already in the SCIM group are immediately added to the Resource Group (backfill), and all future membership changes in Entra ID are automatically reflected. Manual membership edits on the Resource Group via the Hub UI or API will be blocked.",Gt,Z,Ft,et,Ut;return w=new Ce({props:{containerStyle:"float: right; margin-left: 10px; display: inline-flex; position: relative; z-index: 10;"}}),I=new v({props:{title:"How to configure SCIM with Microsoft Entra ID (Azure AD)",local:"how-to-configure-scim-with-microsoft-entra-id-azure-ad",headingTag:"h1"}}),P=new v({props:{title:"Step 1: Get SCIM configuration from Hugging Face",local:"step-1-get-scim-configuration-from-hugging-face",headingTag:"h2"}}),q=new v({props:{title:"Step 2: Configure Provisioning in Microsoft Entra ID",local:"step-2-configure-provisioning-in-microsoft-entra-id",headingTag:"h2"}}),A=new v({props:{title:"Step 3: Enter Admin Credentials",local:"step-3-enter-admin-credentials",headingTag:"h2"}}),D=new v({props:{title:"Step 4: Configure Attribute Mappings",local:"step-4-configure-attribute-mappings",headingTag:"h2"}}),F=new v({props:{title:"Step 5: Start Provisioning",local:"step-5-start-provisioning",headingTag:"h2"}}),R=new v({props:{title:"Assigning Users and Groups for Provisioning",local:"assigning-users-and-groups-for-provisioning",headingTag:"h3"}}),V=new v({props:{title:"Step 6: Verify Provisioning in Hugging Face",local:"step-6-verify-provisioning-in-hugging-face",headingTag:"h2"}}),Q=new v({props:{title:"Step 7: Link SCIM Groups to Hugging Face Resource Groups",local:"step-7-link-scim-groups-to-hugging-face-resource-groups",headingTag:"h2"}}),Z=new ye({props:{source:"https://github.com/huggingface/hub-docs/blob/main/docs/hub/security-sso-entra-id-scim.md"}}),{c(){h=r("meta"),it=s(),tt=r("p"),nt=s(),u(w.$$.fragment),st=s(),u(I.$$.fragment),ot=s(),x=r("p"),x.textContent=Rt,rt=s(),M=r("blockquote"),M.innerHTML=jt,lt=s(),u(P.$$.fragment),at=s(),_=r("ol"),_.innerHTML=Nt,gt=s(),$=r("div"),$.innerHTML=Bt,ut=s(),u(q.$$.fragment),ct=s(),E=r("ol"),E.innerHTML=Vt,pt=s(),u(A.$$.fragment),dt=s(),O=r("ol"),O.innerHTML=Yt,mt=s(),b=r("div"),b.innerHTML=Kt,ft=s(),u(D.$$.fragment),ht=s(),G=r("ol"),G.innerHTML=Qt,vt=s(),C=r("blockquote"),C.innerHTML=Wt,Mt=s(),y=r("ol"),y.innerHTML=Jt,$t=s(),u(F.$$.fragment),bt=s(),U=r("ol"),U.innerHTML=Xt,Ct=s(),z=r("p"),z.innerHTML=Zt,yt=s(),u(R.$$.fragment),Tt=s(),j=r("p"),j.innerHTML=te,Lt=s(),N=r("ol"),N.innerHTML=ee,kt=s(),T=r("div"),T.innerHTML=ie,Ht=s(),B=r("p"),B.innerHTML=ne,St=s(),L=r("blockquote"),L.innerHTML=se,wt=s(),u(V.$$.fragment),It=s(),Y=r("p"),Y.textContent=oe,xt=s(),K=r("ul"),K.innerHTML=re,Pt=s(),u(Q.$$.fragment),_t=s(),W=r("p"),W.textContent=le,qt=s(),k=r("blockquote"),k.innerHTML=ae,Et=s(),J=r("ol"),J.innerHTML=ge,At=s(),H=r("div"),H.innerHTML=ue,Ot=s(),S=r("ol"),S.innerHTML=ce,Dt=s(),X=r("p"),X.innerHTML=pe,Gt=s(),u(Z.$$.fragment),Ft=s(),et=r("p"),this.h()},l(t){const e=$e("svelte-u9bgzb",document.head);h=l(e,"META",{name:!0,content:!0}),e.forEach(i),it=o(t),tt=l(t,"P",{}),de(tt).forEach(i),nt=o(t),c(w.$$.fragment,t),st=o(t),c(I.$$.fragment,t),ot=o(t),x=l(t,"P",{"data-svelte-h":!0}),a(x)!=="svelte-1pgpjv7"&&(x.textContent=Rt),rt=o(t),M=l(t,"BLOCKQUOTE",{class:!0,"data-svelte-h":!0}),a(M)!=="svelte-jxebfy"&&(M.innerHTML=jt),lt=o(t),c(P.$$.fragment,t),at=o(t),_=l(t,"OL",{"data-svelte-h":!0}),a(_)!=="svelte-vp67rt"&&(_.innerHTML=Nt),gt=o(t),$=l(t,"DIV",{class:!0,"data-svelte-h":!0}),a($)!=="svelte-lg246v"&&($.innerHTML=Bt),ut=o(t),c(q.$$.fragment,t),ct=o(t),E=l(t,"OL",{"data-svelte-h":!0}),a(E)!=="svelte-1x5d6yu"&&(E.innerHTML=Vt),pt=o(t),c(A.$$.fragment,t),dt=o(t),O=l(t,"OL",{"data-svelte-h":!0}),a(O)!=="svelte-2czyo"&&(O.innerHTML=Yt),mt=o(t),b=l(t,"DIV",{class:!0,"data-svelte-h":!0}),a(b)!=="svelte-87qlw7"&&(b.innerHTML=Kt),ft=o(t),c(D.$$.fragment,t),ht=o(t),G=l(t,"OL",{"data-svelte-h":!0}),a(G)!=="svelte-z276xl"&&(G.innerHTML=Qt),vt=o(t),C=l(t,"BLOCKQUOTE",{class:!0,"data-svelte-h":!0}),a(C)!=="svelte-vzvwsc"&&(C.innerHTML=Wt),Mt=o(t),y=l(t,"OL",{start:!0,"data-svelte-h":!0}),a(y)!=="svelte-1uv9nlb"&&(y.innerHTML=Jt),$t=o(t),c(F.$$.fragment,t),bt=o(t),U=l(t,"OL",{"data-svelte-h":!0}),a(U)!=="svelte-19z0kne"&&(U.innerHTML=Xt),Ct=o(t),z=l(t,"P",{"data-svelte-h":!0}),a(z)!=="svelte-e26blt"&&(z.innerHTML=Zt),yt=o(t),c(R.$$.fragment,t),Tt=o(t),j=l(t,"P",{"data-svelte-h":!0}),a(j)!=="svelte-1adnj32"&&(j.innerHTML=te),Lt=o(t),N=l(t,"OL",{"data-svelte-h":!0}),a(N)!=="svelte-6rmees"&&(N.innerHTML=ee),kt=o(t),T=l(t,"DIV",{class:!0,"data-svelte-h":!0}),a(T)!=="svelte-b9clbp"&&(T.innerHTML=ie),Ht=o(t),B=l(t,"P",{"data-svelte-h":!0}),a(B)!=="svelte-g5lntq"&&(B.innerHTML=ne),St=o(t),L=l(t,"BLOCKQUOTE",{class:!0,"data-svelte-h":!0}),a(L)!=="svelte-15tqmae"&&(L.innerHTML=se),wt=o(t),c(V.$$.fragment,t),It=o(t),Y=l(t,"P",{"data-svelte-h":!0}),a(Y)!=="svelte-1w8e1er"&&(Y.textContent=oe),xt=o(t),K=l(t,"UL",{"data-svelte-h":!0}),a(K)!=="svelte-f5jv3r"&&(K.innerHTML=re),Pt=o(t),c(Q.$$.fragment,t),_t=o(t),W=l(t,"P",{"data-svelte-h":!0}),a(W)!=="svelte-103q11v"&&(W.textContent=le),qt=o(t),k=l(t,"BLOCKQUOTE",{class:!0,"data-svelte-h":!0}),a(k)!=="svelte-16hyu3v"&&(k.innerHTML=ae),Et=o(t),J=l(t,"OL",{"data-svelte-h":!0}),a(J)!=="svelte-1noiyl3"&&(J.innerHTML=ge),At=o(t),H=l(t,"DIV",{class:!0,"data-svelte-h":!0}),a(H)!=="svelte-v183nr"&&(H.innerHTML=ue),Ot=o(t),S=l(t,"OL",{start:!0,"data-svelte-h":!0}),a(S)!=="svelte-bxfv2j"&&(S.innerHTML=ce),Dt=o(t),X=l(t,"P",{"data-svelte-h":!0}),a(X)!=="svelte-g7qwj8"&&(X.innerHTML=pe),Gt=o(t),c(Z.$$.fragment,t),Ft=o(t),et=l(t,"P",{}),de(et).forEach(i),this.h()},h(){g(h,"name","hf:doc:metadata"),g(h,"content",Le),g(M,"class","warning"),g($,"class","flex justify-center"),g(b,"class","flex justify-center"),g(C,"class","warning"),g(y,"start","4"),g(T,"class","flex justify-center"),g(L,"class","tip"),g(k,"class","note"),g(H,"class","flex justify-center"),g(S,"start","2")},m(t,e){be(document.head,h),n(t,it,e),n(t,tt,e),n(t,nt,e),p(w,t,e),n(t,st,e),p(I,t,e),n(t,ot,e),n(t,x,e),n(t,rt,e),n(t,M,e),n(t,lt,e),p(P,t,e),n(t,at,e),n(t,_,e),n(t,gt,e),n(t,$,e),n(t,ut,e),p(q,t,e),n(t,ct,e),n(t,E,e),n(t,pt,e),p(A,t,e),n(t,dt,e),n(t,O,e),n(t,mt,e),n(t,b,e),n(t,ft,e),p(D,t,e),n(t,ht,e),n(t,G,e),n(t,vt,e),n(t,C,e),n(t,Mt,e),n(t,y,e),n(t,$t,e),p(F,t,e),n(t,bt,e),n(t,U,e),n(t,Ct,e),n(t,z,e),n(t,yt,e),p(R,t,e),n(t,Tt,e),n(t,j,e),n(t,Lt,e),n(t,N,e),n(t,kt,e),n(t,T,e),n(t,Ht,e),n(t,B,e),n(t,St,e),n(t,L,e),n(t,wt,e),p(V,t,e),n(t,It,e),n(t,Y,e),n(t,xt,e),n(t,K,e),n(t,Pt,e),p(Q,t,e),n(t,_t,e),n(t,W,e),n(t,qt,e),n(t,k,e),n(t,Et,e),n(t,J,e),n(t,At,e),n(t,H,e),n(t,Ot,e),n(t,S,e),n(t,Dt,e),n(t,X,e),n(t,Gt,e),p(Z,t,e),n(t,Ft,e),n(t,et,e),Ut=!0},p:fe,i(t){Ut||(d(w.$$.fragment,t),d(I.$$.fragment,t),d(P.$$.fragment,t),d(q.$$.fragment,t),d(A.$$.fragment,t),d(D.$$.fragment,t),d(F.$$.fragment,t),d(R.$$.fragment,t),d(V.$$.fragment,t),d(Q.$$.fragment,t),d(Z.$$.fragment,t),Ut=!0)},o(t){m(w.$$.fragment,t),m(I.$$.fragment,t),m(P.$$.fragment,t),m(q.$$.fragment,t),m(A.$$.fragment,t),m(D.$$.fragment,t),m(F.$$.fragment,t),m(R.$$.fragment,t),m(V.$$.fragment,t),m(Q.$$.fragment,t),m(Z.$$.fragment,t),Ut=!1},d(t){t&&(i(it),i(tt),i(nt),i(st),i(ot),i(x),i(rt),i(M),i(lt),i(at),i(_),i(gt),i($),i(ut),i(ct),i(E),i(pt),i(dt),i(O),i(mt),i(b),i(ft),i(ht),i(G),i(vt),i(C),i(Mt),i(y),i($t),i(bt),i(U),i(Ct),i(z),i(yt),i(Tt),i(j),i(Lt),i(N),i(kt),i(T),i(Ht),i(B),i(St),i(L),i(wt),i(It),i(Y),i(xt),i(K),i(Pt),i(_t),i(W),i(qt),i(k),i(Et),i(J),i(At),i(H),i(Ot),i(S),i(Dt),i(X),i(Gt),i(Ft),i(et)),i(h),f(w,t),f(I,t),f(P,t),f(q,t),f(A,t),f(D,t),f(F,t),f(R,t),f(V,t),f(Q,t),f(Z,t)}}}const Le='{"title":"How to configure SCIM with Microsoft Entra ID (Azure AD)","local":"how-to-configure-scim-with-microsoft-entra-id-azure-ad","sections":[{"title":"Step 1: Get SCIM configuration from Hugging Face","local":"step-1-get-scim-configuration-from-hugging-face","sections":[],"depth":2},{"title":"Step 2: Configure Provisioning in Microsoft Entra ID","local":"step-2-configure-provisioning-in-microsoft-entra-id","sections":[],"depth":2},{"title":"Step 3: Enter Admin Credentials","local":"step-3-enter-admin-credentials","sections":[],"depth":2},{"title":"Step 4: Configure Attribute Mappings","local":"step-4-configure-attribute-mappings","sections":[],"depth":2},{"title":"Step 5: Start Provisioning","local":"step-5-start-provisioning","sections":[{"title":"Assigning Users and Groups for Provisioning","local":"assigning-users-and-groups-for-provisioning","sections":[],"depth":3}],"depth":2},{"title":"Step 6: Verify Provisioning in Hugging Face","local":"step-6-verify-provisioning-in-hugging-face","sections":[],"depth":2},{"title":"Step 7: Link SCIM Groups to Hugging Face Resource Groups","local":"step-7-link-scim-groups-to-hugging-face-resource-groups","sections":[],"depth":2}],"depth":1}';function ke(zt){return he(()=>{new URLSearchParams(window.location.search).get("fw")}),[]}class xe extends ve{constructor(h){super(),Me(this,h,ke,Te,me,{})}}export{xe as component};

Xet Storage Details

Size:
17.9 kB
·
Xet hash:
2b04e4a14f21300e3e11d253fd6370e68f1fe307a8a3eae8b9fffbd8400c3993

Xet efficiently stores files, intelligently splitting them into unique chunks and accelerating uploads and downloads. More info.