Zoom SCIM error - provisioning error (anyone else getting this?)

Luke McDermott 0 Reputation points
2023-08-26T02:23:12.9033333+00:00

Not sure how to properly ask this question... so here goes.

We have started to get errors when provisioning or deprovisioning to zoom.

Provisioning:
1st Step.

  1. Import user = Success
  2. Match user between source and target system = skipped

The error messages are shown below.

Zoom work around:
The new User Principal Name and password Just created in Azure is sent to zoom. However no other fields are sent.

So you can login to zoom directly with these credentials just created in Azure.
Then in zoom the other details can be filled in manually.

SSO works for zoom.

Zoom provisioning error


Occurs for provisioning and de-provisioning



Provisioning:

1st Step.

1. Import user = Success

Gets stuck on second step

2. Match user between source and target system = skipped

This entry is being skipped, because it conflicts with an existing entry hosted in a different tenant of the target application. Almost nothing can be done, except possibly by the person corresponding to the entry. That person may have created a personal account in the target application, using her or his organisational email address, for example. So, unless the person can be contacted, and is willing to delete their pre-existing account, the conflict will persist. For many applications, the skipping of the entry will have no adverse consequences; all that matters is that the person corresponding to the entry in the source directory also has a record somewhere in the target application, and that is indeed the case.




DeProvisioning:



Match user between source and target system


Failed to match an entry in the source and target systems User ‘******@sissoo.com'



Error code
SystemForCrossDomainIdentityManagementServiceIncompatible
Error message
Received response from Web resource.
   Resource: https://api.zoom.us/scim/Users/epmjkU15Rl6pEj8JP-ZLeA
   Operation: GET 
   Response Status Code: BadRequest
   Response Headers: Connection: keep-alive
x-zm-trackingid: v=2.0;clid=us06;rid=WEB_ef2ee378150e2363b2a77cffe3b615eb
x-content-type-options: nosniff
pragma: no-cache
x-zm-zoneid: OH1
CF-Cache-Status: DYNAMIC
Cache-Control: no-store, no-transform, must-revalidate, no-cache
Date: Fri, 18 Aug 2023 10:59:03 GMT
Set-Cookie: zm_aid=""; Domain=.zoom.us; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/; Secure; HttpOnly
zm_haid=""; Domain=.zoom.us; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/; Secure; HttpOnly
zm_tmaid=""; Domain=.zoom.us; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/; Secure; HttpOnly
zm_htmaid=""; Domain=.zoom.us; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/; Secure; HttpOnly
cred=659C13053D92C2E7E9EC2F2530A3061D; Path=/; Secure; HttpOnly
_zm_ctaid=eYqp3NoGTLu7FxDfH6zSbA.1692356343028.5051100c193f6b2aedba898051359c61; Domain=.zoom.us; Expires=Fri, 18-Aug-2023 12:59:03 GMT; Path=/; Secure; HttpOnly
_zm_chtaid=234; Domain=.zoom.us; Expires=Fri, 18-Aug-2023 12:59:03 GMT; Path=/; Secure; HttpOnly
_zm_mtk_guid=4e158ef50434488d80e8e340cf821aa9; Domain=.zoom.us; Expires=Sun, 17-Aug-2025 10:59:03 GMT; Path=/; Secure
__cf_bm=9hnC5CrNRRmZD.bUn4Q62IerfYrSKXGES2e_5btSR7Y-1692356343-0-Ae25ftIU/NsnBBXNr0lJYkAjkn3x0pPLKCEHrxoDCGnjA9sEfZ2RlUIUaw5Ykj+KPwla5PooJlE4rCOlMgvIn6w=; path=/; expires=Fri, 18-Aug-23 11:29:03 GMT; domain=.zoom.us; HttpOnly; Secure
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=GosY3jbma1Dam6J4cK5%2Beiyz12UAD8sKKp0By%2BytoF80Ai8sSf3lB5raGnh3i0TUuJzNcrBwg3jrmUbnVFf1arCWVlug3jXulhw0Y%2Fr0xqbl2EN7HEl2yxmXfNxA"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0.01,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 7f89a5275dc260d9-DUB
alt-svc: h3=":443"; ma=86400
   Response Content: {"code":200,"message":"Account...
—————————————
Community Center | Not monitored
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Danny Zollner 10,801 Reputation points Microsoft Employee Moderator
    2023-08-27T00:33:05.69+00:00

    Zoom has "company managed" accounts but also allows people to sign up for unmanaged "consumer" accounts using any email address, including their company one. I'm not sure if this is only possible before a company has purchased Zoom and associated domains with the application. The error message is stating that there is an account with the same userName in another Zoom environment - either the consumer realm, or another company/corporate tenant, somehow.

    You'll likely need to reach out to Zoom's support to understand why the attempts to create some of these users are failing.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.