Want to provision only users which are added/removed in the Groups(either security or microsoft 365) to the provisioning application and not other users, can this be possible?

Roshan Kumawat 0 Reputation points
2024-04-11T09:13:50.15+00:00

I want to provision only users who are added/Removed in the Group(Either security or Microsoft 365) using the "Provision Microsoft Entra ID Groups" with the scope filter based on the display name and don't want to provision other users on the application which are not part of those Groups can this be possible?
Can we disable this setting "Provision Microsoft Entra ID Users" on Azure?

Currently, it has been observed that all users from Azure ad are getting provisioned in the target application apart from the users in that Group (either security or Microsoft 365).

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

1 answer

Sort by: Most helpful
  1. Navya 20,490 Reputation points Microsoft External Staff Moderator
    2024-04-22T09:27:20.92+00:00

    Hi @Roshan Kumawat

    Thank you for following up on this and I apologize for the delayed response!

    I want to provision only the users to the provisioning application (for example ServiceNow) who are added/removed to Certain groups, and do not want to provision other users to the target application, can this be possible?

    In application provision, we can use scope filters to scope users or groups. But unfortunately, the scoping filter IsMemberOf and members attribute on a group are not currently supported. So, it is not possible to provision only users who have been added or removed from specific groups in Azure AD to a provisioning application.

    User's image

    For your reference: https://learn.microsoft.com/en-us/entra/identity/app-provisioning/define-conditional-rules-for-provisioning-user-accounts?pivots=app-provisioning#create-scoping-filters

    Hope this helps. Do let us know if you any further queries.

    Thanks,

    Navya.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.