Share via

in enterprise app, user is added but it is not propagated to AWS SSO

Navin Kumar 0 Reputation points
2026-03-16T20:32:19.4933333+00:00

in enterprise app, user is added but it is not propagated to AWS SSO

Microsoft Security | Microsoft Entra | Microsoft Entra External ID

1 answer

Sort by: Most helpful
  1. Carolyne-3676 1,131 Reputation points
    2026-03-18T13:10:52.6566667+00:00

    Hello Navin!
    The most common cause is because the user is assigned to the Enterprise App, but SCIM provisioning scope or assignment-based scoping blocks it—only users who are direct members of assigned users/groups (no nested groups) and meet required attributes (e.g., givenName, surname, userName) will be provisioned to AWS IAM Identity Center.

    I think you should first confirm Provisioning = Automatic, Status = On, the SCIM token/endpoint is valid, and review Provisioning Logs for errors; then force an on‑demand provision for the user—AWS won’t receive the user until Entra provisioning successfully runs.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.