A cloud-based identity and access management service for securing user authentication and resource access
Treat roles[].primary as a JSON Boolean consistently; the string requirement is an acknowledged Microsoft Entra SCIM Validator bug, and Microsoft has not documented a workaround that reliably satisfies both contradictory test paths.^1^
Correct endpoint behavior
Return the same representation from POST, PATCH, direct GET, and filtered/list GET:
{
"roles": [
{
"value": "admin",
"display": "Administrator",
"type": "application",
"primary": true
}
]
}
Also parse filter literals such as primary eq true as Boolean values, not strings. Do not switch serialization according to the preceding operation.
The fact that roles is multi-valued does not leave its subattributes untyped: the SCIM schema defines the types of properties within each complex value. Microsoft’s SCIM API examples likewise use an unquoted Boolean in complex-value filters—for example, primary eq true.^2^
How to handle the two failed validator tests
Since always-string, always-Boolean, and operation-dependent serialization have already been tested, there is no further endpoint representation demonstrated to satisfy both validator expectations. Record these two failures as validator exceptions:
- Save the complete request/response trace for each failing test.
- Include the validator test name and the contradictory expected/actual types.
- Include your
/Schemasdeclaration forroles.primary. - Demonstrate that every endpoint returns Boolean
trueorfalse. - Reference Microsoft’s accepted response acknowledging this specific string-versus-Boolean behavior as a validator bug.^1^
The validator documentation lists other known limitations but does not list a flag or configuration that changes roles.primary coercion.^3^ The general SCIM behavior flag documented by Microsoft changes specific PATCH scenarios such as active, single-valued strings, replacing multiple attributes, and removing group members; it does not document a fix for roles.primary.^4^
If this is for App Gallery onboarding
The Microsoft Entra SCIM Validator is a development tool, not the validation mechanism required for App Gallery publication. Microsoft directs gallery publishers to run the Azure Logic Apps validation template and submit those results instead.^3^
Therefore:
- Keep production behavior standards-compliant with Boolean
primary. - Do not introduce request-history-dependent output solely to make the validator pass.
- Submit the validation evidence with the two known contradictory failures and engage the product/onboarding team if those failures block submission.
References
- in SCIM validator tool, in request, at attribute role the 'primary' value is string but should be boolean - Microsoft Q&A
- Microsoft Entra ID SCIM API reference
- Tutorial: Validate a SCIM endpoint
- Known issues and resolutions with SCIM 2.0 protocol compliance of the Microsoft Entra user provisioning service