Skip to main content
Participant
May 12, 2023
Answered

Group Sync via Azure OIDC SCIM Connection

  • May 12, 2023
  • 1 reply
  • 2040 views

Hello! I have recently been tasked with migrating off of the onprem python job of syncing users from active directory to the adobe identity management tool. When reveiewing all of the documentation for SCIM provisioning for Adobe, there is no documentation about group management via SCIM. When trying to test user sync between Azure and Adobe, I noticed that the user account will get recreated and no groups will be added to the user, so all products and groups information gets deleted. Are there detailed instructions somewhere on how to adjust the SCIM user and or group mappings to send this group and product zone to adobe so that information is synced correctly? Or are there ways to manually map the group name to what currently exists in Adobe as they are different and synced via this python job?

This topic has been closed for replies.
Correct answer Ashish_Harrison

Hi @Ben298571795akb you need to turn off UST/UMAPI and switch to Azure SCIM. 
If you find this answer incorrect could you please provide the information you found?

Thanks!

1 reply

Ashish_Harrison
Adobe Employee
Adobe Employee
May 15, 2023

Hi @Ben298571795akb you can sync user groups and nested groups from Azure to Adobe Admin Console; you need a Premium (P1 or P2) or Microsoft 365 (E3 or A3) subscription.

As Azure takes time, I recommend you try with 1 user group for testing.

Synced user group names cannot be changed as Azure manages them.

 

For more, you can refer to the help documents:

https://learn.microsoft.com/en-us/azure/active-directory/saas-apps/adobe-identity-management-provisioning-tutorial#step-5-configure-automatic-user-provisioning-to-adobe-identity-management

 

https://helpx.adobe.com/in/enterprise/using/add-azure-sync.ug.html#notes-before-sync

 

 

Regards,Ashish Harrison
Participant
May 16, 2023

For clarity, this answer is not the "correct" answer. What Adobe needs, is specific and more flushed out documentation on the migration from the UST that exists on prem, to the Azure Sync SCIM method, highlighting the areas where you need to know what to switch in each tool. I was able to find the information I needed, but after hours of searching and trial and error.

Ashish_Harrison
Adobe Employee
Ashish_HarrisonCorrect answer
Adobe Employee
May 16, 2023

Hi @Ben298571795akb you need to turn off UST/UMAPI and switch to Azure SCIM. 
If you find this answer incorrect could you please provide the information you found?

Thanks!

Regards,Ashish Harrison