Getting started with 1Password for your growing team, or refining your setup? Our Secured Success quickstart guide is for you.
Forum Discussion
EWals
2 years agoNew Contributor
auto remove auto-provisioned groups + users?
Hi,
I just created a scim bridge with azure container and while i was testing i noticed the following:
If i create a group (test group) and add users to the group it nicely add the group + user...
hemal_g_1p
1Password Team
2 years agoHi EWals
Thanks for reaching out.
Great question!
Your 1Password SCIM Bridge should never be able to Delete an account; if a user is deleted, suspended or removed from provisioned groups in your Azure AD, those users should be put into a Suspended
state in their 1Password account. You may delete such users manually as needed.
However the unique situation where a SCIM bridge will Delete a user, is if a user was manually invited through 1Password (without a SCIM bridge) and an Admin never confirmed them before the SCIM bridge made a match on the e-mail address, your SCIM bridge would then Delete the account if the user was Suspended from the IdP side. That scenario would be rare and unlikely in your situation.
You're correct about the wait time of Azure AD as takes approx 40 minute provisioning cycle. To circumvent the 40-minute wait time that Azure AD imposes on 1Password Enterprise application, it has a option called "Provision on demand". You can use it to test or assign a user and immediately view the outcome.
Let me now if you have additional questions.