Hi Team! We've configured SCIM for Azure AD groups...
# prefect-cloud
e
Hi Team! We've configured SCIM for Azure AD groups, but some members are not synchronized. The Azure AD provision log states: "The state of the entry in both the source and target systems already match. No change to the user <email> currently needs to be made. SkipReason: RedundantExport." So it seems that the user is present in Prefect (in fact one of the users got an e-mail invite, but can't log in), but not visible in the Prefect admin UI. Any suggestions?
w
Thanks for the question Erling. On the Members page, do you see their invites in the invitations tab? Maybe resend, or delete and reinvite?
e
Hi! Invitations are disabled since we're using SSO. We've looked into the issue a bit more during the day and we think it's related to the number of allowed members (licenses).
w
ahh yes, makes sense. Okay then I think there’s probably no technical issue here and its between your account manager and you 🙂. Let me know if there are any other snags.
e
We'll increase #licenses and retry the AD sync. I'll let you know if there are any issues
We've now updated to 30 licenses, restarted the Azure Provisioning, but still only 17 people visible in Prefect. The Azure AD provisioning logs states that 24 people are skipped. The reason is that all users exists both in source (AD) and target (Prefect). As I said above, one of the missing users has received an invitational e-mail from Prefect, but gets an error trying to log in.
w
Thanks Erling. I think our auth experts at support@prefect.io will be able to help you more expeditiously, would you ping them a quick email? They know you’re coming.
e
Sure, sent an email now
t
Hi Erling, I am reviewing your email now. Thank you for reaching out.