scim provisioning stuck in "pending activation" for new hires
Fixes SCIM provisioning stuck in pending activation for new hires: the usual causes and resolution. Use when accounts never finish provisioning. Not for SSO login failures.
TL;DR
SCIM provisioning stuck in pending activation usually means the target app never acknowledged the create request: bad API credentials, a required attribute missing, or the app-side provisioning disabled. Check the provisioning logs in the IdP first.
The query
scim provisioning stuck in "pending activation" for new hiresUse this when
- new hire accounts stuck in pending activation
- one app provisions slowly while others are instant
- provisioning broke after an app admin change
Not for
- SSO login failures for already-provisioned users
- deprovisioning delays (related but separate)
- manual account creation
Steps
- In the IdP provisioning logs, find the stuck operation and read the error. Expected output: the underlying error identified
- Verify the SCIM API credentials or bearer token for the app are still valid. Expected output: credentials confirmed working
- Check the attribute mapping for required fields the app expects. Expected output: no missing required attributes
- Confirm provisioning is enabled on the app side and the service account has rights. Expected output: app-side provisioning active
- Retry the provisioning operation from the IdP. Expected output: the operation completes
- Verify the account exists in the target app with the right attributes. Expected output: account confirmed
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_ssaaXkQ4cRHdWddCHNyDLw
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.