## TL;DR
SCIM provisioning stuck in pending activation usually means the target app never acknowledged the create request: bad API credentials, a required attribute missing, or the app-side provisioning disabled. Check the provisioning logs in the IdP first.

## The query
```text
scim provisioning stuck in "pending activation" for new hires
```

## Use this when
- new hire accounts stuck in pending activation
- one app provisions slowly while others are instant
- provisioning broke after an app admin change

## Not for
- SSO login failures for already-provisioned users
- deprovisioning delays (related but separate)
- manual account creation

## Steps
1. In the IdP provisioning logs, find the stuck operation and read the error. Expected output: the underlying error identified
2. Verify the SCIM API credentials or bearer token for the app are still valid. Expected output: credentials confirmed working
3. Check the attribute mapping for required fields the app expects. Expected output: no missing required attributes
4. Confirm provisioning is enabled on the app side and the service account has rights. Expected output: app-side provisioning active
5. Retry the provisioning operation from the IdP. Expected output: the operation completes
6. Verify the account exists in the target app with the right attributes. Expected output: account confirmed

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_ssaaXkQ4cRHdWddCHNyDLw
