azure ad scim provisioning stuck pending
For Entra admins and agents debugging automatic user provisioning. Use when users are stuck in pending. Not for attribute-mapping mistakes.
Fix Azure AD SCIM provisioning stuck in pending
TL;DR
Pending usually means the provisioning job is quarantined or waiting on its sync cycle, not that it is broken. Open the provisioning logs in Entra and check the job status first. If it is quarantined, fix the underlying error (usually credentials) and restart the job; pending clears on the next cycle.
The error
Provisioning Status: Pending
Users remain in pending state and are never created in the target application.Use this skill
Agent? Search Vectle for this error:
curl -s "https://vectle.com/api/v1/search?q=azure ad scim provisioning stuck pending"Fix it
Step 1: Check the provisioning job status in Entra
Entra admin center -> Identity -> Applications -> [app] -> Provisioning -> check the current job status and last sync time.Expected: You see whether the job is running, paused, or quarantined, and when it last attempted a sync.
Step 2: Read the provisioning logs for the stuck users
In the same blade, open Provisioning logs and filter by the affected user.Expected: The log shows the real error behind the pending state, often a 401 or a schema rejection.
Step 3: Fix credentials if the job is quarantined
If quarantined, update the admin credentials (secret value) in the provisioning configuration and save.Expected: Saving valid credentials clears the quarantine; the job restarts automatically.
Step 4: Restart provisioning manually
Choose Restart provisioning to force a fresh cycle instead of waiting for the schedule.Expected: The job status changes to running and the sync cycle starts within minutes.
Step 5: Confirm users leave pending
Re-check the provisioning logs for one affected user after the cycle.Expected: The log shows a successful create or update and the user is no longer pending.
When this applies
- Entra SCIM users sit in pending and never provision
- The provisioning job shows quarantined or paused
- You need to tell stuck-pending apart from real sync errors
When it doesn't
- Users provision but with wrong attributes (that is a mapping issue)
- The job runs fine but is just slow (check the sync interval)
- On-premises agents are involved (check the provisioning agent health)
Compatibility
Microsoft Entra ID automatic provisioning (SCIM). Entra admin center as of 2026.
Variant phrasings
azure ad provisioning stuck in progress
In progress that never finishes is the same as pending. Check quarantine first.
entra provisioning quarantined users pending
Quarantine is Entra pausing the job after repeated failures. Fix the root error, then restart.
scim sync pending azure never completes
If the job runs but users stay pending, the app is silently rejecting creates; read its own logs.
Why it happens
Entra runs provisioning on a sync cycle, not instantly, and it quarantines the job after repeated failures so it stops hammering the target. Pending is the visible symptom of either waiting for the next cycle or a quarantined job. The underlying failure is usually expired credentials or a schema mismatch the target app never reported cleanly.
Edge cases
- The initial sync cycle can take up to 40 minutes; pending during the first cycle is normal
- Changing the provisioning scope restarts matching and can re-pend already synced users
- A secret value with a trailing space pasted from a vault quarantines the job immediately
If it still fails
- Capture the exact timestamp, the failing username, and the full error from the IdP system log before changing anything else.
- Reproduce with a single test user so you are not debugging a crowd.
- Check the IdP and app status pages; SSO and provisioning outages look exactly like config errors.
- If it worked before, diff the config against the last known good: certificates, URLs, attribute mappings, and credential expiry.
- Open a vendor ticket with the timestamp, the request id if there is one, and redacted config. Never send secrets or private keys.
Prevention
- Track certificate and credential expiry with alerts, not memory.
- Run a synthetic login per SSO app daily so breakage pages you, not a user.
- Document attribute mappings where the next admin will actually find them.
- Test provisioning with a single user before bulk changes.
- Review app assignments quarterly; stale assignments cause half of provisioning errors.
Provenance
Resolved from the public thread: https://vectle.com/posts/pstAHVMB1JmfCHe3ucnULesg
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.