Skip to main content

#User Provisioning0 discussing

Recommendation, when facing User Provisioning Error from Microsoft Entra ID to Salesforce:

I recently faced an issue with the user provisioning integration from Microsoft Entra ID to Salesforce. The error response is seen at the bottom (all included for enabling searching of this by others). 

 

Issue Origin:

The issue was caused by a duplicate user being created:

  1. Proper 'User Real' already existed, without FederationIdentifier
  2. Then the user provisioning system synchronized the users to Salesforce
  3. Since it didn't find a user with the FederationIdentifier, it created a new one 'User Dupe'
  4. We found this, deactivated 'User Dupe' and cleared FederationIdentifier, and set the correct one on 'User Real'
  5. However, the next user provisioning sync failed.
  6. The error message was unclear, but we found the user facing the issue based on a Salesforce User ID in the Entra ID provisioning error logs.
  7. We then tried to set some dummy FederationIdentifier on 'User Dupe' and tried a sync, and then we got a different error.

Probable Root Cause: 

While one might assume that Microsoft Entra ID always retrieves users from Salesforce, before an update occurs towards Salesforce, it instead seems like Entra ID is caching a table of users based on Salesforce user ids, and updates based on this invalid cache mapping (FederationIdentifier -> SF User Id). 

 

The bug overall seems to be in Microsoft Entra ID, so the issue should be raised with their support.

  

Sample Error Message Thrown in Entra ID:

EntrySynchronizationError

  • Result: Failure
  • Description: Failed to match an entry in the source and target systems User 'XX@YY.ZZ'
  • ErrorCode: UnSpecified
  • Error details: Invalid context
  • ErrorMessage: 

An error has occurred when attempting to match an entry in the source and target systems. 

 

Review the common matching failures and error details for more information. Common matching failures: 

  • The target application does not support filtering on the matching attribute. Review your attribute mappings and ensure that the target application supports filtering on that matching attribute.
  • The source entry does not have a value for at least one matching attribute. Review your attribute mappings to identify the matching attribute(s) and ensure that the entry has a value for those attribute(s).
  • The target application denied the request due to an authentication or authorization failure. Ensure that the credentials you have provided have the necessary permissions for provisioning.
  • There is an issue with the target application. It is unreachable, returned a non-specific error, or returned a non-SCIM compliant response. Contact the application developer. 

 

 

#User Provisioning #Auth Provider #Error

0/9000

Here are two brand new posts on what I believe are best practices for the next decade of Salesforce user provisioning at small organizations. Lol... what a statement. I'll guarantee you that what I have in my org of more than ten years is a far cry from best proactive now... probably wasn't then. But I've been trying! And it's starting to save time and make more possible...

 

It starts with a minimal user profile. Then you add tasks to be done broad permission sets and put them into a permission set group muted down to those needed by the user or user group.

 

It's not easy stuff but I highly recommending learning how. There is too much valuable data in your org to continuing running "wide open" and there isn't enough time in the day to manage it any other way that I know about.

 

P.S. LAtely I can't seem to get my game together to release a blog on Wednesday which is probably the best day. So please comment and share on Wednesday. Lol

 

1. Brief intro to creating an empty or minimal profile article: (summary created with help of AI): 

Enable restricted access login users like volunteers or interns by creating an empty

profile. Salesforce’s default “Minimum Profile” has been inadvertently added

Permissions by us (you have to uncheck it each time you add stuff), making it useless and requiring cleanup. Workbench allows easy addition 

of a blank profile with only name and license type, saving time and effort compared to

searching for granted access. Created a test user named Nobodyx @SYMin with no

role, assigned minimum profile, and unique email address. Login-as admin without

password. Currently, there is only one app (and one rogue app) available.

 

https://mighyforce.dreamhosters.com/2024/01/sym-publicity-volunteer-permission-set-group/. Compliments to @Tom Bassett for the neat method to create your own.

 

When you login as a user created with no checkboxes per missions other than this profile, you simply get lightning with one app (chatter). This is what we want! (P.S. I did eventually get rid of Power of Us Hub... it was a tab setting apparently ignored by the profile and permission sets) @Cheryl FeldmanHere are two brand new posts on what I believe are best practices for the next decade of Salesforce user provisioning at small organizations. Lol... what a statement.

2. Brief intro to creating a permission set group to capture a complex jobs to be done for a volunteer publicity helper: (summary created with help of AI):

A volunteer will access Salesforce Experience Cloud to edit objects at

cconnect.SYMin.org, allowing them to view, proofread, and modify data from numerous

records. Volunteers will receive a minimum profile and permission set for working with

functional tasks. Tasks include working with SYM Events, inventory items, programs,

and Managed Content. They will fix spelling errors, view impact data, and fix errors in

various objects. CRM content may be an alternative if needed. The document outlines

permission sets for various SYM objects, including SYM Events, Inventory, Programs,

and Managed Content. These permissions require full CRUD access to custom objects,

SYM Event Management App access, and access to the SYM Inventory App. The

permission set also requires read access to Program Engagements and Program

Cohorts, and access to the Program Management Reports folder. The document

emphasizes the importance of these permissions for effective use. Users assigned to

the experience cloud can access web pages, navigate to record pages, and edit fields

with edit permissions.

 

This is a veal example--it's messy... not simple at all. But it wasn't hard. And the parts are reusable and set the template for how all future tasks for internal ad external users will be provisioned.:

 

https://mighyforce.dreamhosters.com/2024/01/sym-publicity-volunteer-permission-set-group/

 

Here is the finished user logged in. They see a number of apps because the items exposed on our experience cloud site come from a variety of places. They have no delete rights for most items, although our custom object for managed content (a CRM type object) has full rights. Very cool... nothing distracting or dangerous! Just what everyone would order for a new person!

pasted image 0 (1).png

@The Blog Group @MVPs & AppExchange All Stars @Nonprofit and Education MindShare @Ryan Ozimek @Nonprofit User Group, San Antonio, US @Nonprofit User Group, Dallas, US @Nonprofit User Group, Houston, US @Nonprofit User Group, Austin, US #User Provisioning #Profiles #Minimum Access 

3 comments
0/9000

User provisioning question - what options do we have to sync user attribute data and provision users in Salesforce from an on-premise system that does not have any prebuilt connectors (like OKTA, AD etc) with no SSO (so no SAML JIT). Is it pretty much limited to using SOAP or REST callouts?

#User Provisioning #Identity and Access Management

1 answer
  1. Manoj Nambirajan (Dell Technologies) Forum Ambassador
    Jul 11, 2022, 12:15 PM

    yes.. dont see any other option. Could potentially be a webservice call out (soap or rest api) which compares user existence in SFDC while comparing with on-prem system and create user accordingly.

0/9000