Skip to main content
Prudhvi Keertipati
Guru
February 3, 2025
Question

PRA - AD Group Synchronization (Pre-Provisioning)

  • February 3, 2025
  • 21 replies
  • 680 views

Hi All,

In PRA, we have a SAML security provider configured for user authentication and provisioning. User will only be provisioned when they first-time logged in.

Is there anyway we can pre-provision the users by LDAP/AD Group synchronization similar functionality as Password Safe (without using SCIM).

 

Thanks,

 

21 replies

Rising Star
May 7, 2025

Hi Naziya, 

 

As previously stated, these are 2 different entities so the users are treated differently.

 

Regards,

Sonam

Prudhvi Keertipati
Guru
May 7, 2025

Hi ​@Naziya, 

As ​@sonam mentioned, LDAP (AD) and SAML are 2 different entities in PRA, even though AD and SAML user account belongs to same user.

We ended up completely removing AD as a Security Provider. We are using PingFederate Outbound Provisioning to provision users with SCIM and PingFederate SSO for authentication. In the backend, PingFederate will pull the users from same AD group for provisioning and SSO. In PRA, for SAML security provider, select SCIM for Provisioning.

Prudhvi K
Rising Star
May 8, 2025

​@Prudhvi Keertipati  - Did you able to get some workaround or fix for this issue?

We are also having similar issue in one environment where we are using Entra ID as SAML provider and users has to be logged in for the first time before you assign the policies or the user ID starts reflecting in PRA. I guess your issue is also same, please confirm. 

Prudhvi Keertipati
Guru
May 8, 2025

​@mj15  Yes, I have a same use case.

As I mentioned in my earlier reply, we are using Outbound Provisioning to provision the users first using SCIM Security Provider that way user accounts are already created and policies applied even before user login for the first time. Then user can login using SAML Security Provider.

In your case, In EntraID Enterprise Applications of your app, there will be Provisioning option which you can use to provisioning the users via SCIM provider. 

In the PRA, For Entra ID SAML Security Provider, in the user provision option, select SCIM provider. this way user will be pre-provisioned with required polices even before they login. 

Prudhvi K
Apprentice
November 6, 2025

Hi All, 

for SAML, SCIM user types, if pre-provisioning is needed then we can use “Available Groups” option present under Security Providers -→ SAML Providers → Authorization Settings → Available Groups

all the required group can be prepopulated in the box and can be used to associate with Group Policies

Trailblazer
February 11, 2026

Hi All,

In PRA, we have a SAML security provider configured for user authentication and provisioning. User will only be provisioned when they first-time logged in.

Is there anyway we can pre-provision the users by LDAP/AD Group synchronization similar functionality as Password Safe (without using SCIM).

 

Thanks,

 

We are also looking for a solution for this scenario. The customer has 100s of users and it is very cumbersome to first tell a new employee to login, then, in our scenario, link the vault account to that login, then tell the user to start using the system. A lot of mis-communication and tickets are raised because of this.

We would like to have the user beforehand (provisioned) so we can link personal vault accounts, etc.

The right way would be SCIM which is apparently supported. After long investigation we were told however it is not supported for Entra which seems one of the major players as an IAM:-)

 

BT any progress on this.

Trailblazer
February 11, 2026

​@mj15  Yes, I have a same use case.

As I mentioned in my earlier reply, we are using Outbound Provisioning to provision the users first using SCIM Security Provider that way user accounts are already created and policies applied even before user login for the first time. Then user can login using SAML Security Provider.

In your case, In EntraID Enterprise Applications of your app, there will be Provisioning option which you can use to provisioning the users via SCIM provider. 

In the PRA, For Entra ID SAML Security Provider, in the user provision option, select SCIM provider. this way user will be pre-provisioned with required polices even before they login. 

Hi

How did you get the provisioning tab in EntraID Enterprise App? We never see that tab. BT told us that it is not supported for PRA.

Can we get in touch to show us how you achieved this? This would be a game changer for 3 of our customers.

Trailblazer
February 11, 2026

​@Prudhvi Keertipati  - Did you able to get some workaround or fix for this issue?

We are also having similar issue in one environment where we are using Entra ID as SAML provider and users has to be logged in for the first time before you assign the policies or the user ID starts reflecting in PRA. I guess your issue is also same, please confirm. 

Same here. mj15 did you ever found a solution to pre-provision users with EntraID? BT told us that SCIM is not supported with EntraID due to missing filter parameters that are not supported

Apprentice
February 19, 2026

​@Prudhvi Keertipati  - Did you able to get some workaround or fix for this issue?

We are also having similar issue in one environment where we are using Entra ID as SAML provider and users has to be logged in for the first time before you assign the policies or the user ID starts reflecting in PRA. I guess your issue is also same, please confirm. 

Same here. mj15 did you ever found a solution to pre-provision users with EntraID? BT told us that SCIM is not supported with EntraID due to missing filter parameters that are not supported

It’s really unfortunate that there’s no support for true synchronization / membership provisioning in the PRA SCIM <> Entra ID scenario. From what’s been discussed here, PRA only provisions users on first login when using Entra ID as a SAML provider and there’s no equivalent to LDAP/AD group pre-provisioning like with Password Safe. 

 

We’ve also heard from others that pre-provisioning via SCIM with Entra ID isn’t feasible in this setup, likely because Entra’s provisioning service doesn’t support the necessary filter parameters or group membership sync behavior that PRA would need on the SCIM side. That makes it difficult to automate user + group provisioning ahead of first login and policy assignment. 

 

It’s disappointing that this gap exists today — it really limits onboarding automation and forces reliance on just-in-time provisioning instead of true sync.

Apprentice
March 6, 2026

We are having exactly the same problem. It is a real Pain for first time users. Ask them to logon, tell them that the error message is “expected”, edit the group policy, vault etc with the now present object and then ask them to reload and sign in again.