Entra Id Scim Api Reference
Feature updateThe reference now documents up to 999 users per page when the projection excludes the manager attribute, plus filters for active users, negated suffix matches, group membership, and group ownership.
Daily.Entra.NewsDaily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →
September 5 was documentation-led: all nine supplied entries were updates, with no new or removed items and no Message Center notices. The substantive guidance covers passkey and Authenticator registration campaigns, SCIM query and permission design, and a Workload ID namespace distinction. The remaining edits are mostly link, schema, and reference maintenance.
The Entra ID guidance describes Microsoft managed, Enabled, and Disabled states, along with method-specific eligibility and prompting conditions. It also lists prerequisites for Authenticator and passkey campaigns and says the updated experience is rolling out through the end of September 2026, so tenant behavior may vary during rollout.
The reference documents up to 999 users per page when the projection excludes the manager attribute. It also covers filters for active users, negated suffix matches, group membership, and group ownership.
The reference adds operation-specific permissions for basic user reads, user creation and updates, group creation and membership changes, and selected user attributes. Provisioning applications can align consent more closely with the operations their workflows perform.
User:ownedGroups and Group:owners are documented as read-only, multi-valued attributes. Their IDs can be used in filter queries but are never returned in response bodies; the page also corrects the groups members.value response-body description.
Workload ID guidance says Azure CLI commands and infrastructure-as-code templates must use Microsoft.Storage. Microsoft.Storage/* is only the Azure portal display convention and is not accepted by the API.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The reference now documents up to 999 users per page when the projection excludes the manager attribute, plus filters for active users, negated suffix matches, group membership, and group ownership.
The permissions table removes individual inline links and adds a note linking to the Microsoft Graph permissions reference. The listed permissions and descriptions remain the same.
The reference adds least-privilege permissions for basic user reads, user creation and updates, group creation and membership changes, and specific user attributes.
The permissions table now lists granular options for reading, creating, and updating users, plus creating groups and managing group memberships. Existing permission descriptions were also clarified.
The schema now documents read-only, multi-valued `User:ownedGroups` and `Group:owners` attributes. Their IDs are usable in filter queries but are never returned in response bodies. It also corrects the `members.value` response-body description for groups.
The SCIM API reference now advises apps that update specific user attributes to use the least-privileged permission and links to the detailed permissions guidance.
The documentation now describes Microsoft managed, Enabled, and Disabled campaign states, method-specific eligibility and prompting conditions, and prerequisites for Authenticator and passkey campaigns. The updated experience is rolling out through the end of September 2026, so tenant behavior may vary during rollout.
The documentation now clarifies that Azure CLI commands and IaC templates must use the provider namespace Microsoft.Storage, while Microsoft.Storage/* is only an Azure portal display convention.
The documentation now clarifies that Azure CLI commands and IaC templates must use Microsoft.Storage. The Microsoft.Storage/* format shown in the portal is only a display convention and is not accepted by the API.