Microsoft Entra ID
Standards

Entra Id Scim Api Reference

In brief

The reference adds least-privilege permissions for basic user reads, user creation and updates, group creation and membership changes, and specific user attributes.

What Entra admins need to know

Review provisioning application permissions and grant the operation-specific permissions required by your SCIM workflows.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Permission type Permissions (least to most privileged)
Application User.ReadBasic.All, User.Read.All, User.ReadWrite.All

Query parameters for List users

Permission typePermissions (least to most privileged)
ApplicationUser.ReadBasic.All, User.Read.All, User.ReadWrite.All

Query parameters for Get user by ID

Permission typePermissions (least to most privileged)
ApplicationUser.Create or User.ReadWrite.All

Required attributes for Create a user

Permission typePermissions (least to most privileged)
ApplicationUser.ReadUpdate.All or User.ReadWrite.All

Constraints for Update a user

Permission type Permissions (least to most privileged)
Application Group.Create or Group.ReadWrite.All

Required attributes for Create a group

Permission type Permissions (least to most privileged)
Application GroupMember.ReadWrite.All or Group.ReadWrite.All for membership changes; Group.ReadWrite.All for group property changes.

Constraints for Update a group

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…