Additional Microsoft Entra services and features related to identity, access, and network security
The error message SystemForCrossDomainIdentityManagementServiceIncompatible indicates that the Microsoft Entra provisioning service is unable to parse the response from your SCIM endpoint. This typically occurs when the SCIM server is not fully compatible with the Azure Active Directory SCIM client.
To address this issue, you should work closely with the third-party application developer to ensure that the SCIM endpoint adheres to the SCIM 2.0 protocol specifications that Azure expects. Here are a few steps you can take on the Azure side:
- Review SCIM Compliance: Ensure that the SCIM endpoint follows the SCIM 2.0 compliance guidelines as outlined by Microsoft. This includes proper formatting of responses and adherence to expected schemas.
- Check Response Structure: Verify that the resource returned from the SCIM endpoint is structured correctly. The response should match the expected format that Azure AD can deserialize.
- Test with Sample Requests: Use sample requests to validate the SCIM endpoint's behavior. Compare the responses with what Azure AD expects to identify discrepancies.
- Consult Documentation: Refer to Microsoft documentation regarding SCIM implementation and compliance to ensure that all requirements are met.
By collaborating with the application developer and ensuring compliance with the SCIM standards, you should be able to resolve this issue.