Entra SCIM Test Connection Fails with “AccessDeniedException”

Sravya Bandari
Sravya Bandari
  • Updated
Audience: Everyone

Products and Versions Covered: 

  • Jama Connect® version(s)
  • Self-hosted
  • Cloud/CVC

Summary

If the SCIM Test Connection (or provisioning) in Microsoft Entra fails with a permissions error (for example, AccessDeniedException), the Jama Connect® SCIM service account likely no longer has Org Admin permissions due to missing user group membership.

org.springframework.security.access.AccessDeniedException: You don't have permission to perform this action.
at impl.DwrServiceSupport.authorize(DwrServiceSupport.java:163)
at impl.DwrServiceSupport.authorizeOrganization(DwrServiceSupport.java:237)
at impl.DwrServiceSupport.canAdminOrganization(DwrServiceSupport.java:570)
at impl.DwrClientServiceSupport.assertUserIsOrgAdmin(DwrClientServiceSupport.java:78)

Resolution

  • Identify the Jama Connect® account used for SCIM provisioning in Microsoft Entra.
  • In Jama Connect®, open the user profile and verify the account is active and is a member of the Org Admin group.
  • Add the SCIM provisioning account to the Org Admin group.
  • Re-run Test Connection in Microsoft Entra provisioning and confirm provisioning succeeds.

Additional Resources 

Feedback:
We welcome your input! Please sign in to leave any comments, suggestions, or ideas for improvement below.

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request

Comments

0 comments

Please sign in to leave a comment.