Skip to main content

Inbound SCIM

Inbound SCIM provisions users and groups from an external system to the Quant0 Org Portal.

Use this configuration when an external identity provider, directory, or application is the source of user or group information and those changes need to be synchronized with Quant0. Pair it with the related configuration in Connected Apps and review the incoming Users and Groups mappings before enabling production synchronization.

Back to SCIM Configuration

Enable Inbound SCIM​

Navigate to:

SCIM Configurations → Inbound

Enable Inbound SCIM.

Copy the SCIM Base URL displayed by the portal.

Provide this URL to the external system administrator.


Configure Authentication​

Select the authentication method required for inbound requests.

If the portal provides a token:

  1. Select Generate Token.
  2. Copy the generated token.
  3. Provide the token to the external system administrator.


Configure Attribute Mapping​

Configure how incoming SCIM attributes map to Quant0 user attributes.

SCIM AttributeQuant0 Attribute
userNameUsername
emails.valueEmail
name.givenNameFirst Name
name.familyNameLast Name
displayNameDisplay Name
activeActive

Configure group mapping if group provisioning is required.


Test Inbound Provisioning​

From the external system:

  1. Create a test user.
  2. Send the user through the SCIM connection.
  3. Verify that the user appears in Quant0.
  4. Update the user and verify the changes.
  5. Test group membership if enabled.
  6. Test deactivation if enabled.


Enable Inbound SCIM​

After successful testing:

  1. Confirm the endpoint.
  2. Confirm authentication.
  3. Confirm attribute mappings.
  4. Enable inbound provisioning.
  5. Save the configuration.


Inbound SCIM Troubleshooting

Unauthorized / Invalid Credentials​

If an inbound request returns an authentication error:

  • Verify that the token is correct.
  • Check whether the token has expired.
  • Generate a new token if required.
  • Update the external system configuration.
  • Send the request again.

Inbound User Not Created​

If an inbound user does not appear in Quant0:

  1. Verify that inbound SCIM is enabled.
  2. Verify that the external system is using the correct SCIM Base URL.
  3. Verify the authentication token.
  4. Check the inbound activity or event history.
  5. Verify that required attributes are being sent.
  6. Check whether the user already exists.

User Created With Missing Attributes​

If the inbound user is created but some attributes are missing:

  1. Open Attribute Mapping.
  2. Verify the mapping for the missing attribute.
  3. Confirm that the external system sends the required value.
  4. Save the mapping.
  5. Send the user update again.

Duplicate User​

If duplicate users are created in Quant0:

  • Check the configured user matching attribute.
  • Use a unique identifier such as External ID, Username, or Email.
  • Verify that the same matching attribute is consistently provided by the external system.

Group Membership Not Synchronized​

If inbound group membership is not synchronized:

  • Verify that group provisioning is enabled.
  • Check the group attribute mapping.
  • Verify that the group exists in the external system.
  • Check the user's group membership in the external system.
  • Review the inbound activity for errors.
  • Send the group membership update again.

Required Attribute Missing​

If inbound provisioning reports a missing required attribute:

  1. Identify the missing attribute from the error.
  2. Open the attribute mapping configuration.
  3. Verify the corresponding mapping.
  4. Confirm that the external system provides the value.
  5. Correct the mapping or source data.
  6. Retry the provisioning operation.

Rate Limit​

If the external system or Quant0 reports a rate-limit error:

  • Reduce the provisioning frequency.
  • Reduce the batch size if supported.
  • Wait for the rate limit to reset.
  • Retry the failed provisioning operation.

Provisioning Repeatedly Fails​

If the same inbound provisioning operation continues to fail:

  1. Open Job History or Activity.
  2. Identify the failed operation.
  3. Review the displayed error.
  4. Verify the SCIM Base URL.
  5. Verify authentication.
  6. Verify attribute mappings.
  7. Correct the configuration or source data.
  8. Retry the operation.
  9. If required, temporarily disable inbound provisioning.