<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue with updating email with SCIM Provisioning in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/issue-with-updating-email-with-scim-provisioning/m-p/136987#M4320</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/167090"&gt;@dbx_user&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;I believe we have tried this move before, and the result was that the user was ignored from future SCIM provisioning runs. We had to manually use the API to add the user back in and are now hooked into manually updating this users user groups through the API.&lt;BR /&gt;&lt;BR /&gt;Has this functionality changed?&lt;BR /&gt;The docs still say that this is the expected functionality. Dot point 3 under provisioning tips here:&amp;nbsp;&lt;A href="https://docs.databricks.com/aws/en/admin/users-groups/scim/aad#provisioning-tips" target="_blank" rel="noopener"&gt;Configure SCIM provisioning using Microsoft Entra ID (Azure Active Directory) | Databricks on AWS&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/167090"&gt;@dbx_user&lt;/a&gt;&amp;nbsp; "The removed user will not be synced again using Microsoft Entra ID provisioning, even if they remain in the enterprise application."&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Well, after stopping and resuming sync in&amp;nbsp;the Enterprise application, the deleted user was synced again.&lt;/P&gt;</description>
    <pubDate>Fri, 31 Oct 2025 13:41:02 GMT</pubDate>
    <dc:creator>Vasyl_S</dc:creator>
    <dc:date>2025-10-31T13:41:02Z</dc:date>
    <item>
      <title>Issue with updating email with SCIM Provisioning</title>
      <link>https://community.databricks.com/t5/administration-architecture/issue-with-updating-email-with-scim-provisioning/m-p/86830#M1682</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;For our set-up we have configured SCIM provisioning using Entra ID, group assignment on Azure is dealt with by IdentityIQ Sailpoint, and have enabled SSO for Databricks. It has/is working fine apart from one scenario. The original email assigned to an account on Entra ID has been &lt;STRONG&gt;updated&lt;/STRONG&gt;&amp;nbsp;from &lt;A href="mailto:user.a@company.org" target="_blank" rel="noopener"&gt;user.A@company.org&lt;/A&gt;&amp;nbsp;to &lt;A href="mailto:user.b@company.org" target="_blank" rel="noopener"&gt;user.B@company.org,&lt;/A&gt;&amp;nbsp; due to a name change.&lt;/P&gt;&lt;P&gt;The email update has been reflected everywhere (Azure, IIQ) so is referring to user.b@. However, Databricks is still trying to match to the original email user.a@. We have revoked access completely to everything and still face the same issue?&lt;/P&gt;&lt;P&gt;Has anyone dealt with this before, or have any ideas of how to deal with the issue?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 10:14:56 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/issue-with-updating-email-with-scim-provisioning/m-p/86830#M1682</guid>
      <dc:creator>ma10</dc:creator>
      <dc:date>2024-08-30T10:14:56Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with updating email with SCIM Provisioning</title>
      <link>https://community.databricks.com/t5/administration-architecture/issue-with-updating-email-with-scim-provisioning/m-p/107645#M2887</link>
      <description>&lt;P&gt;Currently, the email address is an immutable attribute in the Databricks application. To request a change to this behavior, you can submit a&amp;nbsp;&lt;A href="https://docs.databricks.com/en/resources/ideas.html#submit-product-feedback" target="_self"&gt;feature enhancement&lt;/A&gt;. In the interim, you can also submit a support case for a potential workaround.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 17:28:20 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/issue-with-updating-email-with-scim-provisioning/m-p/107645#M2887</guid>
      <dc:creator>Ismael-K</dc:creator>
      <dc:date>2025-01-29T17:28:20Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with updating email with SCIM Provisioning</title>
      <link>https://community.databricks.com/t5/administration-architecture/issue-with-updating-email-with-scim-provisioning/m-p/127340#M3809</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN class=""&gt; &lt;A class="" href="https://community.databricks.com/t5/user/viewprofilepage/user-id/55146" target="_self"&gt;&lt;SPAN class=""&gt;Ismael-K&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Is there any workarounds for this scenario?&lt;BR /&gt;I have exact same problem when the user changed his e-mail in Azure EntraID from &lt;A href="mailto:UserA@BranchA.company.com" target="_blank" rel="noopener"&gt;UserA@BranchA.company.com&lt;/A&gt;&amp;nbsp;to&amp;nbsp;&lt;A href="mailto:UserA@BranchA.company.com" target="_blank" rel="noopener"&gt;UserA@BranchB.company.com&lt;/A&gt;&lt;BR /&gt;I've deleted the user with the old email from the accounts console in accounts.azuredatabricks.net but now, when in the accounts console I searching user with a new email&amp;nbsp;&lt;A href="mailto:UserA@BranchA.company.com" target="_blank" rel="noopener"&gt;UserA@BranchB.company.com&lt;/A&gt;&amp;nbsp;I cannot find it, although it remains in Azure EntraID&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2025 14:10:16 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/issue-with-updating-email-with-scim-provisioning/m-p/127340#M3809</guid>
      <dc:creator>VasylS</dc:creator>
      <dc:date>2025-08-04T14:10:16Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with updating email with SCIM Provisioning</title>
      <link>https://community.databricks.com/t5/administration-architecture/issue-with-updating-email-with-scim-provisioning/m-p/127671#M3826</link>
      <description>&lt;P&gt;For anyone who will face this issue in the future:&lt;BR /&gt;&lt;BR /&gt;In order to fix this issue (user changed his email), you need:&lt;BR /&gt;1) Because email is an&amp;nbsp;immutable attribute - check in Databricks account console, affected user's account, and if it has an&amp;nbsp;old email - delete the&amp;nbsp;user with the&amp;nbsp;old email.&lt;BR /&gt;2) Determine the&amp;nbsp;correct Enterprise application SCIM Connector (if you have multiple).&lt;BR /&gt;3) Stop and restart synchronization of the&amp;nbsp;SCIM Connector&lt;BR /&gt;Check synchronization logs and that user appeared back in&amp;nbsp;Databricks account console.&lt;BR /&gt;&lt;BR /&gt;No need to make any changes with user account in Azure EntraID.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Aug 2025 13:45:08 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/issue-with-updating-email-with-scim-provisioning/m-p/127671#M3826</guid>
      <dc:creator>VasylS</dc:creator>
      <dc:date>2025-08-07T13:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with updating email with SCIM Provisioning</title>
      <link>https://community.databricks.com/t5/administration-architecture/issue-with-updating-email-with-scim-provisioning/m-p/136844#M4315</link>
      <description>&lt;P&gt;I believe we have tried this move before, and the result was that the user was ignored from future SCIM provisioning runs. We had to manually use the API to add the user back in and are now hooked into manually updating this users user groups through the API.&lt;BR /&gt;&lt;BR /&gt;Has this functionality changed?&lt;BR /&gt;The docs still say that this is the expected functionality. Dot point 3 under provisioning tips here:&amp;nbsp;&lt;A href="https://docs.databricks.com/aws/en/admin/users-groups/scim/aad#provisioning-tips" target="_blank"&gt;Configure SCIM provisioning using Microsoft Entra ID (Azure Active Directory) | Databricks on AWS&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 23:43:58 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/issue-with-updating-email-with-scim-provisioning/m-p/136844#M4315</guid>
      <dc:creator>dbx_user</dc:creator>
      <dc:date>2025-10-30T23:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with updating email with SCIM Provisioning</title>
      <link>https://community.databricks.com/t5/administration-architecture/issue-with-updating-email-with-scim-provisioning/m-p/136987#M4320</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/167090"&gt;@dbx_user&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;I believe we have tried this move before, and the result was that the user was ignored from future SCIM provisioning runs. We had to manually use the API to add the user back in and are now hooked into manually updating this users user groups through the API.&lt;BR /&gt;&lt;BR /&gt;Has this functionality changed?&lt;BR /&gt;The docs still say that this is the expected functionality. Dot point 3 under provisioning tips here:&amp;nbsp;&lt;A href="https://docs.databricks.com/aws/en/admin/users-groups/scim/aad#provisioning-tips" target="_blank" rel="noopener"&gt;Configure SCIM provisioning using Microsoft Entra ID (Azure Active Directory) | Databricks on AWS&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/167090"&gt;@dbx_user&lt;/a&gt;&amp;nbsp; "The removed user will not be synced again using Microsoft Entra ID provisioning, even if they remain in the enterprise application."&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Well, after stopping and resuming sync in&amp;nbsp;the Enterprise application, the deleted user was synced again.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2025 13:41:02 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/issue-with-updating-email-with-scim-provisioning/m-p/136987#M4320</guid>
      <dc:creator>Vasyl_S</dc:creator>
      <dc:date>2025-10-31T13:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with updating email with SCIM Provisioning</title>
      <link>https://community.databricks.com/t5/administration-architecture/issue-with-updating-email-with-scim-provisioning/m-p/137090#M4323</link>
      <description>&lt;P&gt;The other option is to raise a ticket with Databricks Accounts team. Our Databricks team worked on the backend and the new email was synced.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2025 17:09:09 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/issue-with-updating-email-with-scim-provisioning/m-p/137090#M4323</guid>
      <dc:creator>nayan_wylde</dc:creator>
      <dc:date>2025-10-31T17:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with updating email with SCIM Provisioning</title>
      <link>https://community.databricks.com/t5/administration-architecture/issue-with-updating-email-with-scim-provisioning/m-p/138049#M4423</link>
      <description>&lt;P&gt;Ok right, thankyou for that, this was recently? I think it was about a year ago when we first saw this.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Did you have to delete the user with the API or could you still delete from console? Our SCIM set up has the user as 'SCIM managed' so we can only make alterations to the user with SCIM api.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2025 23:15:26 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/issue-with-updating-email-with-scim-provisioning/m-p/138049#M4423</guid>
      <dc:creator>dbx_user2</dc:creator>
      <dc:date>2025-11-06T23:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with updating email with SCIM Provisioning</title>
      <link>https://community.databricks.com/t5/administration-architecture/issue-with-updating-email-with-scim-provisioning/m-p/138096#M4424</link>
      <description>&lt;P&gt;I've deleted the user from the Databricks account console. We had multiple occurrences of this one (user changed e-mail) 2 months ago and 1 week ago.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Nov 2025 10:54:17 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/issue-with-updating-email-with-scim-provisioning/m-p/138096#M4424</guid>
      <dc:creator>Vasyl_S</dc:creator>
      <dc:date>2025-11-07T10:54:17Z</dc:date>
    </item>
  </channel>
</rss>

