Google Workspace AutoProivisionsing Office 365

E8419
New Contributor III

Hello

 

I think this was talked about on the currents community before, but I am having an issue which MS says is a Google issue(which I tend to believe) and Google says its an MS issue, so I am hoping you can help me.

I have created the SAML app for Office 365 and I have auto provisioning on.  I have it mapped to a group.  Anyone I add to a certain group gets auto provisioned in Office 365 in the Azure portal.

I had to hard delete a users account from Azure and now no matter what I do they are not reprovisioning from Workspace -> Azure.  I have removed and added them to the provisioning group in Workspace.  Made no difference.

I have looked for a colliding Immutable ID, can't find one.

I feel Workspace auto provisioning is not resending them over to be reprovisioned.  I am unsure how to prompt that to happen again.  MS said try changing an attribute on the Workspace side, but that has not repormpted the creation.

 

Any help would be appreciated.

 

 

3 REPLIES 3

Kim_Nilsson
Admin Moderator

I know exactly why that is.

I also have a "fix" for such a broken user.

I'll post a link to the process here whenever I'm back at my computer. Maybe later tonight or tomorrow.

--
https://wheretofind.me/@NoSubstitute

Kim_Nilsson
Admin Moderator

Ah, found the bookmark!

https://peppercrew.nl/2019/07/g-suite-sso-provisioning-accounts-with-azure-ad-and-manually-deleted-a...

The process is to create a new user in O365 with the reference to the existing user in Workspace. It will then semi-connect with Workspace and work for future login.

There's nothing that can be done to avoid this, so do your very best to NOT delete users in O365, ever. Only ever delete them on the Workspace side.

--
https://wheretofind.me/@NoSubstitute

E8419
New Contributor III

Thank you so much!  That did it and now I have bookmarked it too, not that I will ever delete a Google Federated user from Azure again!