Allow change team for SCIM users #245

Closed
opened 2026-04-05 16:19:10 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @arthur-lbchn on 11/27/2025

Is your feature request related to a problem? Please describe.

When Entra ID is used for SCIM, the system restricts the ability to manipulate default groups and users, even when the "Push Groups" setting is disabled in the SCIM configuration.

Currently, all users synced from Entra ID are automatically created in the "Members" team by default. However, we have specific users (e.g., DevOps) who need to be promoted to the Admins or Owners team. Because the UI locks down group management when SCIM is active, we cannot manually promote these users, and since we are not pushing groups from Entra ID, there is no way to assign these roles:

Image Image

Describe the solution you'd like

If "Push Groups" is disabled, the system should allow local administrators to manually manage team assignments and roles (e.g., promoting a synced user to Owner), as the identity provider is not managing group membership.

Image
*Originally created by @arthur-lbchn on 11/27/2025* **Is your feature request related to a problem? Please describe.** When Entra ID is used for SCIM, the system restricts the ability to manipulate default groups and users, even when the "Push Groups" setting is disabled in the SCIM configuration. Currently, all users synced from Entra ID are automatically created in the "Members" team by default. However, we have specific users (e.g., DevOps) who need to be promoted to the Admins or Owners team. Because the UI locks down group management when SCIM is active, we cannot manually promote these users, and since we are not pushing groups from Entra ID, there is no way to assign these roles: <img width="1016" height="664" alt="Image" src="https://github.com/user-attachments/assets/a70866be-3dcc-4469-96f9-2cebfa30b630" /> <img width="1024" height="392" alt="Image" src="https://github.com/user-attachments/assets/67cc1020-7538-4981-9081-0836772f06a9" /> **Describe the solution you'd like** If "Push Groups" is disabled, the system should allow local administrators to manually manage team assignments and roles (e.g., promoting a synced user to Owner), as the identity provider is not managing group membership. <img width="2406" height="664" alt="Image" src="https://github.com/user-attachments/assets/4c884f4d-1a21-4688-9019-91c4093e312a" />
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/oneuptime#245