We currently have Single Sign-On setup with Azure AD using Provisioning. We have an overarching group called say "Everyone" that has the "end-user" role assigned. We then have a separate group called "Zendesk_Agents" that has the "agent" role assigned. We have a subset of users in each group, but when provisioning happens, the users in the group "Zendesk_Agents" do NOT get updated to the role of "agent" inside of Zendesk. We had to manually change the existing users within Zendesk to have the "agent" role.
Is this an expected behavior when a user belongs in two groups with different roles when using provisioning on the Azure AD side?
Please sign in to leave a comment.