Q: 8
You created the Netskope application in your IdP for user provisioning and validated that the API
Integration settings are correct and functional. However, you are not able to push the user groups
from the IdP into your Netskope tenant.
Options
Discussion
Option D
Probably A. In some practice tests, group sync failures could be tied to deactivated users in IdP groups. Official guide touches on this but I'm not 100% sure, so check documentation to confirm.
I don't think it's A, D is the real issue here since with SCIM you must provision users before groups.
C/D? Technically, if you try to push a group before its users exist in Netskope, SCIM won’t map group membership correctly. But if the IdP had missing create permissions (B), user creation would fail outright. Pretty sure D is right unless some other condition is tripping it up. Someone disagree?
C/D? I usually see group syncs fail if users aren't in Netskope yet, so D matches most SCIM setups. But B about permission could mess things up too, just not in this exact sequence I think. SCIM wants user objects present before group objects reference them. Not 100% locked on D though, happy to hear other takes.
D makes sense here. With SCIM you have to make sure users get pushed to Netskope before the groups, otherwise group provisioning fails since it can't map the users. Pretty common SCIM gotcha honestly, but open to other takes.
D imo. A is tempting but it's really a SCIM order thing, users need to be present first or group sync fails.
D not A. In SCIM, if you push the group before users exist in Netskope, group sync fails. A looks like a trap since deactivated users aren't the main issue here. Pretty sure it's D based on similar exam questions, but open to arguments.
A
Makes sense to me, D. Users need to be in Netskope first before you can sync the groups.
Be respectful. No spam.