getsentry / getsentry/sentry

[Azure SCIM] User removed from group in azure not deleted from Sentry when identity is not linked.

Open
#85,832 2 comments 0 reactions 0 assignees View on GitHub
Product Area: Settings - Auth
Dominant language
Python
Stars
44.8k
Forks
4.9k
Avg merge
22h 21m
Merged PRs (30d)
586

Description

### Environment

SaaS ([https://sentry.io/]())

### Steps to Reproduce

1. Integrate SSO with Azure in Sentry
2. Configure SCIM provisioning
3. Add users to an Azure group and provision them to Sentry.
4. The user gets invited to Sentry and added to the correct team.
5. Remove the user from the group without the user having an Azure identity linked to the Sentry user.

### Expected Result

The user is removed from the team and from Sentry (if not a member of any other group assigned to Sentry in Azure) as per the documentation:

> As a result of these changes, users who are assigned will be sent an invitation email. When a user is un-assigned, their membership object in Sentry will be deleted.

### Actual Result

The user remains unchanged in Sentry.

This seems to happen when a user is a Member of the organisation but has no Azure identity linked. The SCIM provisioning settings are set to delete users in Sentry. It is confirmed that the user is not assigned to a provisioned group (screenshot below).

The team settings in Sentry show the user's membership controlled by SCIM, it is not possible to manually remove the user from the Team, it can only be done via SCIM.

Information on the affected user and organisation is available in the internal ticket: [https://sentry.zendesk.com/agent/tickets/145754]()
Relevant screenshots:

Image

![Image](https://uploads.linear.app/3ed206af-f87a-40aa-82a0-150bf83e43e6/99f9860a-19e8-4877-8562-d4d1b7eb7219/20dab2a4-9b4e-4d8a-892b-17021f66224e?signature=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJwYXRoIjoiLzNlZDIwNmFmLWY4N2EtNDBhYS04MmEwLTE1MGJmODNlNDNlNi85OWY5ODYwYS0xOWU4LTQ4NzctODU2Mi1kNGQxYjdlYjcyMTkvMjBkYWIyYTQtOWI0ZS00ZDhhLTg5MmItMTcwMjFmNjYyMjRlIiwiaWF0IjoxNzczOTU0NDg3LCJleHAiOjE4MDU1MjUwNDd9.3gD4df4bKq8HSVDjDPv2e1YMEG2QLDPF5In1C2CBmzo)

### Product Area

Settings - Auth

### Link

*No response*

### DSN

*No response*

### Version

*No response*

Contributor guide

Open the contributing guide

Research direction

Start in the Settings - Auth area and trace Azure SCIM provisioning for users removed from assigned groups when no Azure identity is linked. Reproduce the listed sequence and verify that the user is removed from the team and Sentry when no other assigned group grants membership.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure
Domain
authentication, authorization
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.