License Portal

How SCIM Provisioning Behaves in AQT

Understand how AQT applies SCIM provisioning, seats, removals, and managed exceptions.

Table of Content

This article is intended for workspace Owners and Admins who have set up, or are setting up, SCIM provisioning. For the setup steps themselves, please see the guide for your provider: Setting Up Single Sign-On and Provisioning with Microsoft Entra ID, Setting Up Single Sign-On and Provisioning with Okta, or Setting Up Single Sign-On and Provisioning with Your Identity Provider.

This article describes how AQT behaves once provisioning is running: what it will and will not change, what happens when you run out of seats, how removing people works, and how to handle individuals who need to sit outside provisioning.

What Provisioning Will Not Change

  • Ownership. No group can make somebody an Owner. Please contact support to change who owns a workspace.

  • Accounts on unverified domains. If someone’s address is on a domain you have not verified, they are left as they are and stay password- or invitation-managed. The request still succeeds, and the user is listed under the declined and ignored entries. Verify the domain and they are picked up on the next sync.

  • Users who belong to another organization’s workspace. That is a conflict, and nothing changes on either side.

  • Anything you set by hand. A license group or role assigned manually is not overwritten by provisioning. Only something a mapping granted can be taken back by a mapping.

Existing Accounts

Provisioning never creates a duplicate account. If a user already has an AQT account, from a Just-In-Time sign-in or a manual invitation, SCIM links to the existing account instead of creating a new one, and their entitlements are then worked out from their group memberships.

Running Out of Seats

Nothing breaks when seats run out, and nobody is rejected. Users are still created and can still sign in. They cannot activate AQT One until they hold a license, and they are listed as awaiting a seat.

AQT tells your provider the request succeeded. This is intentional: returning a failure makes most providers retry for weeks and eventually suspend the whole synchronization, which would also stop people who have left from being removed.

Free or buy a seat and waiting users are assigned automatically, usually within fifteen minutes, and immediately if you free the seat yourself. Nothing needs re-running in your directory.

AQT emails your administrators once when this starts, and again only if the reason changes, rather than once per affected person.

Removing People

Marking someone inactive in your directory releases their license, clears their activations and signs them out. They stay in your workspace, keep their role and group memberships, and return exactly as they were if you reactivate them.

Deleting them from the application in your directory detaches them from your workspace entirely, releasing license, role and memberships. Their account itself survives, and anything they bought personally stays theirs.

Either way, someone who comes back returns to the same account rather than a new one, and their entitlements are worked out fresh from their group memberships.

Nothing here runs on a timer. A user who is inactive for a long time is never detached automatically.

Individual Exceptions

Occasionally someone needs to sit outside provisioning: a contractor, a shared account, someone mid-transfer. A workspace Owner can mark an individual as managed in AQT instead, and provisioning then leaves their license group and role alone. Turn it off and they are worked out from your groups again.

This is restricted to Owners deliberately. The mark freezes a role that would otherwise be lowered, so an Administrator able to apply it to themselves could keep Administrator access after leaving the group that granted it.