← SC-300: identity, access, and operations
08 / 11 · 40 MIN

Objects, attributes, and external lifecycle

Resolve attribute permissions, partial imports, and recreated guests.

Attributes with their own permissions

Custom security attributes have separate permissions for definition, assignment, and reading. Global Administrator does not grant value access by default. In a fictional migration team, an operator sees a user but cannot read an internal classification field; check the attribute role and set scope before changing the schema. If the task is assigning an existing value, identify the appropriate assignment permission. These attributes are not automatically SAML or JWT claims. The application contract must identify how it obtains and uses the data.

Imports with partial failures

A CSV import needs reconciliation by row. Download the current template, preserve required columns, and inspect operation results. In a fictional batch of 100 people, 97 accounts appear and three fail. Identify those three rows and their errors, confirm the objects already created, and prepare a limited correction. Resubmitting everything without control creates conflicts and obscures diagnosis. Keep a record without passwords containing identifiers, state, owner, and deadline for pending cases; account creation does not confirm licensing or application access.

What can recreate a guest

Cross-tenant synchronization can provision a user again after target deletion while that user remains in source scope. Imagine a review removing a supplier guest and the object returning during the next shift. Inspect the source, configuration, and provisioning logs before repeating deletion. A durable correction must align authorized synchronization scope with the review outcome. The target team remains responsible for local resources; the source team controls the synchronized population. Record both owners and check the following cycle to confirm the intended state persists.

Partner federation and resource access

SAML or WS-Fed federation lets a partner authenticate users through its identity provider. Configuration includes issuer, endpoint, and certificate; redemption order can also matter in B2B flows. In a fictional onboarding, first establish which IdP received the request and whether the invitation followed the expected redemption path. Then check application assignment. Valid authentication does not establish that the user has the required business role. Plan certificate renewal and an access check after the change, with both organizations involved in acceptance.

IN PRACTICE

In a fictional project, 97 of 100 accounts were created and a removed guest returned. Treat the import and synchronization scope as two separate causes.

Common pitfalls

Repeat the entire batch; confuse an attribute with a claim; remove only at the target; treat federation as authorization.

Related topics: Tenant, scope, and objects · Hybrid identity and partners · Methods and emergency access

Take this idea with you

Follow the object, permission, and source determining state.

Create account

Reference: Custom security attributes · SC-300 objectives effective 2026-04-27; product documentation reviewed 2026-10-01; 2026-10-28 English update compared separately