Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers SCIM users groups and recovery. Provision approved identities with scoped tokens while protecting company boundaries and administrator roles. Current availability: Implemented; verification required. Before you start. An authorized administrator with mandatory MFA completed. The correct company and provider permissions; keep credentials out of screenshots and chat. Step 1. Configure the intended identity provider. In Identity & SSO expand SCIM provisioning and generate its connection token. Copy it once into the provider SCIM application secret field. Step 2. Use https://connect.techlaststop.com/api/scim/v2 as the base URL. Map userName to the approved email and externalId to the exact immutable SSO subject. For Microsoft use the object identity required by the OIDC mapping; never substitute an email alias. Step 3. Assign one authorized synthetic user first. Verify the created company user is basic, within the company and paid-seat capacity. TLS staff provisioning creates a viewer; it cannot create an owner. Step 4. Before adopting an existing account, an administrator must approve its exact immutable link. Provisioning cannot take over an existing identity just because its email matches. Step 5. Test display-name update, suspension, reactivation, pagination, group add/remove and stale version rejection. Groups contain only SCIM users from the same connection and do not grant roles by themselves. Step 6. Test local deletion and its 60-day recycle entry. Protected administrators use the portal lifecycle workflow. Review a restored user and relink/reconcile its provider identity before resuming provisioning. Step 7. Review the event log, last-used time and expiry. Rotate the 90-day token and replace it in the provider. Disable the connection immediately on offboarding or suspected credential exposure. Now verify the result. Cross-company identifiers and revoked tokens are rejected. Password, role and paid-entitlement writes are rejected. Groups support up to 2,000 assigned portal users; list calls return at most 200 per page. If you get stuck. Only documented equality filters and PATCH operations are supported; SCIM bulk is not implemented. Use paginated provider provisioning. A connection token does not install or authorize an IdP application. A full multi-company membership model for one email address is not implemented. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.