We are facing account creation failure in CyberArk PAM Connector where we are trying to add a user to safe which worked prior after an upgrade to SCIM Connector. The versions are PVWA 14.6 and SCIM v1.26.4.14
The error is : java.io.IOException: {“schemas”:[urn.ietf.params.scim.api.messages.2.0.Error] status 500, detail: Unable to add LDPA user. Failed to add as a safe member.
Note: CyberArk is mapped to okta to fetch user details which SailPoint is using in create provisioning form as NativeIdentifier and UserName.
The issue got resolved as we connected with both SailPoint and CyberArk vendors.
SCIM log revealed that SailPoint request contained duplicate member entries in the group payload, causing conflict error for existing group members. Hence CyberArk vendor suggested to install latest SCIM version v1.26.4.14, this version handles the duplicate member entries in the payload when updating groups.
Also, LDAP Bind user password must be correct.