I am receiving the following error when trying to create a CyberArk user:
java.io.IOException: {“schemas”:[“urn:ietf:params:scim:api:messages:2.0:Error”],“status”:400,“detail”:“user data is required”}
I am using the IIQ 8.3 PAM module to connect to CyberArk SCIM2 Server v1.25.5.7. I’m attempting to create the user with the Manage Accounts Quicklink using the default provisioning form provided by the PAM server application configuration. Following is an example of the provisioning plan capture by a Before Provisioning rule:
<!DOCTYPE ProvisioningPlan PUBLIC “sailpoint.dtd” “sailpoint.dtd”>
<ProvisioningPlan nativeIdentity=“john.doe” targetIntegration=“CyberArk PAM Server 2” trackingId=“0e753549135d41c19139449ebde39d5c”>
<AccountRequest application=“CyberArk PAM Server 2” op=“Create”>
<Attributes>
<Map>
<entry key=“flow” value=“AccountsRequest”/>
<entry key=“interface” value=“LCM”/>
<entry key=“operation” value=“Create”/>
</Map>
</Attributes>
<AttributeRequest name=“userName” op=“Set” value=“john.doe”/>
<AttributeRequest name=“name.formatted” op=“Set” value=“john.doe”/>
<AttributeRequest name=“name.familyName” op=“Set” value=“Doe”/>
<AttributeRequest name=“name.givenName” op=“Set” value=“John”/>
<AttributeRequest name=“displayName” op=“Set” value=“john.doe”/>
<AttributeRequest name=“emails.work.value” op=“Add” value=“john.doe@example.com”/>
</AccountRequest>
<Attributes>
<Map>
<entry key=“identityRequestId” value=“0000000027”/>
<entry key=“requester” value=“spadmin”/>
<entry key=“source” value=“LCM”/>
</Map>
</Attributes>
<Requesters>
<Reference class=“sailpoint.object.Identity” id=“0ab82da68e761ecb818e7660519a00ea” name=“spadmin”/>
</Requesters>
</ProvisioningPlan>
I am able to successfully provision a delete operation but not create. Has anyone else run into this issue or have an idea how to troubleshoot the root cause? The error message seems to indicate the payload is missing for a /Users POST operation, but I don’t understand why.