CyberArk User Provisioning Fails

I am receiving the following error when trying to create a CyberArk user:
java.io.IOException: {“schemas”:[“urn:ietf:params:scim:api:messages:2.0:Error”],“status”:400,“detail”:“user data is required”}

I am using the IIQ 8.3 PAM module to connect to CyberArk SCIM2 Server v1.25.5.7. I’m attempting to create the user with the Manage Accounts Quicklink using the default provisioning form provided by the PAM server application configuration. Following is an example of the provisioning plan capture by a Before Provisioning rule:

<!DOCTYPE ProvisioningPlan PUBLIC “sailpoint.dtd” “sailpoint.dtd”>
<ProvisioningPlan nativeIdentity=“john.doe” targetIntegration=“CyberArk PAM Server 2” trackingId=“0e753549135d41c19139449ebde39d5c”>
<AccountRequest application=“CyberArk PAM Server 2” op=“Create”>
<Attributes>
<Map>
<entry key=“flow” value=“AccountsRequest”/>
<entry key=“interface” value=“LCM”/>
<entry key=“operation” value=“Create”/>
</Map>
</Attributes>
<AttributeRequest name=“userName” op=“Set” value=“john.doe”/>
<AttributeRequest name=“name.formatted” op=“Set” value=“john.doe”/>
<AttributeRequest name=“name.familyName” op=“Set” value=“Doe”/>
<AttributeRequest name=“name.givenName” op=“Set” value=“John”/>
<AttributeRequest name=“displayName” op=“Set” value=“john.doe”/>
<AttributeRequest name=“emails.work.value” op=“Add” value=“john.doe@example.com”/>
</AccountRequest>
<Attributes>
<Map>
<entry key=“identityRequestId” value=“0000000027”/>
<entry key=“requester” value=“spadmin”/>
<entry key=“source” value=“LCM”/>
</Map>
</Attributes>
<Requesters>
<Reference class=“sailpoint.object.Identity” id=“0ab82da68e761ecb818e7660519a00ea” name=“spadmin”/>
</Requesters>
</ProvisioningPlan>

I am able to successfully provision a delete operation but not create. Has anyone else run into this issue or have an idea how to troubleshoot the root cause? The error message seems to indicate the payload is missing for a /Users POST operation, but I don’t understand why.

Hi  @dowella  ,
I didn’t work for Cyberark but I could integrate BeyondTrust and everything was working perfectly.
I checked the plan you have provided with this Add user

Cyber documentation and found few things are missing
can you validate all the attributes mentioned here are available?

If attributes are missing you can add and try
Thanks

I found the issue. The “CyberArk PAM Server 2” application XML provided by CyberArk as part of the SCIM Sever installation files does not include a password attribute in the provisioning policy. Once I added it, account creation worked.

<Form name=“Create Account Form” objectType=“account” type=“Create”>
<Attributes>
<Map>
<entry key=“pageTitle” value=“Create Account Form”/>
</Map>
</Attributes>
<Description>Provisioning form for create account.</Description>
<Section>
<Field displayName=“User Name” name=“userName” required=“true” reviewRequired=“true” type=“string”/>
<Field displayName=“Formatted Name” name=“name.formatted” reviewRequired=“true” type=“string”/>
<Field displayName=“Family Name” name=“name.familyName” reviewRequired=“true” type=“string”/>
<Field displayName=“Given Name” name=“name.givenName” reviewRequired=“true” type=“string”/>
<Field displayName=“Display Name” name=“displayName” reviewRequired=“true” type=“string”/>
<Field displayName=“Email” name=“emails.work.value” reviewRequired=“true” type=“string”/>
<Field displayName=“Active” name=“active” type=“boolean” value=“true”/>
<Field displayName=“Location” name=“location” type=“string” value=“"/>
<Field displayName=“cyberarkUserType” name=“cyberarkUserType” type=“string” value=“EPVUser”/>
<Field displayName=“Password” name=“password” type=“secret” value=”***********"/>
</Section>
</Form>