Other: Enable SCIM Mapping of Entra ID Groups to Fivetran Team and Destination/Connector-Level Roles
Not plannedCurrent Limitation:
According to the current SCIM documentation and support feedback, Fivetran does not support configuring Team roles or Destination/Connector-level roles via SCIM. Currently, SCIM is limited to syncing identity and account-level roles only. Consequently, when users are provisioned via Microsoft Entra ID administrators must manually assign Team or Destination permissions in the Fivetran UI or use the REST API after the user has been synced.
Business Impact:
This limitation prevents fully automated user provisioning. Large organizations relying on Identity Providers (IDPs) to manage granular permissions via Groups cannot reflect these permissions in Fivetran automatically. This increases administrative overhead and the risk of human error, as users may have access to the platform but lack the specific resource permissions needed to perform their jobs until an admin manually intervenes.
-
Official comment
Hi Mohsen,
This feature—SCIM mapping of Entra ID groups to Fivetran Team and Destination/Connector-level roles—is not currently on our roadmap. Feedback and upvotes on requests like this help us gauge demand and prioritize development; every upvote on this post adds to the case for considering this capability in future planning.
To help justify potential commitment, it would be helpful to have more details about your specific use case or requirements—do you need both:
Entra ID groups --> Fivetran Team
and
Entra ID groups --> Fivetran Destination/Connector-level roles
or would one or the other suffice?In the meantime, we recommend using the Fivetran REST API or Terraform provider to automate bulk assignments.
Thanks,
Pieter
Please sign in to leave a comment.
Comments
1 comment