How to Review Entra Provisioning Service Permissions After August 2026 Patch Tuesday
August 2026's Entra ID fixes included a critical elevation-of-privilege flaw in the Entra Provisioning Service. Even though Microsoft fixed it server-side, it's a good moment to review provisioning permissions in your tenant.
What the provisioning service does
Entra provisioning creates, updates and removes accounts automatically:
- HR-driven inbound provisioning (Workday, SuccessFactors, API-driven) into Entra ID or Active Directory.
- Outbound app provisioning (SCIM) to SaaS applications.
- Cross-tenant synchronization between your tenants.
- Entra Connect / cloud sync between Active Directory and Entra ID.
Each can create users, change attributes and modify group memberships — powerful capabilities.
Step 1: Inventory provisioning jobs
In the Entra admin center, review Enterprise applications with provisioning configured, cross-tenant synchronization configurations, and Entra Connect / cloud sync settings.
Step 2: Review scope
For each job:
- Which users and groups are in scope?
- Which attributes are written, and could any affect access (for example, group memberships, manager, department used in dynamic groups or Conditional Access)?
- Can it create privileged users or add users to privileged groups?
Step 3: Review credentials
- SCIM tokens and secrets: who has them, where are they stored, when do they expire?
- API-driven provisioning apps: which permissions (for example,
SynchronizationData-User.Upload)?
Step 4: Restrict administration
Limit who can configure provisioning (Application Administrator, Hybrid Identity Administrator) and manage those roles with PIM.
Step 5: Monitor
- Provisioning logs for unexpected creates and updates.
- Audit logs for provisioning configuration changes.
- Alerts when provisioning adds users to privileged groups.
Step 6: Protect privileged groups
Use role-assignable groups (which only privileged roles can manage) for groups that grant admin access, and exclude them from provisioning scope.