Hi Rihab BEN MALEK . Curious if you have been able to figure this out as we sort of have the same issue and questions. Early off we discovered the same where all users synced and caused issues, we have created individual AD groups and assigned them to the Enterprise application. therefore, when the SCIM process kicks off the users are assigned to the correct division and correct role. With that being said Onboarding is working perfectly the challenge we are having if a user changes roes and divisions. it's one of 2 scenarios what 1) the user is added to the new Azure AD group and when the SCIM process runs it just adds the role onto what the user had before "prepends it" and does not remove the previous role 2) When moving to another division the division is updated in GENESYS, but the groups are prepended. Looking at the community and supporting documentation there is no clear was to set SCIM up when having multiple divisions and multiple roles, to your point is there a need for Multiple AD Azure security groups to accurately sync account modifications such as role. changes and division changes?
------------------------------
Matt Thacker
WTI Holdings LLC
------------------------------