Use PDIs? Take our 5-minute survey to help shape the PDI roadmap.

Impact of Disabling OOB SAML Auto-Provisioning Transform Map Used by Azure/Entra ID SSO

Pavan S
Tera Contributor
 
Hi Team,
 
we're investigating whether it is safe to disable the OOB SAML Auto-Provisioning transform map (u_imp_saml_user_3tfrn5kmdn → sys_user) used by our Azure/Entra ID SSO configuration.
We've observed that records are being inserted into the source import table by the Guest user during SAML login, and the transform map contains only basic mappings (email, user_name, first_name, sso_source) along with simple onBefore/onAfter scripts. The onAfter script appears to only send SAML.User.AutoProvisioning.Create/Update telemetry events and does not update any records. We are trying to understand whether this transform map is actively used for Just-In-Time (JIT) user provisioning or user attribute updates during SSO login. If we disable the transform map, would it impact existing user logins, new user creation, user profile updates, or any SAML/MFA-related functionality? Also, does this transform send any information back to Azure AD/Entra ID or MFA providers, or is it only used internally within ServiceNow for user provisioning and analytics? We're seeing a very high volume of Import Set Runs associated with this table and want to understand the potential impact before considering deactivation. Can anyone help me on this.
0 REPLIES 0