SUPPORT.TWILIO.COM END OF LIFE NOTICE: This site, support.twilio.com, is scheduled to go End of Life on February 27, 2024. All Twilio Support content has been migrated to help.twilio.com, where you can continue to find helpful Support articles, API docs, and Twilio blog content, and escalate your issues to our Support team. We encourage you to update your bookmarks and begin using the new site today for all your Twilio Support needs.

Troubleshooting User Roles Reverting to Unchecked Status in Access Management

Issue

When attempting to grant a user specific access roles (such as Warehouse Admin) in the Segment workspace Access Management settings, the checkbox reverts back to Unchecked after saving or switching pages. Manually assigned roles or user groups are not persisting for the user.

 

Product

Segment

 

Environment

Segment Console

 

Cause

This behavior occurs when the workspace has SCIM (System for Cross-domain Identity Management) auto-provisioning enabled for Single Sign-On (SSO). When SCIM is active, the external Identity Provider (IdP), such as Okta or Azure AD, acts as the absolute source of truth for user identities and group memberships. Any manual changes made directly in the Segment Console will be automatically overwritten and reverted by the active sync to match the IdP's configuration.

 

Resolution

To resolve this issue and successfully grant permissions to a user, roles must be managed using IdP groups rather than individual assignments in the Segment Console.

Follow these steps to grant access:

  1. In your Identity Provider (e.g., Okta), assign the user to a specific Group designed for the desired Segment access level.
  2. Ensure that this Group is configured to push to Segment via SCIM.
  3. Log in to the Segment Console and navigate to Settings > Workspace Settings > Access Management.
  4. Select the User Groups tab.
  5. Locate the newly synced Group from your IdP, click Edit User Group, and manually assign the desired roles (e.g., Warehouse Admin, Source Admin) to this group.

Once the IdP syncs, the user will inherit the permissions assigned to the group in the Segment Console without reverting.

 

Additional Information 

  • When your IdP pushes a new group to Segment via SCIM, that group automatically starts with the default "Minimal Workspace Access". This baseline permission does not grant access to any sources, destinations, or other resources. You must always manually assign the initial roles to the group within the Segment Console.
  • Any Segment group memberships must be reassigned when a user is removed and re-added from your workspace.
Have more questions? Submit a request
Powered by Zendesk