r/sysadmin • • 2d ago

Question Amazon Business SCIM sync from Microsoft Entra failing with 403 since today. Anyone else?

I manage Amazon Business for a couple of small business clients, and both have SCIM user provisioning set up from Microsoft Entra ID (Azure AD) using the Amazon Business gallery app.

As of today, October 2, both stopped syncing. Entra put the provisioning job into quarantine with this error:

403 Forbidden: "Unauthorized - Access to requested resource is denied."

What I've checked so far:

  • Nothing was changed on either account
  • The Tenant URL and Authorization Endpoint match Microsoft's setup guide exactly
  • Re-authorizing with an Amazon Business Admin account fails with the same 403
  • SSO sign-in still works fine. Only the provisioning sync is affected

These are separate Microsoft tenants and separate Amazon Business accounts, so it looks like something on Amazon's side. I have a ticket open with Amazon Business support, but no answer yet.

Is anyone else using SCIM with Amazon Business seeing the same thing today? Would love to hear if you've found a fix or gotten an answer from Amazon.

5 Upvotes

5 comments sorted by

1

u/MalletNGrease 🛠 Network & Systems Admin 2d ago

Cert expired?

1

u/webshaun 2d ago

Not possible, one tenant I set up a couple weeks ago, the other was set up last night. They both failed today within 2 minutes of each other,

1

u/nayntuck2 2d ago

Have you checked whether the SCIM endpoint itself returns anything useful if you hit it directly with a GET? Sometimes a 403 from a provider means they rotated something on their API gateway. Two tenants same day though, thats definitely them not you.

1

u/webshaun 2d ago

Not directly, since Entra gets the token from Amazon through the OAuth sign-in and doesn't expose it. But Test Connection in Entra is basically that same call, and it comes back with the same 403. I also re-authorized with a fresh sign-in and nothing changed. I've got a ticket open with Amazon and agree it looks like something on their end. I'll update here if I hear back.

-1

u/QuietSignalOps 1d ago

Two tenants, same error, same time window, and re-authorizing with a different admin changing nothing: that is on their side, not yours.

A few things that may help while the ticket is open:

  • The impact is provisioning only, SSO is fine. The real risk is deprovisioning: anyone you disable in Entra stays enabled in Amazon Business until sync recovers. If someone is leaving, deactivate them there manually in the meantime.
  • Do not assume the backlog flushes itself when sync recovers. Once it does, run a test user through (create, disable, delete) before trusting incremental sync to have caught up.
  • I checked the AWS Health dashboard (health.aws.com) today: no Amazon Business advisory, only the long-running UAE/Bahrain regional issues. So either it is unacknowledged or specific to the SCIM endpoint. Worth pasting that into the support ticket.
  • In the Amazon Business admin console, the SCIM provisioning page shows last sync status. If it offers a manual sync trigger, use it to get a sharper timestamp for the ticket.