ADA-C01 exam dumps

ADA-C01 practice question 126 of 565

SnowPro® Advanced: Administrator. Professional level, Snowflake. Free question with the correct answer and a full explanation.

ADA-C01 Question 126

Single answerEnable, configure, and manage SCIM integration

A company is integrating Microsoft Entra ID with Snowflake to automate user and role provisioning for a new analytics business unit. The Snowflake account already has a custom security integration for SCIM, and initial provisioning worked. However, when the IAM team tries to update user attributes and assign new groups in Entra ID, provisioning begins to fail for some objects. Investigation shows the SCIM access token used by Entra ID was generated months ago by an administrator who has since left the company, and that user account has been disabled in Snowflake. The security team wants the fastest remediation that restores provisioning and aligns with Snowflake best practices for ongoing SCIM management. Which action should the Snowflake administrator take?

  1. A

    Generate a new SCIM access token using a dedicated service user with the ACCOUNTADMIN role, update the token in Entra ID, and retain the existing SCIM security integration.

  2. B

    Re-enable the departed administrator's Snowflake user temporarily so the old SCIM token becomes valid again, then rotate it later during the next maintenance window.

  3. C

    Drop and recreate the SCIM security integration so Snowflake issues a new endpoint URL and automatically re-establishes trust with Entra ID.

  4. D

    Create a new SAML2 security integration for Entra ID and use its token for SCIM provisioning, because SAML and SCIM tokens are interchangeable for identity lifecycle operations.

Show answer and explanation

Correct answer: A

Explanation

This scenario tests practical administration of Snowflake SCIM integrations. In Snowflake, SCIM provisioning is configured through a SCIM security integration, and the identity provider uses a SCIM access token generated in Snowflake to authenticate provisioning requests. A key operational detail is that the token is associated with the Snowflake user who generated it. If that user is disabled or otherwise unavailable, provisioning can fail. The recommended remediation is to generate a replacement token using a dedicated service user and update the identity provider configuration, rather than relying on a personal admin account. This aligns with Snowflake best practices for service continuity, auditability, and least privilege. Relevant Snowflake documentation includes guidance on SCIM security integrations, generating SCIM access tokens, and using dedicated service principals or service users for automated identity lifecycle management.

  • A. Correct.

    Correct. Snowflake SCIM provisioning uses an OAuth bearer token associated with the user who generated it. If that Snowflake user is disabled, the SCIM token can no longer be used successfully for provisioning operations. Best practice is to generate the SCIM access token from a dedicated service user rather than from an individual administrator account, then update the identity provider configuration to use the new token. Retaining the existing SCIM security integration is appropriate if the integration itself is correctly configured.

  • B. Incorrect.

    Incorrect. Temporarily re-enabling a former administrator to restore an old token is operationally risky and conflicts with least-privilege and service-account best practices. It may restore service briefly, but it does not address the root cause: the token is tied to a disabled personal account. Snowflake guidance favors using a dedicated service user for SCIM token generation.

  • C. Incorrect.

    Incorrect. Recreating the SCIM security integration is not the fastest or most appropriate remediation when the failure is due to an invalid token tied to a disabled Snowflake user. The integration object and endpoint can remain valid; the problem is the bearer token used by the identity provider. Recreating the integration would add unnecessary change risk.

  • D. Incorrect.

    Incorrect. SAML security integrations are used for authentication/SSO, not for SCIM lifecycle provisioning. Snowflake SCIM provisioning requires the SCIM security integration and an associated SCIM access token. SAML and SCIM serve different functions and their tokens are not interchangeable.

Timed practice exam

Take a ADA-C01 practice test under exam conditions

65 questions in 115 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam