Staying in Sync with External Identity Provider

I don’t believe that you’ll be able to have that going through (starting at) Auth0; in Management API v1 (Past Migrations) there’s an endpoint that could technically allow you to perform a search directly against Azure AD which could be relevant towards this scenario. However, that version of Management API is deprecated and to my knowledge there’s no counterpart to that endpoint in v2.