The PingAuthorize sample user data allows an employeeType attribute but does not populate it with values for any users.

Confirm that user.2 cannot read the description attribute, even though the profile scope allows it, by running the following command.

curl --insecure -X GET https://localhost:7443/scim/v2/Me -H 'Authorization: Bearer {"active": true, "sub": "user.2", "scope": "profile", "client_id": "client1", "aud": ""}'

The response should be similar to the following response.
