User Provisioning with SCIM: What Actually Works
A standard for automatically creating, updating and disabling user accounts from a customer's identity system.
The key figures
- Standard
- SCIM defines a protocol for managing identities
- Automation
- joiners, movers and leavers are handled automatically
- Deprovisioning
- removes access when people leave
- Groups
- SCIM can synchronize group membership
Why this is worth getting right
Manual account management breaks down at scale, and stale accounts are a security risk.
Do this, not that
Do
- Implement SCIM for enterprise customers
- Handle deactivation as well as creation
- Map groups to roles deliberately
- Log provisioning actions
- Test with real identity providers
Don’t
- Manual account creation for large customers
- Ignoring deactivation events
- Silent failures in synchronization
- Custom provisioning APIs per customer
When to bring in help
Our advice Bring in help when enterprise customers require automated provisioning.
Where this comes from
- RFC Editor — RFC 7644 System for Cross-domain Identity Management
- Microsoft Learn — User provisioning
The figures and practices above come from the sources listed.
Working on something like this?
We take on Web Design & Development work for teams who want it done once, properly. Tell us what you are building and we will tell you honestly whether we are the right studio for it. Start a project.
Where to go next
Spotted something wrong? Report an error on this page. We correct on the page and say what changed.