SCIM provisioning is an emerging concept in the world of identity and access management, and it has the potential to redefine the way we create and manage user accounts in web applications.<\/p>\n\n\n\n
One report noted that the average company spent 78% more<\/a> on Software-as-a-Service in 2018 than the year prior, and the trend is continuing upward. With the explosion of SaaS and web apps, it\u2019s important to understand how to streamline user management across those resources and what new tools can play a role.<\/p>\n\n\n\n
SCIM provisioning is a cloud-based identity management solution that enables organizations to efficiently manage user identities and access rights across various applications and systems. With SCIM provisioning, companies can easily add or remove users, grant or revoke access rights, and streamline workflows. This not only improves security and compliance but also reduces costs and enhances operational efficiency. By implementing SCIM provisioning, companies can ensure seamless integration with third-party cloud services and applications, simplify user management, and improve overall productivity.<\/p>\n\n\n\n
SCIM was first known<\/a> as \u201cSimple Cloud Identity Management\u201d \u2014 and it was born out of developers\u2019 desire to standardize web application identity management.<\/p>\n\n\n\n
In the early 2010s, standards existed to authenticate and authorize online users, but a standard didn\u2019t exist to create users in various online services, SCIM co-creator Kelly Grizzle told an audience<\/a> at the Austin API Summit in 2018. He and other co-creators set out to address what they saw as a gap in the industry and to centralize identities used to access web apps.<\/p>\n\n\n\n
SCIM is now recognized by the the Internet Engineering Task Force (IETF), and its creators have, since its earliest draft schema<\/a>, made clear what its purpose is: \u201cIn essence, make it fast, cheap, and easy to move identity in to, out of, and around the cloud.\u201d<\/p>\n\n\n\n
There are various benefits of SCIM provisioning, including: <\/p>\n\n\n\n
With SCIM, admins no longer need to manually create and delete user accounts in web apps \u2014 which saves them valuable time and reduces the chance for errors in the authorization levels granted to users.<\/p>\n\n\n\n
It\u2019s important to note that SCIM provisioning differs in both its implementation and output from another type of web app provisioning, Just-in-Time<\/a>.<\/p>\n\n\n\n
Just-in-Time provisioning is an extension of the SAML protocol and automates user provisioning. In this configuration, user accounts are created the first time they try to log in to an application via SAML assertions that pass the attributes required for account creation.<\/p>\n\n\n\n
SCIM, on the other hand, does not use SAML. Instead, it standardizes the way objects are represented among web applications. Beyond that, it automates not only user provisioning but also the modification and deletion of user accounts through an ongoing sync between the identity provider and linked service providers.<\/p>\n\n\n\n
For example, if an employee quits, an admin can deprovision them in the identity provider, and that change will propagate to SCIM-enabled web applications and automatically delete the accounts there, too. JIT provisioning does not provide these capabilities.<\/p>\n\n\n\n
Both JIT and SCIM can be implemented through a web application single sign-on (SSO) solution, though. At this point, SAML JIT<\/a> provisioning is far more widely adopted than SCIM provisioning, though we anticipate the adoption of SCIM will continue to grow because of the benefits it provides to organizations.<\/p>\n\n\n\n
If you\u2019re looking to implement SSO, including SCIM, in your organization, our SSO buying guide<\/a> is a good place to start. You can also try the JumpCloud\u00ae<\/sup> SSO offering, now including SCIM for Slack<\/a>, absolutely free. <\/p>\n\n\n\n
Simply sign up for a JumpCloud account<\/a> and start leveraging SSO with SCIM today. <\/p>\n","protected":false},"excerpt":{"rendered":"