Identity Security and PAM Blog for CISOs and IT Security Pros

What Is SCIM Provisioning? How It Works, Benefits, and More

Written by Schuyler Brown | Dec 12, 2022, 1:00:00 PM

Auto-provisioning via SCIM streamlines cloud identity management, increases employee productivity and reduces IT costs. So, what is SCIM?

System for cross-domain identity management (SCIM) is an open standard that simplifies cloud identity management and automates user provisioning across multiple domains. SCIM supports the exchange of user identity data between an enterprise identity provider or an identity and access management (IAM) system and cloud service providers, allowing easy access to cloud-based applications while keeping sensitive data secure. It alleviates the burden of manual provisioning and gives employees a frustration-free user experience.

What is SCIM protocol?

The SCIM protocol is an application-level standard that enables secure management and exchange of identity data across domains. Based on JavaScript object notation (JSON) and representational state transfer (REST), the SCIM standard uses REST APIs to facilitate the creation, modification, retrieval and discovery of identity resources, including users and groups.

Why is SCIM provisioning important?

The adoption of cloud-based applications has made SCIM user provisioning a core piece of identity management. With the average enterprise using nearly 1,300 cloud services, companies need a secure, cost-effective way to automate provisioning and manage the user lifecycle in the cloud. 

SCIM provides the scalability growing companies need. As organizations hire more employees and adopt more cloud-based applications, IAM becomes increasingly complex. Managing large numbers of accounts manually consumes valuable IT time, introduces errors, and impedes productivity. SCIM solves these problems and offers additional advantages.

What are the benefits of SCIM provisioning?

Perhaps the greatest benefit of SCIM is that it provides a standardized, secure methodology for exchanging information between IT systems. This gives you interoperability across domains without expensive custom integrations. 

SCIM enables single sign-on (SSO), which improves security compliance and reduces the attack surface available to malicious actors. Automating individual users’ access and SCIM group provisioning significantly reduces manual efforts and mitigates the risk of human error and zombie accounts. A modern SCIM tool simplifies employee onboarding and offboarding and provides visibility into all IT infrastructure.

SCIM auto-provisioning also increases productivity across the entire organization. Besides freeing up IT teams to focus on more valuable tasks, SCIM, in partnership with access management, reduces the time required to grant access to backend infrastructure, boosting employee productivity. Together, these benefits improve the return on investment (ROI) on IT infrastructure and reduce the total cost of ownership (TCO). 

How does SCIM work?

SCIM defines a schema for representing user and group identities and provides a REST API for managing identity lifecycles. The API uses common HTTP request methods (e.g., POST, GET, DELETE, etc.) to perform create, read, update and delete (CRUD) operations on identities.

In SCIM, the “client” is the company’s IAM system or identity provider (SCIM IdP) and the “service provider” is typically a software-as-a-service (SaaS) application, such as Salesforce or Zoom. The client stores and manages the identities and permissions the service providers require. When an administrator creates, changes or deletes an account on the client side, SCIM automatically updates the service provider side, keeping all systems in sync.

Defining core identity resources in a SCIM environment enables clients and service providers to communicate user identity data securely. Because SCIM supports interoperability across domains, it connects to cloud-based applications and works with other enterprise security tools, such as firewalls.

SCIM vs. SAML vs. SSO

SCIM vs. SAML

Security assertion markup language (SAML) is an XML-based standard that enables authentication using user credentials stored in an enterprise IAM system. While the global SAML market continues to grow and SAML provides an easy way to manage access to the resources an organization hosts, it is an ineffective system used on its own for cross-domain identity management

Organizations that use cloud-based solutions need a method for managing user access to resources in external providers’ domains. SCIM provisioning provides a way to automate access to all the applications and services an organization uses. Without SCIM, IT administrators would need to create and maintain external user accounts manually—a very complex and time-consuming task.

SCIM vs. SSO

Single sign-on (SSO) is an authentication method that enables users to access multiple applications using a single set of login credentials—typically, a username and password. It strengthens security and eliminates the need for users to remember a separate set of credentials for every application they access.

While SCIM and SSO work together, each serves a different purpose. SCIM provides an easy way to provision users’ access across multiple domains, whereas SSO performs SCIM authentication by verifying users’ credentials.

While SCIM and SSO work together, they serve different purposes. SCIM manages the lifecycle of user accounts, including provisioning, deprovisioning, and synchronizing attributes such as group membership. SSO controls how users authenticate to applications. 

How Delinea supports SCIM provisioning

Delinea supports SCIM 2.0 through a cloud-native SCIM connector that synchronizes users, groups, folders and secrets in both directions between your IAM or identity management and administration (IGA) system and the Delinea Platform. You choose which users and groups your identity provider manages and joiner-mover-leaver (JML) changes flow through without a ticket.

Delinea's SCIM connectors integrate IAM and IGA providers with both the Delinea Platform and Secret Server using the SCIM 2.0 protocol. From there, you can manage users and groups, assign folders and secrets permissions, and remove access when people leave.

Why simplifying provisioning can save you time and money 

Delinea gives security teams precise control over who reaches which systems. Conditional access based on your own criteria and variables reduces the risk of data exposure and shrinks the attack surface, without slowing anyone down.

Pairing SCIM provisioning with the Delinea Platform gives you one source of trust for identity. That eases friction, streamlines provisioning and deprovisioning, reduces IT costs and gets people to the resources they need sooner, within a zero-trust framework.