What is SCIM?
By enabling SCIM provisioning, you can configure a push-based directory sync from your identity provider (idP) to Secureframe. User and user updates (e.g. active status) are pushed to Secureframe in near real-time.
SCIM (System for Cross-domain Identity Management) is a standard protocol that automates the management of user identities across systems. SCIM simplifies tasks like creating, updating, and deactivating user accounts in multiple systems. It’s particularly useful for organizations with a large user base, as it reduces the manual effort required to maintain accurate user data.
Key features of SCIM:
Automates user provisioning and deprovisioning.
Ensures consistency of user data across connected systems.
Reduces administrative overhead by syncing user data from a central identity provider (IdP) to other applications.
Setting up SCIM
Note: SCIM is available on the Complete plan only. If you are on Complete and do not see the SCIM Settings tab in Company Settings, reach out to [email protected] to discuss enabling this feature.
In Secureframe, go to Company Settings → SCIM Settings.
Click Start configuring SCIM.
Click Add SCIM Connection and follow the step-by-step workflow on the screen. If your provider is not listed, select Custom SCIM to set up a custom connection.
Automatic Invites
By default, Secureframe imports SCIM groups. To automatically invite users from your SCIM sync:
Go to Personnel.
Open Personnel Settings.
Open Invite personnel.
Add the SCIM group to the Automatic group invites selector (make sure the toggle is checked).
If you don't see SCIM groups in this selector, make sure you have provisioned them in the SCIM app you've setup in your identity provider (idP). Groups from a SCIM connection are prefixed with the idP vendor name, for example, "Okta SCIM - Contractors".
Frequently Asked Questions (FAQ)
I already have a Secureframe SAML app set up in Okta, do I need to create a second app to enable SCIM provisioning, or can I add SCIM to the existing SAML app?
While it may be possible to add SCIM to your existing SAML app in Okta, we recommend creating a separate SCIM app as outlined in the WorkOS SCIM setup instructions (usually titled "SCIM 2.0 Test App (OAuth Bearer Token)" in Okta). This approach ensures full compatibility and minimizes configuration issues.
To enable SCIM, navigate to your Secureframe Company Settings → SCIM Settings:
https://app.secureframe.com/company-settings/scimSettings
Is a SCIM connection the same as an SSO connection?
No, a SCIM connection is separate from an SSO connection. They serve different purposes: SCIM handles user-related data synchronization, while SSO focuses only on authentication.
Does setting up an SSO connection sync user-related data?
No, setting up an SSO connection does not sync user-related data. SSO is limited to authentication and does not involve provisioning or updating user accounts.
How can I sync user-related data?
User-related data will only be synced when a SCIM connection is established and properly configured. Without a SCIM connection, no user data synchronization will occur, even if an SSO connection is active.
How do I enable and set up SCIM?
SCIM is available on the Complete plan. If you have Complete, go to Company Settings → SCIM Settings and follow the setup steps in this article.
If you are on Complete and do not see the SCIM Settings tab, SCIM may not be enabled on your account yet. Reach out to [email protected] to discuss enabling this feature.
Do I need both SCIM and SSO?
In many cases, organizations benefit from using both SCIM and SSO together. Here’s why:
SSO streamlines login and enhances security by centralizing authentication.
SCIM ensures that user data stays consistent across systems and automates user lifecycle management.
For example, when a new employee joins, SCIM can automatically create their account in multiple applications, and SSO allows them to access these applications with a single login.
