Skip to main content

SCIM Provisioning

Provision and deprovision accounts and groups without confusing lifecycle synchronization with authentication federation.

Control objective

The System for Cross-domain Identity Management (SCIM) standard defines HTTP-based schemas and operations for managing users and groups across systems. Provisioning creates and updates local account state. Deprovisioning disables or removes it. These are lifecycle operations, not authentication ceremonies.

Provisioning flow

An identity source or lifecycle system calls the service provider's SCIM endpoint with authorized requests. The provider maps stable identifiers, validates schemas, applies create, replace, patch, delete, and group membership operations, and returns protocol results. The system must handle retries and out-of-order change safely.

Federation is separate

OpenID Connect or SAML can authenticate a user without creating every application record. SCIM can create an account without authenticating its user. Keep account status, federation subject mapping, group state, application permission, and session state connected but distinct.

Failure and residual risk

Duplicate identifiers can create or link the wrong account. Partial updates can leave stale groups. A disabled SCIM record might not terminate active sessions. Delete and recreate operations can change identifiers. Broad SCIM credentials can modify many accounts.

Pomerium boundary

Pomerium uses federated authentication and route policy. It does not replace application provisioning. If route policy depends on directory groups, operators must understand how those groups are sourced, refreshed, and revoked. Applications can still need SCIM or another lifecycle process for local accounts.

Evaluation checklist

  • Which stable identifier joins the source and service-provider account?
  • Are create, update, disable, delete, retry, and out-of-order cases tested?
  • Does deprovisioning terminate or invalidate relevant sessions and permissions?
  • Are SCIM credentials narrowly scoped, rotated, and audited?
  • Is provisioning kept separate from authentication and authorization decisions?

Sources and further reading

Keep learning

Identity and AuthenticationStandards and Protocols

Identity Federation

Establish trust between an identity provider and relying party without treating an assertion as universal authority.

Learn this term
Authorization and PolicySecurity Operations and Risk

Authorization Drift

Authorization drift is the gap that develops when effective access no longer matches intended access.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo