SCIM provisioning basics: what the protocol does and where it stops
ILM Reference editors · Published 2026-02-24 · 3 minute read
TRACK: BASICS · LESSON 2 OF 11
SCIM is a standard HTTP protocol that lets an identity provider or IGA platform create, update and deactivate user accounts in an application. It is defined in IETF RFC 7644 (September 2015). It automates joiners, movers and leavers for applications that implement it, and it does nothing for applications that do not, or for accounts created inside the application by hand.
What is SCIM?
System for Cross-domain Identity Management (SCIM) is an application-level protocol for provisioning and managing identity data over HTTP. The protocol is specified in IETF RFC 7644, published in September 2015 as a Proposed Standard. An application that supports SCIM exposes endpoints for users and groups, and a provisioning client (usually the identity provider or the IGA platform) calls those endpoints when something changes.
The operations map to ordinary HTTP methods: create a resource, read it, replace it, modify part of it, or delete it. Requests and responses are JSON documents that follow a shared schema, so one client can provision many applications the same way instead of maintaining a custom integration for each.
What does SCIM do for joiners, movers and leavers?
| Lifecycle event | What the provisioning client does | Typical SCIM operation |
|---|---|---|
| Joiner | Creates the account and adds it to the groups for the role | Create a user, then update group membership |
| Mover | Changes attributes such as department or manager, and changes group membership | Modify the user and the groups |
| Leaver | Deactivates the account or deletes it, depending on policy | Set the user inactive, or delete the user |
| Review outcome | Removes access a reviewer revoked | Modify group membership |
Many applications prefer deactivation to deletion for leavers, because deletion can remove records the business still needs. Your policy should say which one applies, per application, and your audit evidence should show which one happened.
Which tools rely on SCIM?
Most governance platforms use SCIM as one of several ways to reach applications. Okta Identity Governance describes automated provisioning for thousands of apps using the SCIM standard. Microsoft Entra ID Governance provisions through SCIM, LDAP, SQL, SOAP or REST, and uses the ECMA connector host for some on-premises applications. Other platforms add their own connector frameworks for systems without SCIM, such as C1's open-source Baton connectors or Veza's Open Authorization API.
Where does SCIM stop?
- Applications that do not implement it. Many legacy, on-premises and custom-built applications have no SCIM endpoint. These are the disconnected applications that end up on tickets and spreadsheets.
- Accounts created outside it. SCIM manages the accounts the provisioning client created or linked. A local account that an administrator created inside the application does not pass through SCIM, so a leaver's deactivation does not touch it.
- Access defined inside the application. If an application grants permissions through its own internal roles that are not exposed as SCIM groups, the provisioning client cannot see or change them.
- Proof that the change happened. A successful SCIM call is a record from the client's side. Auditors may still ask for evidence from the application itself.
That is why a complete program pairs SCIM for the applications that support it with a documented process, or a discovery tool, for the ones that do not. See the joiner-mover-leaver process guide for the manual path.
What should you check for each application?
- Does it support SCIM, and which operations: create, update, deactivate, delete, groups?
- Is deactivation or deletion the leaver action, and is that written down?
- Can accounts also be created locally, and who can create them?
- Are the application's internal roles exposed as groups the provisioning client can manage?
- Where is the evidence that a leaver's account was disabled, and how long is it kept?
Sources
Reviewed Sep 2026
Six labels for the same account list, and what each one asks you to do.