Contacto
06.10.26

Understanding the SCIM protocol and how it works

What is the SCIM protocol (System for Cross-domain Identity Management)?

Automating identity management has become a top priority for any company that keeps adding business applications. This article covers the essentials of the SCIM protocol: what it is, how it works technically, the concrete benefits it brings to IT teams, and how it compares with other identity protocols such as SAML, SSO and LDAP. Thanks to a shared standard, companies can connect their various systems while keeping custom development to a minimum, even as the number of employees or applications grows.

SCIM, short for System for Cross-domain Identity Management, is a standardized protocol that automates identity management between an identity provider and an application. In practice, SCIM automatically creates, updates and deletes user accounts, with no manual work on each platform involved. It is an open standard published by the IETF. Its current version, SCIM 2.0, is described in RFCs 7642, 7643 and 7644, and its principle remains the same whatever the identity provider or target application.

SCIM's main strength lies in this standardization: instead of building a specific integration for each application, IT teams rely on a common protocol that is widely recognized and adopted across the industry. This lightens the workload for administrators and makes identity management more reliable across the whole company, from the day an employee is hired to the day they leave.

How does the SCIM protocol work?

SCIM is built on a simple principle: automating identity data exchanges between two systems that would otherwise have to be synchronized by hand, at a significant cost in time and effort for IT teams.

Exchanges between identity provider and application, throughout the lifecycle

In a SCIM architecture, the identity provider (IdP), meaning the company's directory or identity management solution, acts as the sender. It sends the target application the information needed to create or update a user account: name, email, group membership, activation status. The application, for its part, exposes an interface that can receive this information and apply it directly, so nobody has to enter the same data in two different places.

These exchanges cover the entire lifecycle of a user account: creation when someone joins, updates when they change role or work group, then deactivation when they leave. This is what allows a company to keep its internal directory consistent with all of its applications, including cloud-hosted ones, wherever the employees concerned are located.

The data format used

On the technical side, SCIM relies on a REST API and the JSON data format. The SCIM schema defines two main resource types: Users, for user accounts, and Groups, for the groups they belong to. Each resource follows a standardized schema, which ensures that any SCIM-compatible application understands the information it receives without extra processing. Create, read, update and delete operations rely on the standard HTTP methods (POST, GET, PUT, PATCH, DELETE) and apply directly to both resource types.

This common foundation (REST API, JSON, standardized schema) explains why SCIM has become a reference for identity provisioning: software vendors only need to implement the protocol once to become compatible with most identity providers on the market, whether their product is a SaaS service or a tool installed on premises.

What are the benefits of SCIM for IT management?

Beyond the technical side, the value of SCIM for an IT team shows up very concretely on several levels: speed, security and workload.

Automate account creation and deletion with SCIM provisioning

The first benefit of SCIM provisioning is the automated creation and deletion of user accounts. When a new employee joins the company, their access to the various applications is created automatically as soon as they are registered in the directory, without IT teams having to step in application by application. The same automation applies when a contract ends: deactivating the account in the IdP is automatically passed on to every tool involved, which greatly reduces the risk of leaving an active account behind after someone leaves.

Reduce errors and security risks

Entering user accounts manually in several different systems multiplies the risk of error: forgotten deactivations, inconsistent information across platforms, orphaned accounts that remain active when they should not. These orphaned accounts are a real security risk, since they are access points that escape administrators' control. By automating the synchronization of identity data, SCIM naturally cuts down on this type of error and strengthens control over the application landscape, however complex the information system.

Save time on access administration

For a company managing several hundred or even several thousand users, manual account management puts a heavy load on IT teams. SCIM frees up that time for higher-value work instead of repetitive account creation or update tasks. It also improves the user experience: employees get their access from day one, with no waiting time caused by manual processing. This is the case in GLPI, where the SCIM plugin automates provisioning for technician and end-user accounts, while authentication is handled separately, for example through the OAuth SSO plugin.

SCIM compared with other identity protocols

SCIM is often mentioned alongside other identity and access management protocols. It helps to clarify the role of each one, as they complement each other rather than compete.

SCIM vs SAML: what is the difference?

SAML is an authentication protocol: it lets a user prove their identity and access an application without entering their credentials again. SCIM does not handle authentication, but provisioning, meaning the creation and updating of the accounts themselves. In practice, the two protocols are often used together: SCIM prepares the user account, then SAML manages the login to the application.

SCIM vs SSO: what role does each play?

SSO (single sign-on) lets a user log in once to access several applications, without re-entering a password for each one. As with SAML, the link with SCIM is direct: SCIM makes sure the account exists and its information is up to date, then SSO handles the everyday login experience. A company that sets up SSO therefore has every reason to rely on SCIM as well to automate provisioning. In GLPI, the OAuth SSO plugin handles login (Google, Microsoft Entra ID, Okta, etc.), while the SCIM plugin manages the account lifecycle.

SCIM vs LDAP: what is the difference?

LDAP and SCIM do not address the same need: LDAP is used to query a directory and authenticate users, while SCIM is used only to provision accounts in applications. LDAP is still widely used to manage a corporate directory. SCIM, which is more recent, was designed to meet the needs of modern architectures, particularly when a company combines several cloud platforms and applications that do not share the same directory. Which one to use depends on the context: LDAP suits an information system centralized around a single domain, while SCIM offers more flexibility as the number of applications or products to connect grows, or when some of them are hosted outside the internal network. In many cases, both approaches coexist, for instance when a company moves its information system towards an integration with Microsoft Entra ID (formerly Azure Active Directory) while keeping an existing LDAP directory.

SCIM and open source: identity management without proprietary connectors

In an information system built around open source tools, a recurring challenge is connecting the various software components without piling up custom developments. This is precisely one of SCIM's strengths: because it relies on an open, widely adopted standard, it can link a directory or identity provider to an application without a proprietary connector or a purpose-built API.

For an IT department that wants to stay in control of its information system, this approach has a direct benefit. It avoids depending on a single vendor for access management, while relying on a protocol supported by most of today's identity providers and business applications. IT teams can evolve their application landscape, connect new products and services, or change identity provider without calling their whole identity management architecture into question. This principle matches the very philosophy of a tool like GLPI: relying on open standards rather than proprietary mechanisms, so the company keeps control of its information system. To learn more about what the tool offers day to day, all of its features are presented in detail on the website.

How to implement SCIM in your information system

Implementing SCIM follows a fairly similar logic from one system to another, even though the exact steps vary depending on the identity provider and the application involved.

Key deployment steps

  • Configure the identity provider to expose the account and group data to be synchronized
  • Enable SCIM provisioning support on the application side, usually through a dedicated authentication token
  • Define the attributes to synchronize (identifiers, emails, groups, activation status) according to business needs
  • Run a first test synchronization on a limited number of accounts to check that the data sent is consistent
  • Set up continuous monitoring to make sure the synchronization process keeps working correctly over time

This setup can build on resources that are already documented. For a concrete example combining SCIM and authentication through a cloud identity provider, the SCIM provisioning tutorial with OAuth SSO and Azure AD details the technical steps to follow in that specific context.

Technical prerequisites and SCIM support

On the identity provider side, the directory must be SCIM-compatible, which is the case for most current cloud solutions, such as Microsoft Entra ID or Okta. An on-premises Active Directory does not support SCIM natively: it usually goes through Entra ID or a third-party tool. On the application side, a SCIM endpoint must be exposed, usually with documentation listing the supported attributes and the methods available for the Users and Groups resources. It is also recommended to check the integration's scalability limits beforehand, especially for companies with a large workforce or a high number of groups to synchronize.

SCIM in a nutshell

The SCIM protocol now plays a central role in corporate identity management. By automating user account provisioning, it reduces the effort needed to administer access and limits the risks tied to orphaned accounts. This page has covered the main technical and functional points of SCIM: its definition, how it works, its benefits, how it compares with SAML, SSO and LDAP, and the main steps to implement it. For a company that relies on open source tools, SCIM remains an accessible way to gain efficiency at every level of its information system, without giving up control over its identity data.

También te puede gustar estos artículos

06.10.26
What is the SCIM protocol (System for Cross-domain Identity Management)? Automating identity management has become a top priority for any company that keeps adding business applications. This article covers the essentials of the SCIM protocol: what it is, how it works technically, the concrete benefits it brings to IT teams, and how it compares with […]
05.10.26
GLPI 12 is scheduled for release in October 2026. Under our support model, which always covers the two latest major versions, this release will mark the end of support for GLPI 10. What this means for your instance Once GLPI 12 is out, instances still running GLPI 10 will no longer receive: Running an unsupported […]
01.10.26
Due to an undetected regression, GLPI 11.0.10 crashes when loading some plugins. Version 11.0.11 has been released to address the issue. We recommend that all users upgrade as soon as possible. As a reminder, here are the details of version 11.0.10, which also apply to 11.0.11: Many bug fixes have also been made, read the changelogs […]
30.09.26
11.0.10 and 10.0.28 releases fix several security issues that have been recently discovered. Update is strongly recommended! Important note: with the upcoming release of GLPI 12.0.0, version 10.0.28 will be the final release of the 10.0 branch, which will no longer receive bugfixes. Many bug fixes have also been made, read the changelogs for more […]
29.09.26
Requests get lost across several mailboxes, response times keep growing, and nobody knows who is handling what? That is a clear sign it is time to structure your support with a proper ticketing tool. GLPI is the open source ticketing tool that brings your customer service ticket management and your IT asset inventory together in […]
24.09.26
A new GLPI Agent version is now available! GLPI-Agent 1.20 has been released. You can download it on the GLPI Agent github project: https://github.com/glpi-project/glpi-agent/releases/tag/1.20 You can check changes details in the official online Changelog available here: https://github.com/glpi-project/glpi-agent/blob/1.20/Changes This new version fixes the following security issues: We strongly encourage you to update your agents. Bug fixes […]
23.09.26
Congratulations! We are happy to announce our new Silver GLPI Network partner in China: KNX Innovation Limited. With more than 15 years of experience in enterprise system architecture and integration, KNX Innovation Limited helps organizations modernize their business applications and transform their enterprise systems. The team has solid implementation experience on major platforms such as […]
Giesecke+Devrient (G+D), headquartered in Munich, designs security technologies used in banknote counting machines, passports, and other security products worldwide. With more than 14,000 employees, 40 countries, and 123 subsidiaries and joint ventures, the company relies on a central IT team in Munich supported by local colleagues in India, Singapore, Canada, and numerous production sites around […]
22.09.26
Congratulations! We are pleased to announce our new Silver GLPI Network partner in India: RecoChain We are excited to welcome our new Silver GLPI Network partner in India: RecoChain. RecoChain is a digital transformation partner that combines software with expert services, helping businesses build and deploy autonomous AI applications quickly. The company brings deep expertise in cybersecurity […]
18.09.26
On Sunday, September 6, the GLPI team took part in the 10 km du Trocadéro in Paris, one of the city's classic urban races, with a route offering a stunning view of the Eiffel Tower along the way. Running for ARSLA Beyond the physical challenge, the team ran in support of ARSLA (Association pour la […]
Industrializing support for 7,000 users Hexafret, a rail freight subsidiary of SNCF, runs support for 4,000 employees and around 7,000 internal and external users while helping the country avoid the emission of more than 1 million tonnes of CO2 and over 1 million long-distance trucks on the road every year. Behind that operation, the support […]
16.09.26
Two new GLPI versions are now available! We've just released GLPI 11.0.9 and GLPI 10.0.27 to patch several critical security vulnerabilities.We strongly advise upgrading your instances as soon as possible! GLPI 11.0.9 changelog: https://github.com/glpi-project/glpi/milestone/91?closed=1GLPI 10.0.27 changelog: https://github.com/glpi-project/glpi/milestone/90?closed=1 Get the updates here: https://github.com/glpi-project/glpi/releases You will find below the list of security issues fixed in theses bugfixes […]
08.09.26
We are pleased to announce the availability of OAuth authentication in GLPI Android Inventory Agent 1.9.0. This new feature enhances the security of Android deployments by providing a modern, dedicated authentication mechanism specifically designed for inventory operations. More Secure and Dedicated Authentication With this new version, administrators can configure a dedicated OAuth client for GLPI Android Inventory Agent, […]
07.09.26
GLPI 12 has now reached the Release Candidate stage. This means no more new features will be added; the focus is now on bug fixing, and completing translations. The version is feature-ready, and we’re very close to the stable release. GLPI 12 stable will be released in October 🎉 You can already explore what’s coming in this […]
02.09.26
Congratulations! We are pleased to announce our new Silver GLPI Network partner in France: Helpline UXLINE is the GLPI Center of Expertise at HELPLINE by Everience. As a direct TECLIB partner, the team supports organizations in industrializing their ITSM/ESM processes and modernizing their support services.  Our consultants cover every component of a GLPI project: ITSM/ESM governance, […]
Managing IT and business services across 1,700 stores, 11 states, and 29,000 employees is a major engineering and governance challenge. Facing restrictive licensing costs and fragmented history, Grupo DPSP, a Brazilian giant formed by the merger of Drogaria São Paulo and Drogaria Pacheco, had to completely rethink its service management strategy. In this exclusive video […]
19.08.26
Congratulations! We are pleased to announce our new Silver GLPI Network partner in Azerbaïdjan: InSol LLC InSol LLC is an IT services company based in Azerbaijan, specializing in managed IT services, IT infrastructure, system administration, cloud solutions, cybersecurity, and technical support. They help organizations establish reliable and secure IT environments by offering proactive support, infrastructure management, […]
In the public sector as well as in large-scale IT service management, maintaining flawless service continuity while meeting strict contractual requirements is a daily challenge. In Brazil, Consórcio DPZ, a strategic consortium formed by three major companies from the Pernambuco region (Datamétrica, Pronet, and Zero Um) rises to this challenge across the entire state government […]
04.08.26
We are pleased to announce a new version of the GLPI Agent: 1.19. You can download it on the GLPI Agent github project: https://github.com/glpi-project/glpi-agent/releases/tag/1.19 This new version fixes the following security issues: The release also includes few bug fixes and enhancements: We also introduce experimental support for coming GLPI 12: You can check changes details in […]
When you are a major IT services provider operating across 16 countries, leaving any request to chance is simply not an option. For Econocom’s Product Care team—responsible for after-sales service and hardware warranties—having robust IT software is an absolute requirement for success. Between the technical workshop and the customer entry point, one unified solution stood […]
1 2 3 … 20
chevron-right
LinkedIn Facebook Pinterest YouTube rss Twitter instagram facebook en blanco rss-en-blanco linkedin en blanco Pinterest YouTube Twitter instagram