DEV Community

Jen Easterly
Jen Easterly

Posted on

SCIM Identity Management: Automating User Provisioning and Deprovisioning

A new employee joins on Monday. They need access to several business applications. After 6 months, they are transferred to another department and their needs are different. They do not stay in the company for long and these accounts must be either disabled or terminated.

As an organization expands, handling all the changes manually can become cumbersome and challenging. The problem is resolved by IAM SCIM, which facilitates the exchange of the identity information in a standardized manner and automates the user lifecycle management between compatible systems.

What Exactly Is SCIM?

SCIM is the acronym for System for Cross-domain Identity Management. It is an HTTP based standard to make it easier to manage identity information over different domains and applications.
SCIM 2.0 defines standardized resources and operations that allow identity systems and applications to communicate without requiring a completely different provisioning method for every integration.
Two important SCIM resources are:
Users: Individual identities and their attributes
Groups: Sets of users which may be used to create organization or access structures.
SCIM may also be extended for the organization or service provider to add extra identity attributes.

Follow an Identity Through Its Lifecycle

The easiest way to understand SCIM is to follow what happens to an employee account.

  1. A User Joins Now, if HR hires a new employee into the organization's system of record, what happens? That information can be passed to an identity platform where it can be used to identify which connected apps need an account. A user resource can then be created using a standardized request for a SCIM enabled application. Instead of an administrator manually creating accounts application by application, provisioning can become part of an automated identity workflow.
  2. Something About the User Changes Employees rarely keep exactly the same responsibilities forever. Someone may: Move to another department Receive a different job title Change their name Join or leave a group Take on different responsibilities SCIM supports operations for modifying identity resources. It has a protocol that supports HTTP methods for creating, retrieving, replacing, updating, and deleting resources. For example, there is a partial update possibility of a resource with PATCH. This enables an IAM SCIM integration to maintain synced supported downstream applications when relevant identity information changes.
  3. The User Leaves The main area where identity automation comes in handy is offboarding. Organizations may find themselves with redundant accounts for former employees in applications. An automated lifecycle process can be used to automate deprovisioning actions in connected applications based on a change in the authoritative identity source. Depending on how the service is configured for SCIM and the organization's workflow, this could be disabling or removing the user resource.

SCIM Does Not Decide Who Gets Access

There is an important distinction here.
SCIM is primarily a standard for exchanging and managing identity data. It does not, by itself, determine an organization's access policies.
Think of the responsibilities separately:

SCIM: Its main purpose is to provision and manage identity data, such as creating, updating, and removing user accounts across systems.

Authentication: This verifies who the user is.

Authorization: This determines what the user can access once their identity is verified.

IAM policies: These define and enforce identity and access rules, setting the conditions under which access is granted.

This is important because having SCIM does not make a total identity-security strategy.

Why Automation Matters at Enterprise Scale

Manual provisioning might seem like a manageable task for an organization that has a small number of systems. But this is fast changing when hundreds or thousands of identities are interacting with many cloud and enterprise applications.
Standardized provisioning can help organizations:
Reduce repetitive account administration
Update supported applications more consistently
Accelerate onboarding and offboarding workflows
Reduce dependence on application-specific provisioning processes
Maintain more consistent identity information across connected systems
SCIM was specifically designed to make identity management across domains easier and reduce the complexity of user-management operations.

From Account Creation to Lifecycle Automation

Provisioning is not simply about creating an account on an employee's first day. Identity data continues changing throughout that person's relationship with an organization.
This is why IAM SCIM can be best understood as a component of an overall identity lifecycle.
Organizations can replace numerous disconnected manual tasks with repeatable workflows when compatible applications can get standardized identity updates. The outcome is a more palatable way of maintaining user identities from on-boarding to role changes and eventually deprovisioning.

Top comments (0)