Prompt
How do I add SCIM provisioning after SSO is already working?
Latest observation
Oct 7, 2026
OpenAI APIWeb search: off
You can add SCIM provisioning after SSO is already working—they’re separate integrations, so you usually don’t need to redo SSO.
High-level process
-
Keep your existing SSO configuration
- No changes needed unless your IdP requires sharing the same app for both SSO and SCIM.
-
Enable SCIM in your app / service
- In your admin console, turn on SCIM provisioning or create a provisioning connector.
-
Generate or retrieve the SCIM credentials
- Typically this is:
- SCIM base URL / endpoint
- Bearer token / API token
- Sometimes the token is separate from the SSO certificate or SAML settings.
- Typically this is:
-
Configure SCIM in your IdP
- In Okta / Azure AD / OneLogin / etc., open the existing app or create a provisioning app.
- Enter the SCIM endpoint and secret token.
- Set the username identifier mapping (often email).
-
Test provisioning
- Push one user and one group.
- Verify create/update/deactivate behavior.
-
Turn on sync lifecycle settings
- Decide whether to provision:
- users only, or users + groups
- create, update, deactivate, reactivate
- Map attributes like first name, last name, email, display name, etc.
- Decide whether to provision:
Common gotchas
- SSO app and SCIM app may be separate
- Some IdPs use the same app for both; others require enabling provisioning in the same app.
- SCIM uses a different auth method than SSO
- SAML/OIDC for login, token-based auth for provisioning.
- Existing users may need to be matched
- Make sure the SCIM user identifier matches the account identifier already used in your app.
- Group push may not be immediate
- Deprovisioning and updates can take time depending on the IdP sync schedule.
If you’re using a specific IdP
I can give you exact steps for:
- Okta
- Microsoft Entra ID (Azure AD)
- OneLogin
- Google Workspace
- or a custom SCIM server
If you tell me which IdP and app you’re using, I’ll outline the exact setup.