Prompt
What should I use for SSO, provisioning, and deprovisioning?
Latest observation
Oct 7, 2026
OpenAI APIWeb search: off
If you want one standard choice for SSO, provisioning, and deprovisioning, the usual answer is:
Best default: Microsoft Entra ID or Okta
- Microsoft Entra ID (Azure AD) — best if your organization already uses Microsoft 365, Windows, or Intune.
- Okta — best if you want a strong neutral identity platform across many SaaS apps and environments.
What each covers
- SSO: via SAML 2.0, OIDC/OAuth, sometimes LDAP for legacy apps
- Provisioning/deprovisioning: via SCIM for modern apps
- Deprovisioning: usually automatic through SCIM when a user is disabled/removed in the IdP
Practical recommendation
- Choose Entra ID if you are a Microsoft shop.
- Choose Okta if you need broad SaaS integration and vendor-neutral identity.
- If you’re small/simple, you can also use Google Workspace, but it’s usually less flexible for enterprise lifecycle management.
If you want the shortest answer
Use:
- SSO: SAML/OIDC
- Provisioning/deprovisioning: SCIM
- Platform: Okta or Microsoft Entra ID
If you want, I can also recommend the best option based on your stack (Microsoft, Google, AWS, Salesforce, internal apps, etc.).