SCIM provisioning overview
This topic provides an overview of SCIM 2.0 provisioning. SCIM (System for Cross-domain Identity Management) lets you automate user provisioning and deprovisioning and manage groups using your identity provider (IdP) as the source of truth.
Introduction
SCIM is an open standard protocol designed to simplify user identity management across cloud-based applications and services. SCIM eliminates the manual processes required to onboard and offboard users, ensuring that identity changes in your corporate directory are automatically reflected in HCP Terraform.
When you enable SCIM provisioning, your identity provider becomes the authoritative source for user lifecycle management so that when employees join, change roles, or leave your organization, their access to HCP Terraform is automatically updated without manual intervention.
Benefits
SCIM provisioning provides several key benefits for enterprise identity management.
Automated provisioning
When a new employee is added to your identity provider, SCIM automatically creates their account in HCP Terraform. Team membership is synchronized separately through SCIM group provisioning and team mapping. This eliminates manual account creation and reduces IT administrative overhead.
Reduced manual overhead
SCIM synchronizes user profile changes, such as email updates or group membership changes, automatically between your IdP and HCP Terraform. Administrators no longer need to manually update user information across multiple systems.
Enhanced security through instant deprovisioning
When an employee leaves your organization or loses HCP Terraform access in your IdP, SCIM immediately revokes their access to HCP Terraform. Unlike SAML authentication alone, which only updates access at login time, SCIM proactively removes access regardless of whether the user attempts to log in. This ensures that terminated employees cannot retain access to your infrastructure.
Centralized identity management
Your identity provider serves as the single source of truth for user identities. All user and group management happens in one place, reducing the risk of access inconsistencies and simplifying compliance auditing.
SCIM complements SAML
SCIM and SAML serve complementary but distinct purposes in Terraform Enterprise:
| Protocol | Purpose | When it runs |
|---|---|---|
| SAML | Authentication | At user login |
| SCIM | Provisioning | Continuously, as changes occur in IdP |
You must enable SAML single sign-on (SSO) before configuring SCIM.
When SCIM is enabled, HCP Terraform ignores team membership information in SAML assertions. This prevents potential conflicts between the two systems and ensures that SCIM remains the authoritative source for provisioning.
When SCIM is enabled, HCP Terraform does not create users on login. You must provision users through SCIM before they can authenticate with SAML.
User types
Users provisioned by your IdP cannot be modified directly in HCP Terraform. Profile updates and deprovisioning must occur through the identity provider.
Manually-managed users, including site administrators created for recovery purposes, can be modified within HCP Terraform and are not affected by SCIM operations.
SCIM groups
SCIM groups represent groups from your identity provider. HCP Terraform performs the following acitons during synchronization:
- Stores them as SCIM groups.
- Synchronizes group membership automatically.
- Lets you link groups to teams in HCP Terraform.
Automated team membership management
Link SCIM groups from your IdP to teams in HCP Terraform to enable automatic team membership management.
- You can link a single SCIM group to multiple HCP Terraform teams across different organizations, up to 10,000 teams per group.
- You can only link team to one SCIM group.
- When users are added or removed from a group in the IdP, HCP Terraform automatically updates their team memberships.
- You cannot directly modify team membership in HCP Terraform when the team is linked to a SCIM group.
- You cannot configure the
ownersteam as a SCIM-managed team. This ensures administrators can always access HCP Terraform for troubleshooting.
Source of truth
The IdP is the source of truth for user and team membership management, but organization owners can enable, pause, or disable SCIM provisioning for the organization. Pausing SCIM preserves all existing configurations and mappings but stops processing updates from the IdP.
Supported identity providers
You can enable SCIM with the following identity providers and provider configurations:
- Okta
- Microsoft Entra ID
- Supported generic SAML provider configurations
SCIM interfaces
The HCP Terraform API implements SCIM User and Group resources, as well as the discovery endpoints commonly required by identity providers. Refer to the following topics for more information: