Identity & Access

SCIM

System for Cross-domain Identity Management

Formal standard Global IETF Since 2015

A schema and REST protocol for provisioning and deprovisioning user accounts and groups between systems.

Deprovisioning is the audit finding it prevents. Joiner, mover and leaver controls only hold if account removal propagates automatically to every tool holding data, which is precisely what SCIM automates.

At a glance

Category
Identity & Access
Jurisdiction
Global
Governance
IETF
Status
SCIM 2.0 (RFC 7642, 7643, 7644)
First released
2015

Links

Related frameworks

Other entries under Identity & Access.

See SCIM in context

Open the interactive Data Landscape for Regulation to compare SCIM against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.