Learn more about SCIM
System for Cross-domain Identity Management (SCIM) enables automated user and group lifecycle management between your identity provider (IdP) and your DigiCert® account, DigiCert’s unified single sign-on experience.
When SCIM is enabled, your IdP becomes the source of truth for users and groups in DigiCert services. SCIM automatically creates, updates, and removes users and groups without requiring manual administration in DigiCert.
SCIM works with or without single sign-on (SSO) and independently of how users authenticate.
What can SCIM manage?
SCIM allows you to centrally manage:
User creation and updates
User removal or access revocation
Group creation and updates
Group membership
Dica
SCIM does not manage service access or user role assignments. After groups are synced, assign their service access and user roles in DigiCert account.
How does SCIM work?
In simple terms, you select groups in your IdP, SCIM sends those groups to DigiCert account, and you assign access to them in DigiCert account. The users are then created and receive access based on their group membership.
The following table explains what happens during the initial setup and when you make changes in your IdP:
Phase | Action | Result in DigiCert account |
|---|---|---|
Initial setup | In your IdP, add and configure the SCIM application for DigiCert account. | The IdP is connected to DigiCert account. No users or groups are provisioned yet. |
Initial setup | In your IdP, assign a group to the SCIM application. | The group is included in the provisioning scope. It is not created in DigiCert account until your IdP starts provisioning it. |
Initial setup | Start provisioning the group from your IdP. For example, push the group from Okta. | The group is created in DigiCert account. Its members do not appear yet. |
Initial setup | In DigiCert account, assign services these users should be able to access and at least one user role per service assigned. | New users are created and receive the access and roles assigned to the group. Existing users are converted to SCIM-managed users and can no longer be managed manually in DigiCert account. Any roles assigned to existing users are retained and can be removed manually if they are no longer required. |
Ongoing management | Add a user to a synced group in your IdP. | The user is created in DigiCert account and receives the group’s service access and user roles. |
Ongoing management | Update a user’s details, such as their name or email address, in your IdP. | The user’s details are updated in DigiCert account. |
Ongoing management | Add a user to another synced group in your IdP. | The user receives the service access and user roles assigned to the additional group. |
Ongoing management | Remove a user from a synced group in your IdP. | The user loses the service access and user roles inherited from that group. Access inherited from other groups remains. |
Ongoing management | Disable or delete a user in your IdP. | The user is deprovisioned and can no longer access DigiCert services. |
Supported identity providers
DigiCert® account supports SCIM integration with common enterprise IdPs, including:
About groups used for SCIM provisioning
SCIM provisioning for DigiCert account relies on groups in your IdP to manage user access. You can use existing groups or create new groups for DigiCert account.
Before assigning groups to the SCIM application, ensure that the group contains the users who require the same services and user roles.
Nota
Important: CertCentral role assignments
A CertCentral user can have only one standard user role. If a user belongs to multiple groups that assign different standard CertCentral roles, CertCentral applies only the first standard role it receives.
If your account uses custom roles, a user can have one standard role and multiple custom roles.
What is the difference between SSO and SCIM?
SCIM and SSO are independent capabilities within DigiCert® account.
SSO controls how users authenticate when signing in.
SCIM manages user lifecycle events, such as provisioning, updates, and deprovisioning.
Dica
You can enable either or both of these capabilities, however SCIM, and SSO are recommended for most enterprise environments.