Home
Blog
Full SCIM Provisioning: Group changes now reach env zero without waiting for a login

Full SCIM Provisioning: Group changes now reach env zero without waiting for a login

Chris Graham
env zero Marketing
with special guest
Mitchell
Hashimoto
Mitchell Hashimoto headshot

Until now, env zero learned about your identity provider one user at a time, at login. Add someone to an Okta group and they picked up the matching env zero team the next time they signed in. Remove them from that group and they kept the team until they signed in again. Someone who never signed in did not exist in env zero at all.

The scenarios in which this becomes untenable are numerous: An engineer moves off the payments team on Monday and still has the payments team's project access on Friday, because they have not logged in since. A contractor is offboarded in the IdP and their env zero account waits for a login that never comes. Most platform teams close the gap the same way: an export from the IdP, a spreadsheet, an afternoon, once a quarter.

Our customers and prospective customers asked, we listened.

What shipped

Full SCIM 2.0 support is now generally available. Your identity provider creates, updates, and deactivates env zero users and teams as the changes happen, rather than when someone next signs in.

Four parts:

  • Provisioning modes: Choose whether env zero provisions users at login, only over SCIM, or both.
  • Group push: Push an Okta or Microsoft Entra ID group and env zero creates a team with the same name, then keeps its membership in sync.
  • Token rotation: Issue a new bearer token while the old one keeps working for 24 hours, so you can update your IdP without a provisioning outage.
  • Reconcile: Compare what your IdP thinks is true against what env zero holds, see the drift, and fix it in one pass.

You need an existing SSO connection using SAML or Entra ID, the Edit Organization Settings permission, and an IdP that maps the user's email address to the SCIM userName attribute and sends externalId. env zero rejects a user create that is missing either.

Setting it up

In env zero, open Organization Settings > SSO and click Generate SCIM Token. Copy the endpoint URL and the bearer token, which is shown once.

Then, in Okta, open the env zero app integration, set Provisioning to SCIM, and fill in the connector settings:

  • SCIM connector base URL: the SCIM endpoint URL from env zero
  • Unique identifier field for users: userName
  • Supported provisioning actions: Push New Users, Push Profile Updates, Push Groups
  • Authentication Mode: HTTP Header, with the env zero bearer token as the authorization value

Click Test Connector Configuration, then enable Create Users, Update User Attributes, and Deactivate Users under To App. Entra ID takes the same two values as its Tenant URL and Secret Token, and any other SCIM 2.0 provider can use the same endpoint with the token in the Authorization header.

Pick a provisioning mode before you point your IdP at it

The mode decides what happens at login and whether env zero accepts SCIM writes at all.

  • Full SCIM: no provisioning at login, SCIM writes accepted, a non-member signing in is denied.
  • JIT: users, teams, and admin roles sync from the SAML assertion at login, SCIM writes rejected, a non-member is provisioned at login.
  • Hybrid (legacy): provisioning at login as in JIT, and SCIM writes accepted.

One thing to know before you start: generating a token puts the organization into Full SCIM mode. Login-time provisioning stops immediately, and anyone who is not already a member is denied. If your users rely on being provisioned when they log in, set the mode before you connect your IdP, not after.

What this changes, and what it does not

Team membership stops being a function of who logged in recently. Deprovisioning happens on the next sync rather than the next login attempt, which is the part that matters for offboarding. And reconcile gives you something the login-time model never could: a straight answer to whether env zero and your IdP actually agree, including members who predate SCIM and were never marked as SCIM-owned.

The trade-offs are worth knowing up front. Groups are matched to teams by display name, so pushing a group whose name is already taken by a team returns a conflict until you rename one of them. Members have to exist in env zero before a group push can carry them, which means assigning the user in your IdP first. And in Full SCIM mode the login-time team sync stops running, so any group you were relying on for team membership needs to be pushed over SCIM instead.

Permissions stay where they were. Assign project roles to the team in env zero, and they survive whatever your IdP does to the membership.

Getting started

Set it up from Organization Settings > SSO. The SCIM provisioning guide covers the modes, token rotation, and reconcile, with separate walkthroughs for Okta and Microsoft Entra ID. The full release is in the changelog.

Schedule a technical demo
See env zero in action
Schedule demo

Related Content

All articles
Read more
Read more
Read more
Abstract isometric art with a compass, cubes, and a radar scope
Read more
Read more
Read more