What is SCIM?
Also called: System for Cross-domain Identity Management · SCIM 2.0Definition
SCIM (System for Cross-domain Identity Management) is an open standard for automating user provisioning between an identity provider, such as Microsoft Entra ID or Okta, and applications such as an LMS. SCIM 2.0 is defined by the IETF in RFC 7643, the core schema for users and groups, and RFC 7644, the REST protocol. When HR or IT adds, changes or disables someone in the directory, SCIM creates, updates or deactivates that person’s account in each connected application automatically.
The application exposes SCIM endpoints, chiefly /Users and /Groups. The identity provider calls them with standard HTTP requests: POST to create a user, PATCH or PUT to update attributes such as department or manager, and a PATCH setting active to false to deactivate. Attributes follow the core schema in RFC 7643, with an enterprise extension for fields such as employee number, department and manager.
For corporate L&D, SCIM keeps the LMS in step with the organisation without spreadsheet uploads. New joiners appear on day one with the right department and location, so automatic assignment rules can enrol them in onboarding; movers get the right training when their role changes; and leavers are deactivated, which matters for licence counts and data protection. Bodhih LMS supports SCIM 2.0 directory sync, including deactivation, in its Scale band.
Common mistakes: relying on SSO alone and assuming it removes leavers; mapping too few attributes, so assignment rules have nothing to work with; and hard-deleting users, which destroys their training history, instead of deactivating them.
Key points
- IETF standard: RFC 7643 (schema) and RFC 7644 (protocol).
- Automates create, update and deactivate from the directory.
- Uses REST endpoints /Users and /Groups.
- Complements SSO, which only handles sign-in.
- Deactivate rather than delete to keep training records.
An example at work
A Pune automotive supplier connects Okta to its LMS with SCIM 2.0. When HR adds a new quality engineer, the LMS account is created with department “Quality”, a rule assigns the ISO 9001 induction course, and when someone leaves, the account is deactivated within the sync cycle while their certificates stay on record.
Where this is used at Bodhih
Related terms
Single sign-on
Single sign-on (SSO) is an authentication method that lets people use one corporate login, such as Microsoft Entra ID or Okta, to access many applications.
Learning management system
A learning management system (LMS) is software that delivers, assigns, tracks and reports on training, from e-learning courses to classroom sessions and certifications.
Multi-tenant LMS
A multi-tenant LMS is a learning management system that runs many separate organisations or portals, each with its own users, content, branding and admins, on one platform.
More about SCIM
What is the difference between SCIM and SSO?
SSO handles authentication: letting a person sign in with their corporate account. SCIM handles provisioning: creating, updating and deactivating that person’s account in the application automatically. Most organisations use both, SSO so people can sign in and SCIM so accounts appear and disappear in step with HR records.
Which identity providers support SCIM?
Major identity providers including Microsoft Entra ID, Okta, OneLogin and JumpCloud support SCIM 2.0 provisioning to applications. Google Workspace supports automatic provisioning to selected applications. The application must expose a SCIM 2.0 endpoint for the connection to work.