System for Cross-domain Identity Management (SCIM)
An IETF standard (RFCs 7643 and 7644) for creating, updating and removing user accounts across domains through a common REST and JSON interface, including deprovisioning.
SCIM defines a common schema for users and groups and a REST interface, using JSON, through which one system can create, read, update and delete identities held in another. Version 2.0 is published by the IETF as RFC 7643 (the core schema) and RFC 7644 (the protocol), both from 2015. In a typical deployment, the organisation’s identity provider acts as the SCIM client and pushes account changes to cloud applications, so joiners, movers and leavers are reflected at each service.
SCIM is a provisioning standard, not an authentication one, and it works alongside federated identity. SAML or OpenID Connect signs the user in; SCIM manages whether the account exists at the service. Its main security value is deprovisioning. Disabling a leaver at the identity provider stops new federated sign-ins, but an account already created at a service can remain, and SCIM can automate its removal or suspension. Whether open sessions end at the same moment depends on the service. Just-in-time provisioning creates an account at first sign-in but does not, on its own, remove it later.
Exam relevance: a scenario in which a leaver, disabled centrally, still reaches a cloud application is likely to point to automated deprovisioning with SCIM. Candidates are expected to separate SCIM, which manages the account’s lifecycle, from SAML and OpenID Connect, which handle the sign-in.