Cross-Domain Identity management

Sharing is caring!

&NewLine;<p>The System for Cross-domain Identity Management &lpar;SCIM&rpar; specification is designed to make managing user identities in cloud-based applications and services more accessible&period; It&&num;8217&semi;s an open standard protocol for automating the exchange of user identity information between identity domains and IT systems&period;&nbsp&semi; Its intent is to reduce the cost and complexity of user management operations by providing a common user schema and extension model and binding documents to provide patterns for exchanging this schema using standard protocols&period; In essence&colon; make it fast&comma; cheap&comma; and easy to move users in to&comma; out of&comma; and around the cloud&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><img src&equals;"https&colon;&sol;&sol;docs&period;microsoft&period;com&sol;en-us&sol;learn&sol;wwl-sci&sol;create-configure-manage-identities&sol;media&sol;automatic-user-provisioning&period;png" alt&equals;"Diagram of the process flow for auto user provisioning&period; The flow shows you can have users in an on-premises or cloud human resource management system automatically provisioned as user accounts in Azure A D&period; The Azure A D provisioning service can be called to create and manage the user and groups&period;"&sol;><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<h3 class&equals;"wp-block-heading" id&equals;"components-of-system-scim-system-for-cross-domain-identity-management">Components of system SCIM &lpar;System for Cross-Domain Identity Management&rpar;<&sol;h3>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list"><li><strong>HCM system<&sol;strong>&nbsp&semi;&&num;8211&semi; Applications and technologies that enable Human Capital Management processes and practices that support and automate HR processes throughout the employee lifecycle&period;<&sol;li><li><strong>Azure AD Provisioning Service<&sol;strong>&nbsp&semi;&&num;8211&semi; Uses the SCIM 2&period;0 protocol for automatic provisioning&period; The service connects to the SCIM endpoint for the application and uses the SCIM user object schema and REST APIs to automate the provisioning and de-provisioning of users and groups&period;<&sol;li><li><strong>Azure AD<&sol;strong>&nbsp&semi;&&num;8211&semi; User repository used to manage the lifecycle of identities and their entitlements&period;<&sol;li><li><strong>Target system<&sol;strong>&nbsp&semi;&&num;8211&semi; Application or system that has SCIM endpoint and works with the Azure AD provisioning to enable automatic provisioning of users and groups&period;<&sol;li><&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<p>The key is keeping your identity systems up to date&period; If a user can be automatically deprovisioned from Azure AD&comma; as soon as they&&num;8217&semi;re removed from your Application&comma; i&period;e&period; HR system&semi; you have less worry about a possible breach&period;<&sol;p>&NewLine;