Loading
Salesforce now sends email only from verified domains. Read More
Own from Salesforce
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          Using the System for Cross-Domain Identity (SCIM) with Own Data Platform

          Using the System for Cross-Domain Identity (SCIM) with Own Data Platform

          SCIM (System for Cross-domain Identity Management) is an open standard designed to automate and simplify user identity management across systems. A standardized schema ensures smooth operations between different Identity Providers (IdPs) and Own app.

          SCIM is available for accounts where single sign-on (SSO) is both configured and activated.

          You can integrate SCIM if you use Okta, Azure, or SailPoint as your IdP.

          Own SCIM complies with SCIM 2.0 and RESTful APIs using Header Authentication, allowing your IdP to communicate with Own app.

          Key operations are:

          • Provisioning: Automatically creates user accounts.
          • Deprovisioning: The removal of user accounts when no longer needed.

          For detailed SCIM specifications, see: RFC 7643 and RFC 7644.

          Benefits of SCIM

          • Compliance: Centralized management simplifies regulatory requirements adherence.
          • Streamlined Identity Management:
          • Improved security: This prevents orphaned accounts by automating deprovisioning, thus reducing security risks.
          Note
          Note Only Master Admin users and Security Admin users can enable or disable SCIM provisioning.

          Default Parameters for New Users

          SCIM adds users to the Own app with these parameters.

          • Default Role: Read-Only.
          • Business Unit: Default Business Unit.
            Note
            Note

            The business unit requires the name Default Business Unit.

            Deleting or changing the business unit name causes the integration to fail.

          Use the UI to change the role.

           
          Loading
          Salesforce Help | Article