SCIM is a standard for automating the exchange of user identity information between multiple domains, and is an acronym for Systems for Cross-domain Identity Management. The first version, SCIM 1.0, was released in 2011, followed by an upgrade to SCIM 2.0 in 2015.
Why SCIM Is Needed
Ideally, user management for information systems used by companies and organizations would work so that "all user identity information is tied to a single domain, and any change to that domain information is automatically reflected across all systems." This would prevent data inconsistencies and mean that changes only need to be made once.
In reality, however, it is virtually impossible for all systems to be tied to a single domain, so organizations have had to maintain multiple domains, systems, and user identity databases.
To manage user information accurately and efficiently by linking information across these multiple systems, a standard for exchanging user identity information was needed. Using such a standard to exchange data standardizes the way data is linked and minimizes the effort required. SCIM was created to meet this need and has since been implemented in many identity management products. The spread of cloud services, in particular, has made the need for SCIM even greater.
In the past, internal corporate systems were designed around a central domain, such as Active Directory, with nearly all systems linked to it. However, as the business use of cloud services (especially SaaS) became commonplace, in-house development and deployment on physical servers declined sharply, drawing attention to SCIM as a standard that makes it easy to link internal business systems with SaaS.
How SCIM Differs from the Earlier SPML Standard
Before SCIM appeared, a standard called "SPML (Service Provisioning Markup Language)" had been proposed for linking user identities. Developed by OASIS, a standards organization, SPML came into use in 2003, but it never became widespread due to interoperability issues.
SCIM emerged as a standard that improved on SPML's weak interoperability, and as a result it has been adopted by many identity management products up to the present day.
What SCIM Makes Possible
Using SCIM makes it possible to easily propagate changes whenever user identity information is updated. Specifically, in addition to the most basic operations of "creating and deleting records," it also enables the management of information such as user attributes, attribute schemas, and group access permissions.
For example, when a company hires a new employee, that employee is added to the internal HR database (and conversely, removed from the database upon resignation). With SCIM, changes made in the internal HR database can be automatically reflected in external cloud services linked via SCIM, such as Azure AD, Salesforce.com, and G Suite (note that SCIM uses JSON or XML formatted data via a REST API).
Without SCIM, connecting systems manually would require writing programs to integrate with each company's identity management system, which is highly inefficient. For this reason, the more cloud services a company uses, the greater the benefit of using SCIM for data integration.
Examples of Products That Use SCIM
Many products use SCIM; a few examples are listed below.
- G Suite
- Slack
- Azure AD
- TrustLogin (our product)
- LDAP Manager
- CA Mobile API Gateway
- Onelogin
- Okta
- 1password
The Future of SCIM
Because SCIM is ultimately just a standard for data integration, it does not attract much attention on its own. Since its introduction in 2011, it has steadily gained adoption, mainly among identity management and identity federation products, and our single sign-on product, "TrustLogin," is one of them.
As of this writing (February 2019), no identity federation standard offering greater convenience than SCIM has emerged, so it is expected to continue to gradually gain adoption.