Provisioning Settings
SCIM-managed toggle, default role, and identity claim on Settings → SCIM.
Provisioning Settings
Second section on Settings → SCIM. Copy: Control how SCIM-provisioned users are managed in your organization. Requires manage-settings.
SCIM-Managed Provisioning — When enabled, only SCIM-provisioned users can access this tenant. JIT login provisioning is disabled.
Default SCIM Role — Role assigned to users provisioned via SCIM who do not match any group role mapping. Use No Access to require explicit group membership for platform permissions. Options: No Access, Read Only, Analyst, Admin.
Identity Claim — OIDC claim whose value matches SCIM externalId. Leave empty to use the IdP subject (sub). For Entra ID, set to custom:idp_id and map oid in your Cognito IdP config. Placeholder: sub (default). Saves on blur.
SCIM users show on Settings → Users with a scim: member.