Provisioning Settings
SCIM-managed toggle, default role, and identity claim on Settings → SCIM.
The Provisioning Settings section of Settings → SCIM controls how SCIM-provisioned users are managed in your organization. Only Admins can change these settings.
SCIM-Managed Provisioning
Turn on SCIM-Managed Provisioning so that only SCIM-provisioned users can access this tenant. While it is on, users are no longer created automatically when they first sign in.
Guard shows SCIM-managed provisioning enabled or SCIM-managed provisioning disabled.
Default SCIM Role
Default SCIM Role is the role given to SCIM users who do not match any group in Group Role Mapping. Choose No Access, Read Only, Analyst, or Admin. The default is Read Only.
Choose No Access to require explicit group membership before a SCIM user gets platform permissions.
Guard shows Default SCIM role updated.
Identity Claim
Identity Claim is the sign-in claim Guard uses to match a signed-in user to their SCIM record. Leave it empty to use the IdP subject (sub), shown as the placeholder sub (default). For Entra ID, set it to custom:idp_id.
The value saves when you click out of the field. Guard shows Identity claim updated.
Checking provisioned users
In the users list, SCIM users show an authentication method of SCIM Provisioned and a status of Active or Deactivated.