What is user and group provisioning with SCIM?
User and group provisioning with SCIM (System for Cross-domain Identity Management) allows HP Insights to synchronize users and groups automatically from your identity provider, such as Microsoft Entra ID, Okta, or Ping Identity. Instead of manually creating and maintaining users and groups in HP Insights, administrators manage users and groups in the identity provider, which becomes the source of truth. Changes are then synchronized to HP Insights through the SCIM connection.
SCIM supports the following synchronization activities:
- Create users and groups: Users and groups created in the identity provider are automatically added to HP Insights. Group support varies by provider. For example, Ping Identity does not support user groups; see the provider-specific setup guide for details.
- Update user information: Changes to user attributes, such as names and email addresses, as well as changes to group memberships, are synchronized to HP Insights.
To establish the connection, HP Insights generates a Tenant URL and SCIM Token. The identity provider uses these credentials to authenticate and securely communicate with the HP Insights SCIM endpoint.
When SCIM provisioning is enabled:
- User and group management occurs in the identity provider.
- Changes made in the identity provider are automatically synchronized to HP Insights.
- Administrators typically manage users and group memberships in the identity provider rather than directly in HP Insights.
- User access and role assignments can be managed consistently through identity provider groups and group mappings.
Once a SCIM connection has been established, we recommend using SCIM as the primary method for managing users and groups rather than importing users directly into HP Insights. You can still use import functions to add card information for users if needed.
Important: Avoid mixing provisioning methods
Using SCIM alongside manual user creation or other automatic provisioning workflows can lead to duplicate accounts, synchronization inconsistencies, or unexpected user lifecycle behavior. When SCIM is enabled, the identity provider should generally be treated as the authoritative source for user and group management.
Note
SCIM provisioning synchronizes identity information and group membership. Authentication continues to be handled by the configured identity provider through OpenID Connect (OIDC) or SAML.
SCIM provisioning automates the synchronization of users and groups from your identity provider to HP Insights, reducing administrative effort, improving security, and ensuring user access remains up to date.