# SCIM overview

*Automatic provisioning through SCIM is available starting in* [*Enterprise Edition*](https://www.sonarsource.com/plans-and-pricing/enterprise/)*.*

[SCIM](https://www.rfc-editor.org/rfc/rfc7644) is a protocol used to automatically manage user identity between an identity provider (IdP) and a service provider (SP, SonarQube Server in this context). If you manage permissions through groups, SCIM helps you automatically maintain user existence and permissions in SonarQube Server.

{% hint style="info" %}
For SCIM to work with SonarQube Server, the Identity Provider (IdP) needs to be able to access the SonarQube server, meaning it needs to be reachable from the IdP’s environment. This typically involves exposing the on-premise SonarQube instance to the IdP’s network, either directly or through a secure connection (e.g. public URL, provisioning agent).
{% endhint %}

You can enable SCIM to automate user and group provisioning in SonarQube Server. Supported operations from your IdP are:

* User creation
* User deletion
* Group creation
* Group membership addition and removal
* Group name update
* Group deletion

You can set up automatic provisioning between SonarQube Server and the following IdPs:

* Microsoft Entra ID: see [SCIM with Microsoft Entra ID](/sonarqube-server/instance-administration/authentication/saml/scim/scim-provisioning-with-azure-ad.md)
* Okta: see [SCIM with Okta](/sonarqube-server/instance-administration/authentication/saml/scim/scim-provisioning-with-okta.md)

When you enable automatic provisioning through SCIM, all users and groups become read-only in SonarQube Server. The only operations available in SonarQube Server are local group deletion and local user deactivation (local meaning not managed by SCIM).

Note that before you can configure SCIM provisioning, you must configure SAML.


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://docs.sonarsource.com/sonarqube-server/instance-administration/authentication/saml/scim/overview.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
