Stitchflow
Microsoft Azure / Entra ID logo

Microsoft Azure / Entra ID SCIM guide

Native SCIM

How to automate Microsoft Azure / Entra ID user provisioning, and what it actually costs

Native SCIM requires Premium P1/P2 plan

Summary and recommendation

Microsoft Entra ID (formerly Azure AD) is itself an identity provider that provisions users TO other applications via SCIM. It includes native SCIM provisioning capabilities, but only for Premium P1 ($6/user/month) or P2 ($9/user/month) license holders. Organizations on the free tier cannot automate user provisioning to their SaaS applications at all. Key limitations include 20-40 minute sync intervals, no support for nested groups, and removed attributes not syncing back to target applications.

For organizations with hundreds or thousands of users, the Premium licensing requirement creates a significant cost barrier. A 500-person company moving from free Entra ID to P1 just for provisioning would pay $36,000/year in additional licensing. Many organizations need automated provisioning for compliance and security, but don't require the other Premium features like conditional access policies or advanced security reports.

The strategic alternative

Stitchflow provides SCIM-level provisioning through resilient browser automation that works with any Entra ID plan, including free. Connect your existing Entra ID instance to automate user lifecycle management across all your SaaS applications. Flat pricing under $5K/year, regardless of user count.

Quick SCIM facts

SCIM available?Yes
SCIM tier requiredPro
SSO required first?Yes
SSO available?Yes
SSO protocolSAML 2.0, OIDC, WS-Federation
DocumentationOfficial docs

Supported identity providers

IdPSSOSCIMNotes
OktaSSO only
Microsoft Entra IDGallery app with SCIM
Google WorkspaceJIT onlySAML SSO with just-in-time provisioning
OneLoginSupported

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages Microsoft Azure / Entra ID accounts manually. Here's what that costs:

Source: Stitchflow aggregate data across apps with 2+ instances, normalized to 500 employees
Orphaned accounts (ex-employees with access)7
Unused licenses12
IT hours spent on manual management/year101 hours
Unused license cost/year$3,925
IT labor cost/year$6,088
Cost of compliance misses/year$1,741
Total annual financial impact$11,754

The Microsoft Azure / Entra ID pricing problem

Microsoft Azure / Entra ID gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Tier comparison

PlanPriceSSOSCIM
Entra ID Free$0/user/mo
Entra ID Premium P1$6/user/mo
Entra ID Premium P2$9/user/mo

Plan Structure

PlanPriceSCIM Provisioning
Entra ID Free$0/user/mo
Entra ID Premium P1$6/user/mo
Entra ID Premium P2$9/user/mo

Note: Premium P1 and P2 are also included in Microsoft 365 E3 and E5 plans respectively. Organizations already on these M365 plans have SCIM provisioning available.

What this means in practice

For organizations currently on Entra ID Free wanting automated provisioning:

Team SizeUpgrade to P1Upgrade to P2
100 users$7,200/year$10,800/year
500 users$36,000/year$54,000/year
1,000 users$72,000/year$108,000/year

Calculation: License price × users × 12 months

Additional constraints

Sync limitations
20-40 minute sync intervals mean provisioning changes aren't immediate, creating delays during onboarding/offboarding.
Nested group restrictions
Entra ID doesn't sync nested groups via SCIM, limiting complex organizational structure mapping.
Attribute sync gaps
Removed attributes in Entra ID don't automatically sync deletions to target applications, creating data inconsistency.
Technical requirements
Target applications must support TLS 1.2 for SCIM connections.

Summary of challenges

  • Microsoft Azure / Entra ID supports SCIM but only at Pro tier (custom pricing)
  • Google Workspace users get JIT provisioning only, not full SCIM
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What the upgrade actually includes

Entra ID Premium P1/P2 isn't just about SCIM provisioning. You're buying Microsoft's full enterprise identity platform:

SCIM 2.0 automated provisioning to 1000+ gallery apps
Advanced conditional access policies
Identity governance and access reviews
Privileged Identity Management (P2 only)
Risk-based authentication and identity protection (P2)
Multi-factor authentication enforcement
Custom domain branding
Advanced reporting and analytics
Premium support

The bigger issue: Entra ID's SCIM sync runs every 20-40 minutes, doesn't support nested groups, and requires extensive configuration for each target application. You get the feature, but not necessarily the smooth automation experience you're expecting.

Stitchflow Insight

The reality: if you're already using Microsoft 365 E3/E5, you likely have Premium P1/P2 included. But if you're upgrading specifically for SCIM provisioning, you're paying for enterprise-grade identity features that smaller teams rarely need. We estimate ~60% of Premium features are overkill for organizations that just want to automate user provisioning to their SaaS applications.

What IT admins are saying

Community sentiment on Microsoft Entra ID's SCIM provisioning is mixed, with licensing costs being the primary pain point. Common complaints:

  • Premium P1/P2 licensing required just to enable SCIM provisioning ($6-9/user/month)
  • Nested group limitations breaking organizational hierarchies in target apps
  • 20-40 minute sync delays causing user access issues during onboarding
  • Complex licensing tiers making cost planning difficult for large deployments

We're paying $6 per user per month just to get basic provisioning that should be included. It adds up fast when you have 500+ users.

Reddit r/sysadmin

The nested group limitation is a real problem. Our organizational structure doesn't map cleanly without that support.

Microsoft Tech Community

20-40 minute sync delays mean new hires are sitting around waiting for access. Not exactly the smooth onboarding experience we want.

Spiceworks Community

The recurring theme

While Entra ID offers robust SCIM capabilities, the premium licensing requirement and technical limitations create friction for organizations trying to implement automated provisioning at scale.

The decision

Your SituationRecommendation
On Entra ID Free, need SCIM provisioningUse Stitchflow: avoid the $6/user/mo P1 upgrade
Small team (<100 users), basic provisioning needsUse native SCIM with P1: it's already cost-competitive
Large organization (500+ users), complex provisioningUse native SCIM with P2: you need the advanced features
Need provisioning but don't want Microsoft license dependencyUse Stitchflow: works with any IdP including Google Workspace
Nested group requirements or sub-20 minute sync intervalsUse Stitchflow: native SCIM has known limitations here

The bottom line

Microsoft Entra ID's SCIM requires Premium P1 ($6/user/mo) or P2 ($9/user/mo) licensing, making it expensive for organizations currently on the free tier. For smaller teams or those wanting to avoid Microsoft's per-user licensing model, Stitchflow delivers the same provisioning automation at flat-rate pricing.

Automate Microsoft Azure / Entra ID without the tier upgrade

Stitchflow delivers SCIM-level provisioning through resilient browser automation, backed by 24/7 human in the loop for Microsoft Azure / Entra ID at <$5K/year, flat, regardless of team size.

Works alongside or instead of native SCIM
Syncs with your existing IdP (Okta, Entra ID, Google Workspace)
Automates onboarding and offboarding
SOC 2 Type II certified
24/7 human-in-the-loop monitoring
Book a Demo

Technical specifications

SCIM Version

2.0

Supported Operations

Create, Update, Deactivate, Groups

Supported Attributes

Not specified

Plan requirement

Pro

Prerequisites

SSO must be configured first

Key limitations

  • Requires P1 or P2 license for SCIM provisioning
  • Nested groups not supported in SCIM sync
  • Removed attributes not synced back to target apps
  • Sync interval 20-40 minutes
  • TLS 1.2 required

Configuration for Entra ID

Integration type

Microsoft Entra Gallery app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Entra admin center → Enterprise applications → Microsoft Azure / Entra ID → Provisioning

Required credentials

Tenant URL (SCIM endpoint) and Secret token (bearer token from app admin console).

Configuration steps

Set Provisioning Mode = Automatic, configure SCIM connection.

Provisioning trigger

Entra provisions based on user/group assignments to the enterprise app.

Sync behavior

Entra provisioning runs on a scheduled cycle (typically every 40 minutes).

Entra ID IS the provisioning source. Supports SCIM 2.0 to provision users to 1000s of gallery apps.

Native SCIM is available on Pro. Use Stitchflow if you need provisioning without the tier upgrade.

Unlock SCIM for
Microsoft Azure / Entra ID

Microsoft Azure / Entra ID gates automation behind Premium P1/P2 plan. Stitchflow delivers the same SCIM outcomes for a flat fee.

See how it works
Admin Console
Directory
Applications
Microsoft Azure / Entra ID logo
Microsoft Azure / Entra ID
via Stitchflow

Last updated: 2026-01-11

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

8x8 logo

8x8

SCIM Tax

UCaaS / Business Communications

SCIM StatusIncluded
Manual Cost$11,754/yr

8x8 supports SCIM 2.0 for automated user provisioning, but only on their quote-based X Series plans (previously $24-44/user/month range before they moved to custom pricing). While SCIM can create, update, and deactivate users, it has critical gaps that create ongoing manual overhead: license assignment must be done manually after every user is provisioned, users can't be deleted (only deactivated), and provisioned users don't automatically appear in the Company Directory. For IT teams managing a unified communications platform that typically covers all employees, these limitations defeat much of SCIM's purpose. You're still manually touching every user account to assign licenses and ensure directory visibility. The lack of user deletion support also creates compliance headaches when employees leave - accounts accumulate as "deactivated" rather than being properly removed.

View full guide
Absorb LMS logo

Absorb LMS

SCIM Tax

Learning Management System (LMS)

SCIM StatusIncluded
Manual Cost$11,754/yr

Absorb LMS supports native SCIM provisioning, but only on Enterprise plans with SSO as a required paid add-on. Even with SCIM enabled, the implementation has critical limitations: SAML provisioning only creates accounts on first login and never updates existing users, and full user provisioning requires the specific "Absorb 5 - New Learner Experience" version. For organizations managing compliance training across hundreds or thousands of learners, these gaps create ongoing manual work. The SSO-as-add-on model means you're paying extra fees on top of already custom Enterprise pricing ($6-12/user/month base, but varies significantly). For learning management systems handling external partners, contractors, and employees across different access levels, the inability to update existing user attributes through SAML provisioning forces IT teams into manual account management—exactly what automated provisioning should eliminate.

View full guide
Airbase logo

Airbase

SCIM Tax

Spend Management / Corporate Cards

SCIM StatusIncluded
Manual Cost$11,754/yr

Airbase supports SCIM provisioning, but only on Enterprise plans starting around $8,500/year. While SCIM works with all major identity providers (Okta, Entra ID, Google Workspace), the Enterprise requirement creates a significant barrier for smaller finance teams who need automated provisioning for spend management but can't justify enterprise-level spend management software costs. This creates a particular challenge in finance applications where rapid provisioning and deprovisioning is critical for corporate card access and financial controls. Manual user management means delayed access for new employees needing corporate cards, and more critically, potential security gaps when departing employees retain access to spend management systems. For finance teams handling sensitive financial data and corporate spending, these delays and oversights create both operational friction and compliance risks.

View full guide