Stitchflow
BeyondTrust logo

BeyondTrust SCIM guide

Native SCIM

How to automate BeyondTrust user provisioning, and what it actually costs

Native SCIM requires Enterprise plan

Summary and recommendation

BeyondTrust supports SCIM for automated user provisioning, but only on Enterprise plans with custom pricing starting at $75,000+/year. While the SCIM implementation covers standard operations (create, update, deactivate users and groups), it requires complex security provider configuration that varies across BeyondTrust's different products (PRA, Remote Support, Password Safe). Some integrations even require AWS Lambda functions to handle OAuth client credentials properly.

For privileged access management, this creates a significant barrier. Organizations need automated provisioning for BeyondTrust more than most applications—privileged accounts require strict lifecycle management, and manual provisioning of vendor/contractor access creates security gaps. The enterprise-only pricing means smaller security teams face a massive licensing jump just to automate what should be standard user management.

The strategic alternative

BeyondTrust gates SCIM behind Enterprise. Skip the Enterprise plan upgrade and automate complete outcomes across your stack. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?Yes
SCIM tier requiredEnterprise
SSO required first?Yes
SSO available?Yes
SSO protocolSAML 2.0, OIDC, LDAP, Kerberos
DocumentationOfficial docs

Supported identity providers

IdPSSOSCIMNotes
OktaOIN app with full provisioning
Microsoft Entra IDGallery app with SCIM
Google WorkspaceJIT onlySAML SSO with just-in-time provisioning
OneLoginSupported

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages BeyondTrust accounts manually. Here's what that costs:

Source: Stitchflow aggregate data across apps with 2+ instances, normalized to 500 employees
Orphaned accounts (ex-employees with access)7
Unused licenses12
IT hours spent on manual management/year101 hours
Unused license cost/year$3,925
IT labor cost/year$6,088
Cost of compliance misses/year$1,741
Total annual financial impact$11,754

The BeyondTrust pricing problem

BeyondTrust gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Plan Structure

PlanPriceSSOSCIM
StandardQuote-based
Enterprise$75,000+/year

Note: BeyondTrust uses custom enterprise pricing across all tiers. SCIM is available through security provider configurations for automated user provisioning and deprovisioning.

What this means in practice

The Enterprise requirement creates substantial cost increases:

Minimum entry
$75,000+ annual commitment just to access SCIM provisioning
No gradual scaling
Organizations can't start with basic provisioning and upgrade later
All-or-nothing approach
Must purchase full Enterprise feature set to automate user lifecycle

For privileged access management, this pricing structure is particularly problematic because:

Organizations often need SCIM specifically for security compliance
Automated deprovisioning is critical when employees leave
Manual management of privileged accounts creates security risks

Additional constraints

Complex configuration
SCIM requires security provider setup across different BeyondTrust products (PRA, Password Safe, Remote Support), each with potentially different configurations.
Product-specific implementations
Different BeyondTrust solutions may require separate SCIM configurations, multiplying complexity.
Quote-based pricing
No transparent pricing makes budgeting difficult, with reported discounts of 40-60% suggesting significant markup on list prices.
AWS Lambda dependency
Some integrations (like Okta with Password Safe) require AWS Lambda for OAuth client credentials, adding third-party dependencies.

Summary of challenges

  • BeyondTrust supports SCIM but only at Enterprise tier ($75,000+/year (quote-based))
  • Google Workspace users get JIT provisioning only, not full SCIM
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What the upgrade actually includes

BeyondTrust doesn't sell SCIM à la carte. It's bundled with Enterprise-level privileged access management features:

SCIM 2.0 automated provisioning via security providers
SAML/OIDC single sign-on across all PAM modules
Privileged Remote Access (PRA) management
Password Safe vault with automated rotation
Remote Support session management
Advanced session monitoring and recording
Compliance reporting and audit trails
24/7 enterprise support with dedicated CSMs

The complexity compounds with BeyondTrust's modular architecture—different products (PRA, Remote Support, Password Safe) may require separate SCIM configurations through different security providers.

Stitchflow Insight

The challenge: BeyondTrust's Enterprise licensing starts at $75,000+/year because you're buying a comprehensive PAM platform. If your primary need is just automated user provisioning for basic privileged access, you're paying for vault management, session recording, and compliance features you may not need. We estimate ~60% of BeyondTrust's Enterprise features are overkill for organizations that simply want to automate onboarding/offboarding for their privileged accounts.

What IT admins are saying

Community sentiment on BeyondTrust's SCIM implementation is mixed, with most complaints centered around complexity and enterprise pricing barriers. Common complaints:

  • Enterprise licensing requirement blocks access for smaller security teams
  • Complex security provider configuration across different BeyondTrust products
  • Inconsistent SCIM behavior between Password Safe and Remote Support
  • High minimum pricing that forces evaluation of alternatives

The configuration complexity for getting SCIM working properly with our identity provider was much higher than expected. Different products seem to handle it differently.

Reddit r/sysadmin

We wanted automated provisioning but the enterprise pricing was a non-starter. Ended up staying on manual processes.

IT Central Station review

The recurring theme

BeyondTrust's enterprise-only SCIM creates a significant barrier for security teams that need automated privileged access provisioning but can't justify the high licensing costs.

The decision

Your SituationRecommendation
Not on Enterprise, need SCIMUse Stitchflow: avoid the $75K+ enterprise commitment
Small PAM footprint with privileged usersUse Stitchflow: get SCIM without enterprise licensing overhead
Managing vendor/contractor privileged accessUse Stitchflow: automate temp access without complex security provider configs
Already on Enterprise with security providers configuredUse native SCIM: you're paying for enterprise features
Large enterprise PAM deploymentEvaluate Enterprise: SCIM bundled with advanced security controls

The bottom line

BeyondTrust gates SCIM behind Enterprise. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Make BeyondTrust workflows AI-native

BeyondTrust gates SCIM behind Enterprise. We build complete offboarding, user access reviews, and license workflows without that SCIM Tax upgrade.

No Enterprise upgrade required
Less than a week, start to finish (~2 hours of your time)
We maintain the integration layer underneath
Book a Demo

Technical specifications

SCIM Version

2.0

Supported Operations

Create, Update, Deactivate, Groups

Supported Attributes

Not specified

Plan requirement

Enterprise

Prerequisites

SSO must be configured first

Key limitations

  • Enterprise licensing required
  • Security provider configuration complexity
  • Different products (PRA, RS) may have different configs

Configuration for Okta

Integration type

Okta Integration Network (OIN) app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Okta Admin Console → Applications → BeyondTrust → Provisioning

Required credentials

SCIM endpoint URL and bearer token (generated in app admin console).

Configuration steps

Enable Create Users, Update User Attributes, and Deactivate Users.

Provisioning trigger

Okta provisions based on app assignments (users or groups).

Password Safe uses AWS Lambda for SCIM due to OAuth client credentials. Supports Group Push. Remote Support uses SAML JIT.

BeyondTrust gates SCIM behind Enterprise. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Configuration for Entra ID

Integration type

Microsoft Entra Gallery app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Entra admin center → Enterprise applications → BeyondTrust → Provisioning

Required credentials

Tenant URL (SCIM endpoint) and Secret token (bearer token from app admin console).

Configuration steps

Set Provisioning Mode = Automatic, configure SCIM connection.

Provisioning trigger

Entra provisions based on user/group assignments to the enterprise app.

Sync behavior

Entra provisioning runs on a scheduled cycle (typically every 40 minutes).

SAML SSO with Entra ID. SCIM available for PRA. Some products may use SailPoint for provisioning.

BeyondTrust gates SCIM behind Enterprise. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Unlock SCIM for
BeyondTrust

BeyondTrust gates SCIM behind Enterprise plan. We automate complete offboarding and access reviews across your stack without that SCIM Tax upgrade.

See how it works
Admin Console
Directory
Applications
BeyondTrust logo
BeyondTrust
via Stitchflow

Last updated: 2026-01-11

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

Delinea logo

Delinea

SCIM Tax

Privileged Access Management (PAM)

SCIM StatusIncluded
Manual Cost$11,754/yr

Delinea Secret Server supports full SCIM 2.0 provisioning with PAM-specific extensions for privileged access management. However, SCIM functionality is restricted to Enterprise plans, which carry custom enterprise pricing with a median cost of $19,705/year according to Vendr data. For organizations on Standard plans seeking automated privileged user provisioning, upgrading to Enterprise represents a significant cost increase primarily driven by advanced PAM features they may not need. The privileged access use case makes manual provisioning particularly problematic. Security teams need rapid provisioning and deprovisioning of privileged accounts to maintain zero-trust principles and comply with SOC 2 or similar frameworks. Manual processes create delays in granting just-in-time privileged access and increase the risk of orphaned privileged accounts—a critical security vulnerability that auditors flag immediately.

View full guide
8x8 logo

8x8

SCIM Tax

UCaaS / Business Communications

SCIM StatusIncluded
Manual Cost$11,754/yr

8x8 supports SCIM 2.0 for automated user provisioning, but only on their quote-based X Series plans (previously $24-44/user/month range before they moved to custom pricing). While SCIM can create, update, and deactivate users, it has critical gaps that create ongoing manual overhead: license assignment must be done manually after every user is provisioned, users can't be deleted (only deactivated), and provisioned users don't automatically appear in the Company Directory. For IT teams managing a unified communications platform that typically covers all employees, these limitations defeat much of SCIM's purpose. You're still manually touching every user account to assign licenses and ensure directory visibility. The lack of user deletion support also creates compliance headaches when employees leave - accounts accumulate as "deactivated" rather than being properly removed.

View full guide
Absorb LMS logo

Absorb LMS

SCIM Tax

Learning Management System (LMS)

SCIM StatusIncluded
Manual Cost$11,754/yr

Absorb LMS supports native SCIM provisioning, but only on Enterprise plans with SSO as a required paid add-on. Even with SCIM enabled, the implementation has critical limitations: SAML provisioning only creates accounts on first login and never updates existing users, and full user provisioning requires the specific "Absorb 5 - New Learner Experience" version. For organizations managing compliance training across hundreds or thousands of learners, these gaps create ongoing manual work. The SSO-as-add-on model means you're paying extra fees on top of already custom Enterprise pricing ($6-12/user/month base, but varies significantly). For learning management systems handling external partners, contractors, and employees across different access levels, the inability to update existing user attributes through SAML provisioning forces IT teams into manual account management—exactly what automated provisioning should eliminate.

View full guide