Summary and recommendation
Cornerstone OnDemand, the enterprise learning management system, does not offer native SCIM provisioning despite being a critical application for employee training and compliance tracking. While Cornerstone integrates with Okta and OneLogin for SCIM-based provisioning, this requires Enterprise-level pricing (averaging ~$69,000/year) and complex OAuth 2.0 API setup. More concerning, Microsoft Entra ID provisioning integration has been deprecated and is being removed entirely, leaving organizations using Microsoft's identity platform without automated provisioning options.
This creates a significant operational gap for IT teams managing large employee bases who need learning assignments, compliance training tracking, and manager hierarchy synchronization. Manual user management becomes particularly problematic in learning management systems where employees frequently change roles, departments, or learning requirements. The deprecation of Microsoft Entra provisioning forces organizations to either switch identity providers, accept manual processes, or implement costly workarounds.
The strategic alternative
Cornerstone OnDemand gates SCIM behind Enterprise. Skip the Enterprise plan upgrade and automate complete outcomes across your stack. We maintain the integration layer underneath. You focus on judgment, not plumbing.
Quick SCIM facts
| SCIM available? | Yes |
| SCIM tier required | Enterprise |
| SSO required first? | Yes |
| SSO available? | Yes |
| SSO protocol | SAML 2.0 |
| Documentation | Official docs |
Supported identity providers
| IdP | SSO | SCIM | Notes |
|---|---|---|---|
| Okta | ✓ | ✓ | OIN app with full provisioning |
| Microsoft Entra ID | ✓ | ❌ | SSO only |
| Google Workspace | ✓ | JIT only | SAML SSO with just-in-time provisioning |
| OneLogin | ✓ | ✓ | Supported |
The cost of not automating
Without SCIM (or an alternative like Stitchflow), your IT team manages Cornerstone OnDemand accounts manually. Here's what that costs:
The Cornerstone OnDemand pricing problem
Cornerstone OnDemand gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.
Tier comparison
| Plan | Price | SSO | SCIM |
|---|---|---|---|
| Okta SCIM | Enterprise tier | OAuth 2.0 setup required, complex configuration | |
| OneLogin SCIM | Enterprise tier | Limited to OneLogin customers only | |
| Microsoft Entra | DEPRECATED | ||
| Manual provisioning | All tiers |
Provisioning options
| Method | Availability | Limitations |
|---|---|---|
| Okta SCIM | Enterprise tier | OAuth 2.0 setup required, complex configuration |
| OneLogin SCIM | Enterprise tier | Limited to OneLogin customers only |
| Microsoft Entra | DEPRECATED | Being removed - no longer viable |
| Manual provisioning | All tiers | No automation, manual account management |
Enterprise pricing: ~$69,000/year average (custom quotes only)
What this means in practice
Organizations using Microsoft Entra ID face an immediate crisis - their existing provisioning integration is being sunset with no direct replacement. The recommended "Cornerstone Single Sign-On" app from the Gallery provides SSO but no automated provisioning.
For the remaining SCIM options
Additional constraints
Summary of challenges
- Cornerstone OnDemand supports SCIM but only at Enterprise tier (~$69,000/year average)
- Google Workspace users get JIT provisioning only, not full SCIM
- Our research shows teams manually provisioning this app spend significant hidden costs annually
What Cornerstone OnDemand actually offers for identity
SCIM Provisioning (Enterprise plan only)
Cornerstone supports SCIM provisioning, but only through specific IdP integrations:
| Feature | Okta | OneLogin | Microsoft Entra |
|---|---|---|---|
| Create users | ✓ Yes | ✓ Yes | ❌ Deprecated |
| Update attributes | ✓ Yes | ✓ Yes | ❌ Deprecated |
| Deactivate users | ✓ Yes | ✓ Yes | ❌ Deprecated |
| Group provisioning | ✓ Yes | ✓ Yes | ❌ Deprecated |
| Reactivate users | ✓ Yes | ✓ Yes | ❌ Deprecated |
Critical limitation: Microsoft deprecated their Entra ID provisioning integration for Cornerstone. If you're using Microsoft Entra, you're stuck with manual provisioning or third-party connectors like Aquera.
SAML SSO (Enterprise plan)
| Setting | Details |
|---|---|
| Protocol | SAML 2.0 |
| Initiation | SP and IdP initiated |
| JIT provisioning | ✓ Supported |
| Certificate requirement | SHA256 (older SHA1 deprecated) |
| Setup | Requires coordination with Cornerstone implementation team |
Enterprise Learning Platform Features
The Enterprise plan includes comprehensive LMS capabilities:
Reality check: If you just need SCIM for basic user provisioning, you're paying ~$69,000/year for an enterprise learning management system. Most IT teams only use 10-15% of Cornerstone's full feature set.
Microsoft Entra users: You're particularly stuck since Cornerstone removed native provisioning support for your IdP. You'll need workarounds or third-party solutions regardless of what you pay Cornerstone.
What IT admins are saying
Community sentiment on Cornerstone OnDemand's provisioning automation reveals significant platform dependency concerns:
- Microsoft Entra integration deprecated - Existing Azure AD customers losing automated provisioning capabilities
- Complex OAuth setup requirements - Okta provisioning demands OAuth 2.0 configuration beyond standard SAML
- Certificate management overhead - Manual SHA256 certificate upgrades required for SSO functionality
- Limited IdP flexibility - Effectively restricted to Okta and OneLogin for reliable SCIM provisioning
Microsoft Entra ID provisioning integration is DEPRECATED and being removed. Use newer 'Cornerstone Single Sign-On' app from Gallery instead, or Aquera connector for AD/Entra sync.
OAuth 2.0 required for Okta provisioning setup
The recurring theme
Cornerstone OnDemand's provisioning automation is becoming increasingly fragmented, with Microsoft customers losing native support entirely and other IdP users facing complex technical requirements that go well beyond standard SCIM implementations.
The decision
| Your Situation | Recommendation |
|---|---|
| Small L&D team (<25 learners) with Okta/OneLogin | Use native SCIM via Okta or OneLogin |
| Using Microsoft Entra ID for identity | Use Stitchflow: Entra integration deprecated |
| Enterprise deployment (100+ learners) | Use Stitchflow: avoid OAuth setup complexity |
| Multi-division learning programs | Use Stitchflow: simplified group management |
| Compliance-heavy industries | Use Stitchflow: guaranteed audit trail and support |
The bottom line
Cornerstone OnDemand offers SCIM through Okta and OneLogin, but Microsoft's deprecated Entra integration leaves many enterprises stranded. For organizations needing reliable provisioning automation without OAuth configuration headaches or IdP vendor lock-in, Stitchflow provides universal support at predictable enterprise pricing.
Make Cornerstone OnDemand workflows AI-native
Cornerstone OnDemand gates SCIM behind Enterprise. We build complete offboarding, user access reviews, and license workflows without that SCIM Tax upgrade.
Technical specifications
SCIM Version
2.0
Supported Operations
Create, Update, Deactivate, Groups
Supported Attributes
Not specifiedPlan requirement
Enterprise
Prerequisites
SSO must be configured first
Key limitations
- Microsoft Entra ID provisioning integration deprecated
- OAuth 2.0 required for Okta provisioning setup
- SSO certificate upgrades to SHA256 required
Configuration for Okta
Integration type
Okta Integration Network (OIN) app with SCIM provisioning
Prerequisite
SSO must be configured before enabling SCIM.
Where to enable
Required credentials
SCIM endpoint URL and bearer token (generated in app admin console).
Configuration steps
Enable Create Users, Update User Attributes, and Deactivate Users.
Provisioning trigger
Okta provisions based on app assignments (users or groups).
Full SCIM provisioning: Create, Deactivate, Update, Reactivate users. Group Push, Schema Discovery, Attribute Writeback supported. Requires OAuth 2.0 for API integration setup.
Cornerstone OnDemand gates SCIM behind Enterprise. Stitchflow automates complete workflows without that SCIM Tax upgrade.
Configuration for Entra ID
Integration type
Microsoft Entra Gallery app
Prerequisite
SSO must be configured before enabling SCIM.
Where to enable
IMPORTANT: Microsoft Entra provisioning integration is DEPRECATED and being removed. Use newer 'Cornerstone Single Sign-On' app from Gallery instead, or Aquera connector for AD/Entra sync.
Use Stitchflow for automated provisioning.
Unlock SCIM for
Cornerstone OnDemand
Cornerstone OnDemand gates SCIM behind Enterprise plan. We automate complete offboarding and access reviews across your stack without that SCIM Tax upgrade.
See how it works


