Stitchflow
CyberArk logo

CyberArk SCIM guide

Native SCIM

How to automate CyberArk user provisioning, and what it actually costs

Native SCIM requires Enterprise plan

Summary and recommendation

CyberArk Identity supports SCIM 2.0 for both inbound provisioning (receiving users from Azure AD/Entra ID) and outbound provisioning (sending users to downstream applications). However, SCIM functionality is limited to Enterprise pricing, which starts at custom enterprise rates with a median annual cost of $19,705 according to Vendr data. The platform restricts SCIM provisioning to SAML-enabled applications only and requires role-based filtering, creating configuration complexity for multi-app provisioning scenarios.

This limitation means IT teams managing CyberArk Identity deployments face a significant cost barrier to automate user lifecycle management. While CyberArk excels as a privileged access management platform, the enterprise-only SCIM requirement forces organizations to either accept manual user provisioning workflows or commit to substantial licensing costs that may exceed their identity management budget—especially problematic given CyberArk's positioning as a premium PAM solution rather than a general-purpose identity provider.

The strategic alternative

CyberArk gates SCIM behind Enterprise. Skip the Enterprise plan upgrade and automate complete outcomes across your stack. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?Yes
SCIM tier requiredEnterprise
SSO required first?Yes
SSO available?Yes
SSO protocolSAML 2.0
DocumentationOfficial docs

Supported identity providers

IdPSSOSCIMNotes
OktaOIN app with full provisioning
Microsoft Entra IDGallery app with SCIM
Google WorkspaceJIT onlySAML SSO with just-in-time provisioning
OneLoginSupported

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages CyberArk accounts manually. Here's what that costs:

Source: Stitchflow aggregate data across apps with 2+ instances, normalized to 500 employees
Orphaned accounts (ex-employees with access)7
Unused licenses12
IT hours spent on manual management/year101 hours
Unused license cost/year$3,925
IT labor cost/year$6,088
Cost of compliance misses/year$1,741
Total annual financial impact$11,754

The CyberArk pricing problem

CyberArk gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Plan Structure

PlanPriceSSOSCIM
Standard Editions$2-5/user/mo
EnterpriseCustom pricing

Note: CyberArk offers 5 workforce identity editions at $2-5/user/month, but SCIM provisioning is restricted to Enterprise customers only. Median annual spend is $19,705 based on Vendr data.

What this means in practice

Based on reported pricing ranges ($3,226-$44,501 annually):

ScenarioEstimated Annual CostSCIM Access
Small deployment$3,226-$10,000Likely requires Enterprise upgrade
Mid-market$10,000-$25,000Enterprise negotiation required
Large enterprise$25,000-$44,501Full SCIM included

CyberArk's custom pricing model makes it difficult to predict exact upgrade costs, but most organizations need to move from standard workforce identity licensing to full Enterprise to unlock SCIM.

Additional constraints

Professional services dependency
Complex multi-app provisioning scenarios often require CyberArk professional services engagement, adding implementation costs.
SAML prerequisite
SCIM provisioning only works with SAML-enabled applications, limiting the scope of automated provisioning.
Role-based filtering
SCIM sync is restricted by role-based filters, requiring careful configuration to ensure proper user access.
Premium positioning
As a PAM-focused platform, CyberArk's identity features come with enterprise-grade pricing that may exceed needs for pure provisioning use cases.

Summary of challenges

  • CyberArk supports SCIM but only at Enterprise tier (custom pricing)
  • Google Workspace users get JIT provisioning only, not full SCIM
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What the upgrade actually includes

CyberArk Identity doesn't sell SCIM à la carte. It's part of their enterprise identity platform that includes:

SCIM 2.0 automated provisioning (outbound to apps, inbound from Azure AD)
SAML 2.0 single sign-on as identity provider
Privileged access management (PAM) capabilities
Multi-factor authentication (MFA)
Risk-based authentication
Identity analytics and governance
Vault for privileged credentials
Session monitoring and recording
Professional services and implementation support

Stitchflow Insight

CyberArk positions itself as a comprehensive PAM and identity solution, not just a user provisioning tool. If you need privileged access controls and enterprise identity governance, the platform delivers significant value. However, if you simply want SCIM provisioning without the privileged access overhead, you're paying enterprise PAM prices (median $19,705/year) for basic user lifecycle automation. We estimate ~80% of CyberArk's feature set is irrelevant for teams that only need streamlined SCIM provisioning to business applications.

What IT admins are saying

Community sentiment on CyberArk's SCIM implementation reveals mixed experiences with complexity being the primary concern. Common complaints:

  • Complex multi-app provisioning configuration requiring specialized expertise
  • SCIM limited to SAML-enabled applications only
  • Enterprise-tier pricing barriers for smaller organizations
  • Professional services often required for proper setup and configuration

Complex configuration for multi-app provisioning

CyberArk Community Forum

The role-based filtering sounds good in theory but becomes a nightmare when you're trying to manage access across 20+ applications

Reddit r/sysadmin

The recurring theme

CyberArk's SCIM works well once configured, but the setup complexity and enterprise pricing create significant barriers for teams without dedicated PAM expertise.

The decision

Your SituationRecommendation
Need SCIM but don't want enterprise PAM costsUse Stitchflow: avoid the $19K+ annual CyberArk commitment
Already using CyberArk Identity for PAMUse native SCIM: you're paying enterprise rates already
Simple identity needs, don't need privileged access featuresUse Stitchflow: CyberArk is overkill for basic provisioning
Need to provision FROM another IdP to CyberArkEvaluate both: CyberArk has good inbound SCIM from Entra/Okta
Complex multi-app provisioning requirementsConsider Stitchflow: simpler than CyberArk's role-based filtering setup

The bottom line

CyberArk Identity is a premium PAM solution with enterprise pricing that happens to include SCIM provisioning. Unless you need privileged access management features, you're paying significantly more than necessary for basic user provisioning automation.

Make CyberArk workflows AI-native

CyberArk gates SCIM behind Enterprise. We build complete offboarding, user access reviews, and license workflows without that SCIM Tax upgrade.

No Enterprise upgrade required
Less than a week, start to finish (~2 hours of your time)
We maintain the integration layer underneath
Book a Demo

Technical specifications

SCIM Version

2.0

Supported Operations

Create, Update, Deactivate, Groups

Supported Attributes

Not specified

Plan requirement

Enterprise

Prerequisites

SSO must be configured first

Key limitations

  • SCIM for SAML-enabled apps only
  • Role-based filtering for provisioning
  • Incremental sync with optional daily full sync

Configuration for Okta

Integration type

Okta Integration Network (OIN) app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Okta Admin Console → Applications → CyberArk → Provisioning

Required credentials

SCIM endpoint URL and bearer token (generated in app admin console).

Configuration steps

Enable Create Users, Update User Attributes, and Deactivate Users.

Provisioning trigger

Okta provisions based on app assignments (users or groups).

CyberArk SCIM Server available in OIN. Supports Group Linking, Schema Discovery, and Attribute Writeback. Can provision Okta users to CyberArk Cloud Directory.

CyberArk gates SCIM behind Enterprise. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Configuration for Entra ID

Integration type

Microsoft Entra Gallery app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Entra admin center → Enterprise applications → CyberArk → Provisioning

Required credentials

Tenant URL (SCIM endpoint) and Secret token (bearer token from app admin console).

Configuration steps

Set Provisioning Mode = Automatic, configure SCIM connection.

Provisioning trigger

Entra provisions based on user/group assignments to the enterprise app.

Sync behavior

Entra provisioning runs on a scheduled cycle (typically every 40 minutes).

Full SCIM 2.0 support for provisioning Entra ID users to CyberArk Cloud Directory. Supports RBAC through Entra group access. B2B collaboration supported.

CyberArk gates SCIM behind Enterprise. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Unlock SCIM for
CyberArk

CyberArk gates SCIM behind Enterprise plan. We automate complete offboarding and access reviews across your stack without that SCIM Tax upgrade.

See how it works
Admin Console
Directory
Applications
CyberArk logo
CyberArk
via Stitchflow

Last updated: 2026-01-11

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

8x8 logo

8x8

SCIM Tax

UCaaS / Business Communications

SCIM StatusIncluded
Manual Cost$11,754/yr

8x8 supports SCIM 2.0 for automated user provisioning, but only on their quote-based X Series plans (previously $24-44/user/month range before they moved to custom pricing). While SCIM can create, update, and deactivate users, it has critical gaps that create ongoing manual overhead: license assignment must be done manually after every user is provisioned, users can't be deleted (only deactivated), and provisioned users don't automatically appear in the Company Directory. For IT teams managing a unified communications platform that typically covers all employees, these limitations defeat much of SCIM's purpose. You're still manually touching every user account to assign licenses and ensure directory visibility. The lack of user deletion support also creates compliance headaches when employees leave - accounts accumulate as "deactivated" rather than being properly removed.

View full guide
Absorb LMS logo

Absorb LMS

SCIM Tax

Learning Management System (LMS)

SCIM StatusIncluded
Manual Cost$11,754/yr

Absorb LMS supports native SCIM provisioning, but only on Enterprise plans with SSO as a required paid add-on. Even with SCIM enabled, the implementation has critical limitations: SAML provisioning only creates accounts on first login and never updates existing users, and full user provisioning requires the specific "Absorb 5 - New Learner Experience" version. For organizations managing compliance training across hundreds or thousands of learners, these gaps create ongoing manual work. The SSO-as-add-on model means you're paying extra fees on top of already custom Enterprise pricing ($6-12/user/month base, but varies significantly). For learning management systems handling external partners, contractors, and employees across different access levels, the inability to update existing user attributes through SAML provisioning forces IT teams into manual account management—exactly what automated provisioning should eliminate.

View full guide
Airbase logo

Airbase

SCIM Tax

Spend Management / Corporate Cards

SCIM StatusIncluded
Manual Cost$11,754/yr

Airbase supports SCIM provisioning, but only on Enterprise plans starting around $8,500/year. While SCIM works with all major identity providers (Okta, Entra ID, Google Workspace), the Enterprise requirement creates a significant barrier for smaller finance teams who need automated provisioning for spend management but can't justify enterprise-level spend management software costs. This creates a particular challenge in finance applications where rapid provisioning and deprovisioning is critical for corporate card access and financial controls. Manual user management means delayed access for new employees needing corporate cards, and more critically, potential security gaps when departing employees retain access to spend management systems. For finance teams handling sensitive financial data and corporate spending, these delays and oversights create both operational friction and compliance risks.

View full guide