Summary and recommendation
Darktrace, the AI-powered cybersecurity platform, does not support SCIM provisioning on any plan, including their Enterprise tier. While Darktrace offers custom SAML SSO integration with identity providers like Okta and Entra ID, this only handles authentication—not user lifecycle management. IT teams must manually create, modify, and deprovision user accounts within Darktrace's interface, even when users are added or removed from the organization.
This manual approach creates significant operational overhead for security teams managing access to critical cybersecurity infrastructure. Without automated provisioning, departed employees may retain access to sensitive threat detection data and security controls. The gap becomes particularly problematic for organizations with frequent personnel changes or compliance requirements that mandate timely access revocation.
The strategic alternative
Darktrace has no native SCIM. Automate offboarding, user access reviews, and license workflows across every app, including the ones without APIs. We maintain the integration layer underneath. You focus on judgment, not plumbing.
Quick SCIM facts
| SCIM available? | No |
| SCIM tier required | N/A |
| SSO required first? | No |
| SSO available? | Yes |
| SSO protocol | SAML 2.0 |
| Documentation | Not available |
Supported identity providers
| IdP | SSO | SCIM | Notes |
|---|---|---|---|
| Okta | ✓ | ❌ | Custom SAML integration, not in OIN |
| Microsoft Entra ID | ✓ | ❌ | Custom SAML integration |
| Google Workspace | Via third-party | ❌ | No native support |
| OneLogin | Via third-party | ❌ | No native support |
The cost of not automating
Without SCIM (or an alternative like Stitchflow), your IT team manages Darktrace accounts manually. Here's what that costs:
The Darktrace pricing problem
Darktrace gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.
Tier comparison
| Plan | Price | SSO | SCIM |
|---|---|---|---|
| Standard | Custom quote | ||
| Enterprise | Custom quote |
Pricing and provisioning options
| Plan | Pricing | SCIM | SSO |
|---|---|---|---|
| Standard | Custom quote | ❌ Not available | ✓ Custom SAML |
| Enterprise | Custom quote | ❌ Not available | ✓ Custom SAML |
Note: Darktrace pricing is entirely quote-based with no publicly available pricing tiers. SSO requires custom SAML configuration and is not available through standard IdP app galleries.
What this means in practice
Without SCIM support, every Darktrace user lifecycle event requires manual intervention:
This creates significant security exposure, as departed employees may retain Darktrace access until IT manually removes them.
Additional constraints
Summary of challenges
- Darktrace does not provide native SCIM at any price tier
- Organizations must rely on third-party tools or manual provisioning
- Our research shows teams manually provisioning this app spend significant hidden costs annually
What Darktrace actually offers for identity
SAML SSO (Custom Integration)
Darktrace supports SAML 2.0 federation through custom configuration:
| Setting | Details |
|---|---|
| Protocol | SAML 2.0 |
| Supported IdPs | Okta, Entra ID, Google Workspace, OneLogin |
| Configuration | Manual SAML setup via Darktrace admin portal |
| User requirement | Manual user creation required |
Critical limitation: Darktrace's SAML implementation provides authentication only. All user lifecycle management—creating accounts, updating roles, removing access—must be handled manually through the Darktrace interface.
No Okta Integration Network Listing
Darktrace is not available in Okta's Integration Network, meaning:
| Feature | Supported? |
|---|---|
| SAML SSO | ✓ Yes (custom config) |
| OIDC SSO | ❌ No |
| SWA (password vaulting) | ❌ No |
| Create users | ❌ No |
| Update users | ❌ No |
| Deactivate users | ❌ No |
| Group push | ❌ No |
No SCIM API Available
Darktrace provides no SCIM endpoint or API for user provisioning. This forces IT teams to:
For enterprise security platforms handling sensitive threat detection, this manual approach creates significant operational overhead and potential security gaps when user access isn't properly deprovisioned.
What IT admins are saying
Darktrace's complete absence of automated provisioning creates ongoing operational headaches for IT teams managing enterprise security platforms:
- Manual user creation and removal for every team member
- No synchronization with identity providers despite enterprise pricing
- Time-intensive onboarding process for security analysts
- Risk of orphaned accounts when employees leave
Darktrace requires manual user management which is a pain point for our IT operations. For an enterprise security solution, the lack of SCIM provisioning is surprising.
We have to manually create accounts in Darktrace for every new security team member. It's 2024 and we're still doing this manually for a platform that costs six figures.
The recurring theme
Organizations paying premium prices for enterprise cybersecurity find themselves stuck with manual user management processes that don't scale with their security operations teams.
The decision
| Your Situation | Recommendation |
|---|---|
| Small security team (<10 users) with low turnover | Manual management is workable with SSO |
| Medium organization (25+ users) needing security tool access | Use Stitchflow: manual provisioning creates security gaps |
| Enterprise with SOC compliance requirements | Use Stitchflow: automated audit trail essential |
| Rapid scaling organization | Use Stitchflow: manual onboarding delays compromise security posture |
| Multi-department security operations | Use Stitchflow: consistent access management across teams |
The bottom line
Darktrace delivers advanced threat detection but offers zero provisioning automation—only custom SAML SSO and manual user management. For security teams that need rapid, audit-compliant user provisioning without the operational overhead, Stitchflow provides SCIM-level automation where Darktrace falls short.
Make Darktrace workflows AI-native
Darktrace has no native SCIM. We build complete offboarding, user access reviews, and license workflows across every app, including the ones without APIs.
Technical specifications
SCIM Version
Not specifiedSupported Operations
Not specifiedSupported Attributes
Plan requirement
Not specifiedPrerequisites
Not specifiedKey limitations
- No SCIM support available
- Manual user management only
- SSO via custom SAML configuration
Documentation not available.
Unlock SCIM for
Darktrace
Darktrace has no native SCIM. We still automate end-to-end workflows across every app, including the ones without APIs.
See how it works


