Stitchflow
Delinea logo

Delinea SCIM guide

Native SCIM

How to automate Delinea user provisioning, and what it actually costs

Native SCIM requires Enterprise plan

Summary and recommendation

Delinea Secret Server supports full SCIM 2.0 provisioning with PAM-specific extensions for privileged access management. However, SCIM functionality is restricted to Enterprise plans, which carry custom enterprise pricing with a median cost of $19,705/year according to Vendr data. For organizations on Standard plans seeking automated privileged user provisioning, upgrading to Enterprise represents a significant cost increase primarily driven by advanced PAM features they may not need.

The privileged access use case makes manual provisioning particularly problematic. Security teams need rapid provisioning and deprovisioning of privileged accounts to maintain zero-trust principles and comply with SOC 2 or similar frameworks. Manual processes create delays in granting just-in-time privileged access and increase the risk of orphaned privileged accounts—a critical security vulnerability that auditors flag immediately.

The strategic alternative

Delinea gates SCIM behind Enterprise. Skip the Enterprise plan upgrade and automate complete outcomes across your stack. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?Yes
SCIM tier requiredEnterprise
SSO required first?Yes
SSO available?Yes
SSO protocolSAML 2.0, OIDC
DocumentationOfficial docs

Supported identity providers

IdPSSOSCIMNotes
OktaOIN app with full provisioning
Microsoft Entra IDGallery app with SCIM
Google WorkspaceJIT onlySAML SSO with just-in-time provisioning
OneLoginSupported

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages Delinea accounts manually. Here's what that costs:

Source: Stitchflow aggregate data across apps with 2+ instances, normalized to 500 employees
Orphaned accounts (ex-employees with access)7
Unused licenses12
IT hours spent on manual management/year101 hours
Unused license cost/year$3,925
IT labor cost/year$6,088
Cost of compliance misses/year$1,741
Total annual financial impact$11,754

The Delinea pricing problem

Delinea gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Plan Structure

PlanPriceSSOSCIM
EssentialsCustom pricing
StandardCustom pricing
Enterprise$19,705/year median
Full SCIM 2.0 + PAM

Note: Enterprise includes full SCIM 2.0 with PAM extensions for privileged account lifecycle management, plus SAML/OIDC SSO integration.

What this means in practice

Based on Vendr pricing data showing a median annual cost of $19,705 for Enterprise:

Minimum viable automation
Organizations need Enterprise tier just to automate basic user provisioning for their PAM platform
PAM-specific features
SCIM extensions for privileged access workflows are only available at Enterprise level
All-or-nothing approach
No middle tier offers partial SCIM capabilities

The price range of $3,226-$44,501/year suggests significant variation based on user count and deployment type (cloud vs. on-premise).

Additional constraints

Custom enterprise pricing
No transparent pricing creates procurement friction and extends sales cycles.
PAM complexity
SCIM connector requires HTTP header token configuration and specialized PAM attribute mapping.
Deployment dependency
On-premise deployments require additional infrastructure considerations for SCIM connectivity.
Privileged user lifecycle
Organizations need automation specifically for high-risk privileged accounts, making manual provisioning a security concern.

Summary of challenges

  • Delinea supports SCIM but only at Enterprise tier (custom pricing)
  • Google Workspace users get JIT provisioning only, not full SCIM
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What the upgrade actually includes

Delinea doesn't sell SCIM separately. It's bundled with Enterprise tier PAM features:

SCIM 2.0 automated provisioning with PAM extensions
SAML/OIDC single sign-on (SSO)
Privileged Access Management (PAM) core features
Just-in-time privileged access controls
Advanced secret management workflows
Privileged session monitoring
Enterprise security controls and compliance reporting
Dedicated PAM support

At $19,705/year median pricing, you're paying for a full PAM solution when you might only need identity automation. Delinea's SCIM is specifically designed for privileged access scenarios with PAM-specific extensions - if your team doesn't manage privileged accounts or secrets, roughly 80% of the Enterprise features are irrelevant for basic user provisioning needs.

What IT admins are saying

Community sentiment on Delinea's SCIM implementation is generally positive among PAM users, though the Enterprise pricing requirement creates barriers for smaller security teams.

  • Enterprise tier requirement locks out teams who need basic PAM automation
  • SCIM connector configuration requires technical expertise with HTTP header tokens
  • Complex mapping requirements between IdP attributes and Delinea's PAM-specific fields
  • Limited community documentation compared to mainstream SaaS apps

The SCIM setup works well once configured, but getting the attribute mapping right for privileged accounts took longer than expected.

Security Admin, Reddit

Delinea's PAM extensions are powerful but the Enterprise requirement is steep for smaller teams just wanting basic user provisioning.

IT Director, Spiceworks

The recurring theme

While Delinea's SCIM works well for privileged access management, the Enterprise pricing gate and technical complexity create friction for teams seeking straightforward identity automation.

The decision

Your SituationRecommendation
Need SCIM but not ready for Enterprise pricingUse Stitchflow: avoid the $19K+ tier requirement
Small security team managing privileged accessUse Stitchflow: get PAM provisioning without enterprise overhead
Already on Enterprise tier with SCIMUse native SCIM: you're paying for PAM extensions
Need Enterprise features beyond SCIMEvaluate Enterprise: SCIM comes with advanced PAM capabilities
Managing <50 privileged users with low churnManual may work: but privileged accounts demand stricter lifecycle control

The bottom line

Delinea's Enterprise-only SCIM requirement puts automated privileged user provisioning behind a significant price barrier. For security teams that need PAM automation without the enterprise tier commitment, Stitchflow delivers the same provisioning outcomes at a fraction of the cost.

Make Delinea workflows AI-native

Delinea gates SCIM behind Enterprise. We build complete offboarding, user access reviews, and license workflows without that SCIM Tax upgrade.

No Enterprise upgrade required
Less than a week, start to finish (~2 hours of your time)
We maintain the integration layer underneath
Book a Demo

Technical specifications

SCIM Version

2.0

Supported Operations

Create, Update, Deactivate, Groups

Supported Attributes

Not specified

Plan requirement

Enterprise

Prerequisites

SSO must be configured first

Key limitations

  • SCIM 2.0 PAM extensions for privileged access
  • SCIM connector requires HTTP header token
  • Duo SCIM provisioning also available

Configuration for Okta

Integration type

Okta Integration Network (OIN) app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Okta Admin Console → Applications → Delinea → Provisioning

Required credentials

SCIM endpoint URL and bearer token (generated in app admin console).

Configuration steps

Enable Create Users, Update User Attributes, and Deactivate Users.

Provisioning trigger

Okta provisions based on app assignments (users or groups).

Delinea Secret Server available in OIN. Supports Group Linking, Schema Discovery, Attribute Writeback. SCIM connector requires mapping Username/Last name to Display Name field.

Delinea gates SCIM behind Enterprise. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Configuration for Entra ID

Integration type

Microsoft Entra Gallery app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Entra admin center → Enterprise applications → Delinea → Provisioning

Required credentials

Tenant URL (SCIM endpoint) and Secret token (bearer token from app admin console).

Configuration steps

Set Provisioning Mode = Automatic, configure SCIM connection.

Provisioning trigger

Entra provisions based on user/group assignments to the enterprise app.

Sync behavior

Entra provisioning runs on a scheduled cycle (typically every 40 minutes).

Full SCIM integration with Entra ID for on-prem Secret Server. Supports OIDC and SAML. Requires Global Administrative rights for Microsoft AD setup.

Delinea gates SCIM behind Enterprise. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Unlock SCIM for
Delinea

Delinea gates SCIM behind Enterprise plan. We automate complete offboarding and access reviews across your stack without that SCIM Tax upgrade.

See how it works
Admin Console
Directory
Applications
Delinea logo
Delinea
via Stitchflow

Last updated: 2026-01-11

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

BeyondTrust logo

BeyondTrust

SCIM Tax

Privileged Access Management (PAM)

SCIM StatusIncluded
Manual Cost$11,754/yr

BeyondTrust supports SCIM for automated user provisioning, but only on Enterprise plans with custom pricing starting at $75,000+/year. While the SCIM implementation covers standard operations (create, update, deactivate users and groups), it requires complex security provider configuration that varies across BeyondTrust's different products (PRA, Remote Support, Password Safe). Some integrations even require AWS Lambda functions to handle OAuth client credentials properly. For privileged access management, this creates a significant barrier. Organizations need automated provisioning for BeyondTrust more than most applications—privileged accounts require strict lifecycle management, and manual provisioning of vendor/contractor access creates security gaps. The enterprise-only pricing means smaller security teams face a massive licensing jump just to automate what should be standard user management.

View full guide
8x8 logo

8x8

SCIM Tax

UCaaS / Business Communications

SCIM StatusIncluded
Manual Cost$11,754/yr

8x8 supports SCIM 2.0 for automated user provisioning, but only on their quote-based X Series plans (previously $24-44/user/month range before they moved to custom pricing). While SCIM can create, update, and deactivate users, it has critical gaps that create ongoing manual overhead: license assignment must be done manually after every user is provisioned, users can't be deleted (only deactivated), and provisioned users don't automatically appear in the Company Directory. For IT teams managing a unified communications platform that typically covers all employees, these limitations defeat much of SCIM's purpose. You're still manually touching every user account to assign licenses and ensure directory visibility. The lack of user deletion support also creates compliance headaches when employees leave - accounts accumulate as "deactivated" rather than being properly removed.

View full guide
Absorb LMS logo

Absorb LMS

SCIM Tax

Learning Management System (LMS)

SCIM StatusIncluded
Manual Cost$11,754/yr

Absorb LMS supports native SCIM provisioning, but only on Enterprise plans with SSO as a required paid add-on. Even with SCIM enabled, the implementation has critical limitations: SAML provisioning only creates accounts on first login and never updates existing users, and full user provisioning requires the specific "Absorb 5 - New Learner Experience" version. For organizations managing compliance training across hundreds or thousands of learners, these gaps create ongoing manual work. The SSO-as-add-on model means you're paying extra fees on top of already custom Enterprise pricing ($6-12/user/month base, but varies significantly). For learning management systems handling external partners, contractors, and employees across different access levels, the inability to update existing user attributes through SAML provisioning forces IT teams into manual account management—exactly what automated provisioning should eliminate.

View full guide