Stitchflow
Fleet logo

Fleet SCIM guide

Connector Only

How to automate Fleet user provisioning, and what it actually costs

Summary and recommendation

Fleet, the open-source device management platform for macOS, Windows, and Linux, does not currently support SCIM provisioning on any plan. While Fleet offers SAML 2.0 SSO integration with identity providers like Okta and Entra ID, including Just-In-Time (JIT) user provisioning via SAML attributes, this falls short of true SCIM automation. Fleet's documentation indicates that "SCIM for user provisioning is coming soon," but provides no timeline for availability. Even when SCIM arrives, it will likely require their Premium tier with custom pricing, making it cost-prohibitive for many organizations.

The gap between SSO and full provisioning creates operational overhead for IT teams managing Fleet deployments. While JIT provisioning can create users during first login, it doesn't handle the complete user lifecycle—deprovisioning, role changes, and bulk user management still require manual intervention. For organizations running Fleet across hundreds or thousands of endpoints, this manual overhead becomes a significant compliance and security risk, particularly when employees leave or change roles.

The strategic alternative

Fleet has no native SCIM. Automate offboarding, user access reviews, and license workflows across every app, including the ones without APIs. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?No
SCIM tier requiredN/A
SSO required first?No
SSO available?Yes
SSO protocolSAML 2.0
DocumentationNot available

Supported identity providers

IdPSSOSCIMNotes
OktaFleet supports Okta SSO via SAML, but no OIN catalog integration; SCIM for user provisioning coming soon
Microsoft Entra IDSAML 2.0 SSO supported with Entra ID; JIT provisioning available
Google WorkspaceVia third-partyNo native support
OneLoginVia third-partyNo native support

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages Fleet accounts manually. Here's what that costs:

Source: Stitchflow research, normalized to 500 employees:
Orphaned accounts (ex-employees with access)5
Unused licenses12
IT hours spent on manual management/year85 hours
Unused license cost/year$3,500
IT labor cost/year$5,100
Cost of compliance misses/year$890
Total annual financial impact$9,490

The Fleet pricing problem

Fleet gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Tier comparison

PlanPriceSSOSCIM
Free (Open Source)Free
PremiumCustom pricing

Current provisioning options

PlanPriceSCIMUser Management
Free (Open Source)Free❌ Not availableManual creation only
PremiumCustom pricing❌ Coming soonJIT via SAML attributes

Fleet supports Just-In-Time (JIT) provisioning through SAML attributes, but this creates users only when they first log in - not when they're added to your IdP.

What this means in practice

No proactive user creation: Users must manually log in before their Fleet account exists, creating a gap between when someone joins your team and when they can access device management tools.

Role assignment limitations: While SAML attributes can assign roles during JIT provisioning, you can't pre-configure user access or update roles without user interaction.

Deprovisioning gaps: When employees leave, their Fleet access must be manually revoked since there's no automated way to sync user status from your IdP.

Additional constraints

Timeline uncertainty
Fleet's "coming soon" SCIM implementation has no public release date
Premium requirement
Even when available, SCIM will likely require upgrading to Premium pricing (custom quotes)
JIT dependency
Current workaround requires users to manually log in before their accounts become active
Manual role management
No way to bulk update user permissions or sync group memberships from your IdP

Summary of challenges

  • Fleet does not provide native SCIM at any price tier
  • Organizations must rely on third-party tools or manual provisioning
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What Fleet actually offers for identity

SAML SSO (Available on all plans)

Fleet provides SAML 2.0 integration with identity providers at no additional cost:

SettingDetails
ProtocolSAML 2.0
Supported IdPsOkta, Entra ID, Google Workspace, OneLogin
ConfigurationManual SAML setup via Fleet configuration files
User provisioningJIT (Just-In-Time) only
Role assignmentVia SAML attributes

Key capability: Fleet supports JIT provisioning, meaning users are automatically created when they first authenticate via SAML. Roles can be assigned through SAML attributes, providing basic automated user management.

Current Provisioning Limitations

FeatureFleet Status
SCIM user provisioning❌ Coming soon (not yet available)
Bulk user creation❌ Manual only
User deprovisioning❌ Manual deletion required
Group synchronization❌ Not supported
Real-time updates❌ JIT creation only

The reality: While Fleet's JIT provisioning covers basic user creation, you're still stuck with manual processes for user lifecycle management. No automated deprovisioning means offboarded employees retain access until manually removed.

Premium Pricing Structure

Fleet's Premium tier requires custom pricing for:

Professional support with SLA
Advanced compliance features
Enterprise-grade deployment assistance

Bottom line: Even when SCIM arrives, it will likely be gated behind Premium's custom pricing model, making cost planning difficult for identity management projects.

What IT admins are saying

Fleet's missing SCIM support forces IT teams into manual provisioning workflows despite having SSO configured:

  • Users must be manually created in Fleet before SSO authentication works
  • No automated deprovisioning when employees leave the organization
  • Role assignments require manual configuration even with SAML attributes
  • JIT provisioning exists but doesn't eliminate the need for ongoing user management

Fleet supports Okta SSO via SAML, but no OIN catalog integration; SCIM for user provisioning coming soon

Fleet documentation

SAML 2.0 SSO supported with Entra ID; JIT provisioning available

Fleet SSO docs

Users created via JIT can be assigned roles via SAML attributes

Fleet configuration guide

The recurring theme

Fleet offers solid SSO integration but IT teams still handle all user lifecycle management manually. Even with JIT provisioning, role management and deprovisioning remain time-consuming manual processes that don't scale with growing fleets of devices.

The decision

Your SituationRecommendation
Small IT team (<20 devices) with minimal turnoverManual management is acceptable
Development team using Fleet's open source versionManual management with SSO for authentication
Growing organization (50+ endpoints)Use Stitchflow: automation essential for scale
Enterprise with compliance requirementsUse Stitchflow: automation essential for audit trail
Multi-team deployment with frequent staff changesUse Stitchflow: automation strongly recommended

The bottom line

Fleet is an excellent open source MDM platform, but it lacks modern user provisioning capabilities. With SCIM support still "coming soon" and only JIT provisioning available, organizations scaling beyond basic deployments face significant manual overhead. For teams that need automated user lifecycle management today, Stitchflow delivers SCIM-level provisioning without waiting for native support.

Make Fleet workflows AI-native

Fleet has no native SCIM. We build complete offboarding, user access reviews, and license workflows across every app, including the ones without APIs.

Covers apps without native SCIM, including the ones without APIs
Less than a week, start to finish (~2 hours of your time)
Built with your team; extend to anything else in the company
Book a Demo

Technical specifications

SCIM Version

Not specified

Supported Operations

Not specified

Supported Attributes

Open source MDM for macOS, Windows, LinuxSCIM for user provisioning is coming soon (not yet available)JIT (Just-In-Time) user provisioning supported via SAMLUsers created via JIT can be assigned roles via SAML attributesFree version has no artificial limitsPremium required for professional support with SLA

Plan requirement

Not specified

Prerequisites

Not specified

Key limitations

  • Open source MDM for macOS, Windows, Linux
  • SCIM for user provisioning is coming soon (not yet available)
  • JIT (Just-In-Time) user provisioning supported via SAML
  • Users created via JIT can be assigned roles via SAML attributes
  • Free version has no artificial limits
  • Premium required for professional support with SLA

Documentation not available.

Configuration for Entra ID

Integration type

Microsoft Entra Gallery app

Where to enable

Entra admin center → Enterprise applications → Fleet → Single sign-on

SAML 2.0 SSO supported with Entra ID; JIT provisioning available

Use Stitchflow for automated provisioning.

Unlock SCIM for
Fleet

Fleet has no native SCIM. We still automate end-to-end workflows across every app, including the ones without APIs.

See how it works
Admin Console
Directory
Applications
Fleet logo
Fleet
via Stitchflow

Last updated: 2026-01-20

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

Abnormal Security logo

Abnormal Security

No SCIM

Security / Email Security

ProvisioningNot Supported
Manual Cost$9,490/yr

Abnormal Security, the AI-powered email security platform protecting against BEC and phishing attacks, does not offer SCIM provisioning on any plan. While the platform supports SAML 2.0 SSO integration with identity providers like Okta and Entra ID, this only handles authentication—not automated user lifecycle management. Security teams must manually provision and deprovision analyst access through Abnormal's portal, creating operational overhead and potential security gaps in a platform specifically designed to protect against email-based threats. This manual provisioning model creates significant challenges for security operations. When new SOC analysts join or existing team members change roles, IT admins must coordinate manual account creation and permission updates in Abnormal Security. For a platform that's critical to threat detection and incident response, delays in provisioning can leave security gaps, while delayed deprovisioning creates compliance risks. The irony is stark: a security platform designed to prevent account takeover and credential abuse lacks the automated provisioning controls that prevent exactly these risks.

View full guide
Airwallex logo

Airwallex

No SCIM
ProvisioningNot Supported
Manual Cost$9,490/yr

Airwallex, the global payments and treasury platform, offers no SCIM provisioning support on any plan, including their custom Accelerate enterprise tier. Despite being positioned for enterprise use with features like multi-entity management and advanced treasury controls, Airwallex lacks any official identity provider integrations—no SSO, no provisioning, and no presence in major IdP galleries like Okta's OIN or Microsoft Entra. This creates a significant operational burden for IT teams managing financial access across growing organizations, where manual user provisioning and deprovisioning in a payments platform presents both efficiency and security risks. The absence of identity management capabilities means IT administrators must manually create, update, and remove user accounts in Airwallex—a particularly concerning gap given that this platform handles sensitive financial operations, cross-border payments, and treasury management. Without automated deprovisioning, former employees could retain access to financial systems, creating compliance risks and potential security vulnerabilities that most finance and IT teams cannot afford to overlook.

View full guide
Alkami logo

Alkami

No SCIM
ProvisioningNot Supported
Manual Cost$9,490/yr

Alkami, the digital banking platform used by banks and credit unions, does not offer SCIM provisioning or public SSO integrations. As an enterprise-only platform with custom pricing, Alkami appears to handle user management through direct account administration rather than standardized identity protocols. This creates significant challenges for financial institutions that need to integrate Alkami with their existing identity infrastructure—particularly problematic given the compliance requirements and security standards that banks must maintain. The lack of automated provisioning means IT teams at financial institutions must manually create, update, and deprovision user accounts in Alkami. For a platform handling sensitive financial data and customer information, this manual approach introduces compliance risks and operational overhead. Banks typically require seamless integration between their core identity systems and all applications accessing customer data.

View full guide