Stitchflow
LastPass logo

LastPass SCIM guide

Native SCIM

How to automate LastPass user provisioning, and what it actually costs

Native SCIM requires Business plan

Summary and recommendation

LastPass supports SCIM provisioning starting at the Business tier ($7/user/month), with integration support for all major identity providers including Okta, Entra ID, Google Workspace, and OneLogin. However, LastPass SCIM has critical limitations around deprovisioning: when users are removed, their vault access isn't immediately revoked, and shared folder permissions become complex to manage at scale.

This creates a significant security gap for IT teams. Password vaults contain the most sensitive credentials in your organization—API keys, service accounts, privileged access passwords. When employees leave or change roles, their access to these credentials must be revoked immediately, not left accessible while IT manually cleans up vault permissions. SSO alone doesn't solve this because it only controls login authentication, not ongoing vault access or shared resource permissions.

The strategic alternative

Stitchflow provides SCIM-level provisioning through resilient browser automation for LastPass with proper deprovisioning workflows that immediately revoke vault access and handle shared folder permissions. Works with any LastPass plan and any identity provider. Flat pricing under $5K/year, regardless of user count.

Quick SCIM facts

SCIM available?Yes
SCIM tier requiredBusiness
SSO required first?Yes
SSO available?Yes
SSO protocolSAML 2.0
DocumentationOfficial docs

Supported identity providers

IdPSSOSCIMNotes
OktaOIN app with full provisioning
Microsoft Entra IDGallery app with SCIM
Google WorkspaceJIT onlySAML SSO with just-in-time provisioning
OneLoginSupported

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages LastPass accounts manually. Here's what that costs:

Source: Stitchflow customers using LastPass, normalized to 500 employees:
Orphaned accounts (ex-employees with access)0
Unused licenses6
IT hours spent on manual management/year151 hours
Unused license cost/year$633
IT labor cost/year$9,072
Cost of compliance misses/year$0
Total annual financial impact$9,705

The LastPass pricing problem

LastPass gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Plan Structure (Billed Monthly)

PlanPriceSSOSCIM
Teams$4/user/mo
Business$7/user/mo
EnterpriseCustom pricing

What this means in practice

Using current list prices (Teams → Business for SCIM access):

Team SizeAnnual Upgrade Cost
25 users+$900/year
50 users+$1,800/year
100 users+$3,600/year
250 users+$9,000/year

Calculation: ($7 - $4) × users × 12 months

Additional constraints

Password vault security risks
Deprovisioning doesn't immediately revoke access to existing vault data, creating security gaps during offboarding.
Shared folder complexity
Managing shared folder permissions requires careful configuration to prevent data exposure when users are deprovisioned.
Master password dependencies
Users without federated login still rely on master passwords, complicating the provisioning workflow.
Post-breach considerations
Given LastPass's security incidents, organizations need tight control over vault access timing.

Summary of challenges

  • LastPass supports SCIM but only at Business tier (custom pricing)
  • Google Workspace users get JIT provisioning only, not full SCIM
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What the upgrade actually includes

LastPass doesn't sell SCIM separately. It's bundled with Business plan features at $7/user/month:

SCIM automated provisioning and deprovisioning
SAML 2.0 single sign-on with federated login
Unlimited shared folders and policies
Advanced multifactor authentication
Directory integrations (AD, Azure, Google Workspace)
Unlimited users and password storage
Advanced reporting and security dashboard
Priority customer support

The Business plan makes sense if you need enterprise password management with SSO. But if you just want automated user provisioning for a smaller team already using LastPass Teams ($4/user/month), you're paying 75% more for features like unlimited shared folders and advanced MFA that many teams don't need.

Stitchflow Insight

We estimate ~60% of Business plan features are overkill for organizations that simply want to automate LastPass user lifecycle management without the full enterprise security suite.

What IT admins are saying

Community sentiment on LastPass's SCIM implementation focuses heavily on security concerns and deprovisioning gaps. Common complaints:

  • Deprovisioning doesn't immediately revoke access to existing vault data
  • Complex shared folder permission management creates security gaps
  • Post-breach trust concerns affecting enterprise adoption
  • Master password reset policies clash with automated provisioning workflows

The biggest issue is that when you deprovision someone, they can still access their vault data until their session expires. For a security tool, that's pretty concerning.

Reddit r/sysadmin

Shared folder permissions are a nightmare to manage at scale. SCIM helps with user lifecycle but doesn't solve the vault access complexity.

Spiceworks Community

The recurring theme

While LastPass offers SCIM on reasonable pricing tiers, the fundamental challenge is ensuring truly secure offboarding when password vaults contain critical credentials that need immediate access revocation.

The decision

Your SituationRecommendation
On Teams ($4/user/month), need SCIMUse Stitchflow: avoid the 75% price jump to Business
On Business/Enterprise with native SCIMUse native SCIM: you're already paying for it
Security-first organization with strict offboardingUse Stitchflow: better deprovisioning controls than native
Complex shared folder permissions requirementsUse Stitchflow: managed configuration avoids permission gaps
Small team with low turnoverManual may work: but password vaults make offboarding errors costly

The bottom line

LastPass requires Business tier ($7/user/month) for SCIM—a 75% increase from Teams pricing. For organizations that need automated provisioning without the tier upgrade or want stronger deprovisioning controls for sensitive password data, Stitchflow delivers enterprise-grade automation at flat-rate pricing.

Automate LastPass without the tier upgrade

Stitchflow delivers SCIM-level provisioning through resilient browser automation, backed by 24/7 human in the loop for LastPass at <$5K/year, flat, regardless of team size.

Works alongside or instead of native SCIM
Syncs with your existing IdP (Okta, Entra ID, Google Workspace)
Automates onboarding and offboarding
SOC 2 Type II certified
24/7 human-in-the-loop monitoring
Book a Demo

Technical specifications

SCIM Version

2.0

Supported Operations

Create, Update, Deactivate, Groups

Supported Attributes

Not specified

Plan requirement

Business

Prerequisites

SSO must be configured first

Key limitations

  • Vault data handling during deprovisioning
  • Shared folder permissions need configuration
  • Master password reset considerations

Configuration for Okta

Integration type

Okta Integration Network (OIN) app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Okta Admin Console → Applications → LastPass → Provisioning

Required credentials

SCIM endpoint URL and bearer token (generated in app admin console).

Configuration steps

Enable Create Users, Update User Attributes, and Deactivate Users.

Provisioning trigger

Okta provisions based on app assignments (users or groups).

Full SCIM with real-time provisioning/deprovisioning. Federated login available (no master password). SCIM endpoint requires no software installation.

Native SCIM is available on Business. Use Stitchflow if you need provisioning without the tier upgrade.

Configuration for Entra ID

Integration type

Microsoft Entra Gallery app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Entra admin center → Enterprise applications → LastPass → Provisioning

Required credentials

Tenant URL (SCIM endpoint) and Secret token (bearer token from app admin console).

Configuration steps

Set Provisioning Mode = Automatic, configure SCIM connection.

Provisioning trigger

Entra provisions based on user/group assignments to the enterprise app.

Sync behavior

Entra provisioning runs on a scheduled cycle (typically every 40 minutes).

Full SCIM via Azure AD/Entra. Federated login supported. Deprovisioning removes account access while keeping data available for reactivation.

Native SCIM is available on Business. Use Stitchflow if you need provisioning without the tier upgrade.

Unlock SCIM for
LastPass

LastPass gates automation behind Business plan. Stitchflow delivers the same SCIM outcomes for a flat fee, saving you 75%.

See how it works
Admin Console
Directory
Applications
LastPass logo
LastPass
via Stitchflow

Last updated: 2026-01-11

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

Keeper logo

Keeper

SCIM Tax

Password Management / Security

SCIM StatusIncluded
Manual Cost$11,754/yr

Keeper Security supports full SCIM 2.0 provisioning, but only on Enterprise plans with custom pricing (typically ~$60/user/year for 100+ users). Teams on Business plans ($3.75/user/month) get SSO but no automated provisioning - meaning IT admins must manually invite, assign teams, and manage vault access for every user. When employees leave, deprovisioning only locks their vault rather than deleting the account, creating ongoing security visibility gaps. This creates a significant gap for password management governance. SSO alone doesn't solve the provisioning problem - you still need manual processes for onboarding, role assignments, and vault permissions. For security-critical applications like password managers, manual user lifecycle management introduces compliance risks and delays that undermine the zero-trust model most organizations are trying to achieve.

View full guide
Dashlane logo

Dashlane

SCIM Tax

Password Management / Security

SCIM StatusIncluded
Manual Cost$11,754/yr

Dashlane supports SCIM (the protocol that lets your identity provider automatically create, update, and remove user accounts). But there's a catch: Google Workspace users are locked out of SCIM entirely, limited to JIT provisioning only. For Okta, Entra ID, and PingIdentity users, full SCIM provisioning is available starting at $8/user/month on Business plans. The Google Workspace limitation creates a significant gap for organizations using Google as their primary IdP. Without SCIM, IT teams must manually provision password manager access for every employee onboarding and offboarding - a critical security workflow that should never rely on manual processes. JIT provisioning only works when users first attempt to log in, leaving your password security incomplete until then.

View full guide
1Password logo

1Password

SCIM Tax
SCIM StatusIncluded
Manual Cost$11,167/yr

1Password supports SCIM provisioning on its Business plan ($7.99/user/month), but requires deploying and managing the 1Password SCIM Bridge on your own infrastructure. This self-hosted approach means you're responsible for maintaining servers, handling updates, and troubleshooting connectivity issues between your identity provider and 1Password's systems. The SCIM Bridge also operates separately from SSO (which uses OIDC only), requiring you to configure and maintain two distinct integrations. This architecture creates operational overhead that many IT teams don't want to manage. Unlike cloud-native SCIM implementations, you're essentially running 1Password's provisioning infrastructure for them. When the SCIM Bridge goes down, provisioning stops working. When 1Password updates their API, you need to update your Bridge deployment. For teams that just want automated user lifecycle management, this becomes an ongoing maintenance burden.

View full guide