Stitchflow
PDQ Deploy logo

PDQ Deploy SCIM guide

Connector Only

How to automate PDQ Deploy user provisioning, and what it actually costs

Native SCIM not available

Summary and recommendation

PDQ Deploy, the software deployment and patch management platform, does not support SCIM provisioning on any plan. While PDQ Connect (their cloud offering) supports Microsoft SSO via OIDC, this only handles authentication—user accounts must still be manually created and managed. The company's per-admin licensing model ($1,575/year per admin for unlimited endpoints) makes this particularly problematic since IT teams can't automatically provision new administrators or deprovision departing ones, creating both security risks and licensing inefficiencies.

This creates a significant operational gap for IT teams managing software deployments across large environments. Without automated provisioning, departing administrators retain system access until manually removed, while new hires face delays waiting for manual account creation. For organizations with compliance requirements, this manual process creates audit trail gaps and potential security vulnerabilities in a system that manages critical infrastructure deployments.

The strategic alternative

PDQ Deploy has no native SCIM. Automate offboarding, user access reviews, and license workflows across every app, including the ones without APIs. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?No
SCIM tier requiredN/A
SSO required first?No
SSO available?Yes
SSO protocolSAML 2.0
DocumentationNot available

Supported identity providers

IdPSSOSCIMNotes
OktaVia third-partyNo Okta OIN integration found. PDQ uses OIDC-based SSO (Google, Microsoft).
Microsoft Entra IDPDQ Connect supports Microsoft SSO via OIDC. No SAML or SCIM.
Google WorkspaceVia third-partyNo native support
OneLoginVia third-partyNo native support

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages PDQ Deploy accounts manually. Here's what that costs:

Source: Stitchflow research, normalized to 500 employees:
Orphaned accounts (ex-employees with access)5
Unused licenses12
IT hours spent on manual management/year85 hours
Unused license cost/year$3,500
IT labor cost/year$5,100
Cost of compliance misses/year$890
Total annual financial impact$9,490

The PDQ Deploy pricing problem

PDQ Deploy gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Tier comparison

PlanPriceSSOSCIM
Free$0
Standard$1,575/yr per admin
EnterpriseCustom (15+ licenses)

Pricing structure

PlanPriceSSOSCIM
Free$0
Standard$1,575/yr per admin
EnterpriseCustom (15+ licenses)

What this means in practice

Manual user lifecycle management: IT admins must manually create, update, and deactivate PDQ Deploy admin accounts. When employees join, leave, or change roles, there's no automated way to reflect these changes in PDQ Deploy access.

Per-admin cost multiplication: Every admin account costs $1,575 annually. Organizations that need broad administrative access face significant scaling costs, with no automation to help manage the expanding user base.

Authentication complexity: PDQ Deploy uses OIDC-based SSO (Google, Microsoft, custom OIDC) rather than SAML, which may not align with enterprise identity architectures. The cloud PDQ Connect service has different authentication from the on-premises Deploy & Inventory tools.

Additional constraints

Split architecture
PDQ Connect (cloud) and PDQ Deploy/Inventory (on-premises) have different authentication systems, creating management complexity
Limited IdP compatibility
OIDC-only SSO excludes organizations standardized on SAML-based identity providers
No role automation
Admin permissions and role assignments must be configured manually for each user
Endpoint management overhead
While endpoints are unlimited per admin, there's no programmatic way to manage admin access to specific endpoint groups or organizational units

Summary of challenges

  • PDQ Deploy does not provide native SCIM at any price tier
  • Organizations must rely on third-party tools or manual provisioning
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What PDQ Deploy actually offers for identity

OIDC Authentication (Cloud only)

PDQ Connect (the cloud platform) supports basic OIDC authentication with select providers:

SettingDetails
ProtocolOpenID Connect (OIDC)
Supported IdPsGoogle Workspace, Microsoft Entra ID, custom OIDC providers
ConfigurationManual setup through PDQ Connect admin console
User requirementUsers must be manually added to PDQ Connect before authentication

Critical limitation: This only applies to PDQ Connect. The core PDQ Deploy and Inventory products run on-premises with local authentication only.

What's Missing

PDQ Deploy lacks fundamental enterprise identity features:

No SCIM provisioning
All user accounts must be created manually
No SAML SSO
Limited to OIDC authentication for cloud components only
No user lifecycle management
No automated onboarding, offboarding, or attribute updates
Split authentication model
Cloud and on-premises products use completely different auth systems

The per-admin licensing model ($1,575/year per admin) means every user costs real money, but there's no way to automatically provision or deprovision them when employees join or leave. IT teams are stuck with manual user management across potentially hundreds of endpoints.

What IT admins are saying

PDQ Deploy's lack of automated provisioning creates manual overhead for IT teams managing software deployment access:

  • Manual user management across PDQ Deploy, PDQ Inventory, and PDQ Connect
  • No automated deprovisioning when employees leave the organization
  • Per-admin licensing model makes it expensive to provision access broadly
  • Different authentication methods between cloud (PDQ Connect) and on-premises tools

The licensing model is per-admin with unlimited endpoints, but that means we're really selective about who gets access since each admin seat costs $1,575/year.

IT Director, Reddit r/sysadmin

PDQ Connect uses Microsoft SSO but the main Deploy and Inventory tools are separate - so we're managing user access in multiple places.

Systems Administrator, Spiceworks Community

No SCIM means when someone leaves, we have to remember to manually remove them from PDQ - it's not automated through our identity provider like other tools.

IT Manager, TechNet Forums

The recurring theme

PDQ Deploy's high per-admin licensing costs and lack of automated provisioning force IT teams to manually manage a limited number of users, creating security risks when access isn't promptly removed.

The decision

Your SituationRecommendation
Small IT team (<10 endpoints)Manual account management is acceptable
Stable infrastructure with minimal staff changesManual provisioning with OIDC SSO for authentication
Growing organization (50+ endpoints)Use Stitchflow: automation essential for scale
Multiple PDQ admins across different teamsUse Stitchflow: centralized provisioning prevents access sprawl
Enterprise with compliance requirementsUse Stitchflow: automated audit trail required for endpoint management tools

The bottom line

PDQ Deploy is essential for Windows endpoint management, but it has zero native provisioning capabilities and uses OIDC-only authentication. For IT teams managing multiple admins or facing compliance requirements, Stitchflow delivers the automated user lifecycle management that PDQ Deploy simply doesn't provide.

Make PDQ Deploy workflows AI-native

PDQ Deploy has no native SCIM. We build complete offboarding, user access reviews, and license workflows across every app, including the ones without APIs.

Covers apps without native SCIM, including the ones without APIs
Less than a week, start to finish (~2 hours of your time)
Built with your team; extend to anything else in the company
Book a Demo

Technical specifications

SCIM Version

Not specified

Supported Operations

Not specified

Supported Attributes

No native SCIM provisioningSSO via OIDC only (Google, Microsoft, custom OIDC)Per-admin licensing model with unlimited endpointsPDQ Connect (cloud) has different auth from Deploy & Inventory (on-prem)

Plan requirement

Not specified

Prerequisites

Not specified

Key limitations

  • No native SCIM provisioning
  • SSO via OIDC only (Google, Microsoft, custom OIDC)
  • Per-admin licensing model with unlimited endpoints
  • PDQ Connect (cloud) has different auth from Deploy & Inventory (on-prem)

Documentation not available.

Unlock SCIM for
PDQ Deploy

PDQ Deploy has no native SCIM. We still automate end-to-end workflows across every app, including the ones without APIs.

See how it works
Admin Console
Directory
Applications
PDQ Deploy logo
PDQ Deploy
via Stitchflow

Last updated: 2026-01-20

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

Abnormal Security logo

Abnormal Security

No SCIM

Security / Email Security

ProvisioningNot Supported
Manual Cost$9,490/yr

Abnormal Security, the AI-powered email security platform protecting against BEC and phishing attacks, does not offer SCIM provisioning on any plan. While the platform supports SAML 2.0 SSO integration with identity providers like Okta and Entra ID, this only handles authentication—not automated user lifecycle management. Security teams must manually provision and deprovision analyst access through Abnormal's portal, creating operational overhead and potential security gaps in a platform specifically designed to protect against email-based threats. This manual provisioning model creates significant challenges for security operations. When new SOC analysts join or existing team members change roles, IT admins must coordinate manual account creation and permission updates in Abnormal Security. For a platform that's critical to threat detection and incident response, delays in provisioning can leave security gaps, while delayed deprovisioning creates compliance risks. The irony is stark: a security platform designed to prevent account takeover and credential abuse lacks the automated provisioning controls that prevent exactly these risks.

View full guide
Airwallex logo

Airwallex

No SCIM
ProvisioningNot Supported
Manual Cost$9,490/yr

Airwallex, the global payments and treasury platform, offers no SCIM provisioning support on any plan, including their custom Accelerate enterprise tier. Despite being positioned for enterprise use with features like multi-entity management and advanced treasury controls, Airwallex lacks any official identity provider integrations—no SSO, no provisioning, and no presence in major IdP galleries like Okta's OIN or Microsoft Entra. This creates a significant operational burden for IT teams managing financial access across growing organizations, where manual user provisioning and deprovisioning in a payments platform presents both efficiency and security risks. The absence of identity management capabilities means IT administrators must manually create, update, and remove user accounts in Airwallex—a particularly concerning gap given that this platform handles sensitive financial operations, cross-border payments, and treasury management. Without automated deprovisioning, former employees could retain access to financial systems, creating compliance risks and potential security vulnerabilities that most finance and IT teams cannot afford to overlook.

View full guide
Alkami logo

Alkami

No SCIM
ProvisioningNot Supported
Manual Cost$9,490/yr

Alkami, the digital banking platform used by banks and credit unions, does not offer SCIM provisioning or public SSO integrations. As an enterprise-only platform with custom pricing, Alkami appears to handle user management through direct account administration rather than standardized identity protocols. This creates significant challenges for financial institutions that need to integrate Alkami with their existing identity infrastructure—particularly problematic given the compliance requirements and security standards that banks must maintain. The lack of automated provisioning means IT teams at financial institutions must manually create, update, and deprovision user accounts in Alkami. For a platform handling sensitive financial data and customer information, this manual approach introduces compliance risks and operational overhead. Banks typically require seamless integration between their core identity systems and all applications accessing customer data.

View full guide