Summary and recommendation
Proofpoint, the email security and cybersecurity platform, does not offer documented SCIM provisioning across its product suite. While Proofpoint supports SAML 2.0 SSO with all major identity providers and offers JIT (Just-in-Time) provisioning on Security Awareness Training, the company's multiple products require separate SSO configurations and lack clear SCIM documentation. This creates a fragmented provisioning experience where IT teams must manually manage user accounts across Proofpoint Essentials, TAP (Targeted Attack Protection), and other security products.
The lack of unified SCIM support becomes particularly problematic for enterprise customers paying $25-$70 per user annually for bundled plans or $100k+ for large deployments. Without automated provisioning, IT teams face manual overhead managing user lifecycles across multiple Proofpoint products, creating security gaps when employees change roles or leave the organization. JIT provisioning only works for initial login and doesn't handle deprovisioning or attribute updates.
The strategic alternative
Proofpoint has no native SCIM. Automate offboarding, user access reviews, and license workflows across every app, including the ones without APIs. We maintain the integration layer underneath. You focus on judgment, not plumbing.
Quick SCIM facts
| SCIM available? | No |
| SCIM tier required | N/A |
| SSO required first? | No |
| SSO available? | Yes |
| SSO protocol | SAML 2.0 |
| Documentation | Not available |
Supported identity providers
| IdP | SSO | SCIM | Notes |
|---|---|---|---|
| Okta | ✓ | ❌ | Multiple Proofpoint apps in Okta catalog. Security Awareness Training supports provisioning. Group Linking and Schema Discovery available. |
| Microsoft Entra ID | ✓ | ❌ | Azure AD sync for Essentials. JIT provisioning on Security Awareness Training. Proofpoint on Demand supports Entra SSO. |
| Google Workspace | Via third-party | ❌ | No native support |
| OneLogin | Via third-party | ❌ | No native support |
The cost of not automating
Without SCIM (or an alternative like Stitchflow), your IT team manages Proofpoint accounts manually. Here's what that costs:
The Proofpoint pricing problem
Proofpoint gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.
Tier comparison
| Plan | Price | SSO | SCIM |
|---|---|---|---|
| Essentials | $2-$5/user/month | ||
| TAP | $20-$35/user/year | ||
| Enterprise | $25-$70/user/year bundles |
Pricing and provisioning options
| Plan | Price | SSO | SCIM |
|---|---|---|---|
| Essentials | $2-$5/user/month | ||
| TAP | $20-$35/user/year | ||
| Enterprise | $25-$70/user/year bundles |
Enterprise pricing reality
What this means in practice
Without SCIM, IT admins face different provisioning challenges depending on which Proofpoint products they use:
The lack of automated deprovisioning means terminated employees retain access until manually removed from each Proofpoint product individually.
Additional constraints
Summary of challenges
- Proofpoint does not provide native SCIM at any price tier
- Organizations must rely on third-party tools or manual provisioning
- Our research shows teams manually provisioning this app spend significant hidden costs annually
What Proofpoint actually offers for identity
SAML SSO (All Products)
Proofpoint supports SAML 2.0 federation across its security platform:
| Setting | Details |
|---|---|
| Protocol | SAML 2.0 |
| Supported IdPs | Okta, Entra ID, Google Workspace, OneLogin, any SAML 2.0 provider |
| IdP Support | Multiple IdPs per organization |
| Initiation | Both SP-initiated and IdP-initiated |
| Configuration | Per-product setup required |
Key limitation: Each Proofpoint product (Email Protection, Security Awareness Training, TAP, etc.) requires separate SSO configuration. There's no unified identity setup across the platform.
Limited Provisioning Options
Proofpoint's provisioning capabilities vary by product:
| Product | Provisioning Method | User Management |
|---|---|---|
| Security Awareness Training | JIT provisioning | Create on first login |
| Email Protection Essentials | Azure AD Sync | Automated sync from Entra ID |
| Other products | Manual only | No documented automation |
What's Missing
Bottom line: While Proofpoint offers SSO, the lack of standardized SCIM provisioning means IT teams face manual user management across multiple security products, each with different provisioning capabilities.
What IT admins are saying
Community sentiment on Proofpoint's provisioning setup reveals frustration with the platform's fragmented approach across multiple products:
- Multiple Proofpoint products require separate SSO configurations, creating administrative overhead
- SCIM provisioning capabilities aren't clearly documented or consistently available across products
- SSO setup often requires engaging Proofpoint support team rather than self-service configuration
- Azure AD sync is available for Essentials but provisioning features vary significantly between product lines
User accounts must exist in Proofpoint Dash to use single sign-on... SSO does not substitute account creation.
Multiple IdPs per org supported, but each product may need separate configuration.
The recurring theme
Proofpoint's multi-product architecture creates a provisioning maze where IT teams must manage separate configurations for Security Awareness Training, Threat Response, and other modules - with inconsistent automation capabilities across the suite.
The decision
| Your Situation | Recommendation |
|---|---|
| Single Proofpoint product, stable team | Manual management with SSO acceptable |
| Multiple Proofpoint products (Email Security + TAP + Training) | Use Stitchflow: separate configs create complexity |
| Growing security team with frequent onboarding | Use Stitchflow: JIT only covers training module |
| Enterprise with compliance requirements | Use Stitchflow: audit trail essential for security tools |
| Budget-conscious with basic email security needs | Manual management, but plan for Stitchflow as you scale |
The bottom line
Proofpoint's multi-product architecture creates provisioning headaches—each solution requires separate SSO configuration and SCIM support isn't documented. For organizations using multiple Proofpoint products or needing reliable automation for their security stack, Stitchflow eliminates the complexity of managing separate integrations.
Make Proofpoint workflows AI-native
Proofpoint has no native SCIM. We build complete offboarding, user access reviews, and license workflows across every app, including the ones without APIs.
Technical specifications
SCIM Version
Not specifiedSupported Operations
Not specifiedSupported Attributes
Plan requirement
Not specifiedPrerequisites
Not specifiedKey limitations
- Multiple products with separate SSO configs
- SCIM not clearly documented
- JIT available on some products
- SSO setup may require support team
Documentation not available.
Configuration for Okta
Integration type
Okta Integration Network (OIN) app
Where to enable
Docs
Multiple Proofpoint apps in Okta catalog. Security Awareness Training supports provisioning. Group Linking and Schema Discovery available.
Use Stitchflow for automated provisioning.
Configuration for Entra ID
Integration type
Microsoft Entra Gallery app
Where to enable
Azure AD sync for Essentials. JIT provisioning on Security Awareness Training. Proofpoint on Demand supports Entra SSO.
Use Stitchflow for automated provisioning.
Unlock SCIM for
Proofpoint
Proofpoint has no native SCIM. We still automate end-to-end workflows across every app, including the ones without APIs.
See how it works


