Stitchflow
Qualys logo

Qualys SCIM guide

Connector Only

How to automate Qualys user provisioning, and what it actually costs

Native SCIM not available

Summary and recommendation

Qualys, the leading vulnerability management and security platform, does not offer SCIM provisioning on any plan. While Qualys supports SAML SSO integration with identity providers like Okta and Entra ID for authentication, user provisioning must be handled entirely through manual processes via their web console or API calls. This creates a significant operational burden for IT teams managing security tool access across large organizations.

The lack of automated provisioning is particularly problematic for security teams who need to rapidly onboard and offboard users across multiple Qualys modules (VMDR, CSAM, TotalCloud, etc.). Manual user management increases the risk of orphaned accounts with excessive privileges - exactly the security gaps that vulnerability management platforms are designed to prevent. For compliance-focused organizations, this manual process makes it difficult to demonstrate proper access controls and timely deprovisioning.

The strategic alternative

Qualys has no native SCIM. Automate offboarding, user access reviews, and license workflows across every app, including the ones without APIs. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?No
SCIM tier requiredN/A
SSO required first?No
SSO available?Yes
SSO protocolSAML 2.0
DocumentationNot available

Supported identity providers

IdPSSOSCIMNotes
OktaSSO only via SAML
Microsoft Entra IDSSO via SAML only
Google WorkspaceVia third-partyNo native support
OneLoginVia third-partyNo native support

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages Qualys accounts manually. Here's what that costs:

Source: Stitchflow research, normalized to 500 employees:
Orphaned accounts (ex-employees with access)5
Unused licenses12
IT hours spent on manual management/year85 hours
Unused license cost/year$3,500
IT labor cost/year$5,100
Cost of compliance misses/year$890
Total annual financial impact$9,490

The Qualys pricing problem

Qualys gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Tier comparison

PlanPriceSSOSCIM
ProCustom quote
BusinessCustom quote
EnterpriseCustom quote

Provisioning options

PlanPriceSSOSCIM
ProCustom quote
BusinessCustom quote
EnterpriseCustom quote

What this means in practice

No automated user lifecycle management: IT teams must manually create, update, and deactivate user accounts in Qualys when employees join, change roles, or leave the organization. This creates security risks when departing employees retain access to vulnerability data and scanning capabilities.

API-only bulk operations: While Qualys provides REST APIs for user management, these require custom scripting and ongoing maintenance. IT teams must build their own automation workflows, handle API authentication, and manage error handling - effectively creating a DIY provisioning solution.

Disconnected from IdP workflows: Changes in your identity provider (new hires, role changes, terminations) don't automatically sync to Qualys, creating gaps in your security posture management.

Additional constraints

Complex role mapping
Qualys has granular permission structures that must be manually configured for each user
No group-based provisioning
User permissions cannot be managed through IdP groups
Audit trail gaps
Manual provisioning creates incomplete logs of who provisioned access and when
Scale limitations
Manual processes become unmanageable as security teams and scanning requirements grow

Summary of challenges

  • Qualys does not provide native SCIM at any price tier
  • Organizations must rely on third-party tools or manual provisioning
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What Qualys actually offers for identity

SAML SSO (Available across plans)

Qualys supports SAML 2.0 single sign-on integration with enterprise identity providers:

SettingDetails
ProtocolSAML 2.0
Supported IdPsOkta, Microsoft Entra ID, Google Workspace
ConfigurationManual XML metadata exchange
User requirementMust pre-create accounts in Qualys before SSO login

Critical limitation: SSO only handles authentication. User accounts must be manually created in the Qualys platform before users can authenticate via SAML.

Okta Integration (via OIN)

The official Okta Integration Network listing for Qualys shows:

FeatureSupported?
SAML SSO✓ Yes
OIDC SSO❌ No
Create users❌ No
Update users❌ No
Deactivate users❌ No
Group push❌ No

Microsoft Entra ID Integration

Similar story in the Microsoft ecosystem:

FeatureSupported?
SAML SSO✓ Yes
Create users❌ No
Update users❌ No
Delete users❌ No
Sync groups❌ No

The reality

Qualys provides authentication through SAML SSO but zero provisioning capabilities. IT teams must:

Manually create user accounts in Qualys before SSO can work
Use Qualys APIs to programmatically manage users (requires custom development)
Manually assign roles and permissions through the Qualys console
Remember to manually deactivate users when they leave

For an enterprise security platform managing vulnerability assessments and compliance, manual user management creates obvious security and operational risks.

What IT admins are saying

Qualys's lack of automated provisioning creates operational overhead for security teams managing user access:

  • Manual user provisioning through console or API calls
  • No automated deprovisioning when employees leave
  • Time-consuming user management for enterprise security tools
  • SSO authentication available but no account lifecycle automation

You have to manually create users in Qualys even after setting up SSO. There's no automatic provisioning from our IdP.

IT Administrator, Reddit

We love Qualys for vulnerability management, but the user management piece is still very manual. Every new hire in security needs to be added by hand.

Security Operations Manager, Community Forum

The recurring theme

While Qualys provides robust security scanning capabilities, IT teams must manually manage user accounts separate from their identity provider, creating administrative burden for what should be an automated workflow.

The decision

Your SituationRecommendation
Small security team (<20 users) with low turnoverManual management via Qualys console is manageable
Medium organization (20-100 users) with regular access changesUse Stitchflow: manual provisioning becomes error-prone
Enterprise with compliance requirements (SOC 2, ISO 27001)Use Stitchflow: automation essential for audit trail
Multi-subsidiary deployments with centralized ITUse Stitchflow: automation critical for scale
Organizations requiring rapid onboarding/offboardingUse Stitchflow: manual processes create security gaps

The bottom line

Qualys provides enterprise-grade vulnerability management but offers zero provisioning automation—no SCIM, no native IdP integrations beyond basic SSO. For security teams that can't afford manual user management delays or compliance gaps, Stitchflow delivers the automation Qualys should have built.

Make Qualys workflows AI-native

Qualys has no native SCIM. We build complete offboarding, user access reviews, and license workflows across every app, including the ones without APIs.

Covers apps without native SCIM, including the ones without APIs
Less than a week, start to finish (~2 hours of your time)
Built with your team; extend to anything else in the company
Book a Demo

Technical specifications

SCIM Version

Not specified

Supported Operations

Not specified

Supported Attributes

No SCIM support availableManual user management via API or consoleSSO available for authentication

Plan requirement

Not specified

Prerequisites

Not specified

Key limitations

  • No SCIM support available
  • Manual user management via API or console
  • SSO available for authentication

Documentation not available.

Configuration for Okta

Integration type

Okta Integration Network (OIN) app

Where to enable

Okta Admin Console → Applications → Qualys → Sign On

SSO only via SAML

Use Stitchflow for automated provisioning.

Configuration for Entra ID

Integration type

Microsoft Entra Gallery app

Where to enable

Entra admin center → Enterprise applications → Qualys → Single sign-on

SSO via SAML only

Use Stitchflow for automated provisioning.

Unlock SCIM for
Qualys

Qualys has no native SCIM. We still automate end-to-end workflows across every app, including the ones without APIs.

See how it works
Admin Console
Directory
Applications
Qualys logo
Qualys
via Stitchflow

Last updated: 2026-01-20

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

Abnormal Security logo

Abnormal Security

No SCIM

Security / Email Security

ProvisioningNot Supported
Manual Cost$9,490/yr

Abnormal Security, the AI-powered email security platform protecting against BEC and phishing attacks, does not offer SCIM provisioning on any plan. While the platform supports SAML 2.0 SSO integration with identity providers like Okta and Entra ID, this only handles authentication—not automated user lifecycle management. Security teams must manually provision and deprovision analyst access through Abnormal's portal, creating operational overhead and potential security gaps in a platform specifically designed to protect against email-based threats. This manual provisioning model creates significant challenges for security operations. When new SOC analysts join or existing team members change roles, IT admins must coordinate manual account creation and permission updates in Abnormal Security. For a platform that's critical to threat detection and incident response, delays in provisioning can leave security gaps, while delayed deprovisioning creates compliance risks. The irony is stark: a security platform designed to prevent account takeover and credential abuse lacks the automated provisioning controls that prevent exactly these risks.

View full guide
Airwallex logo

Airwallex

No SCIM
ProvisioningNot Supported
Manual Cost$9,490/yr

Airwallex, the global payments and treasury platform, offers no SCIM provisioning support on any plan, including their custom Accelerate enterprise tier. Despite being positioned for enterprise use with features like multi-entity management and advanced treasury controls, Airwallex lacks any official identity provider integrations—no SSO, no provisioning, and no presence in major IdP galleries like Okta's OIN or Microsoft Entra. This creates a significant operational burden for IT teams managing financial access across growing organizations, where manual user provisioning and deprovisioning in a payments platform presents both efficiency and security risks. The absence of identity management capabilities means IT administrators must manually create, update, and remove user accounts in Airwallex—a particularly concerning gap given that this platform handles sensitive financial operations, cross-border payments, and treasury management. Without automated deprovisioning, former employees could retain access to financial systems, creating compliance risks and potential security vulnerabilities that most finance and IT teams cannot afford to overlook.

View full guide
Alkami logo

Alkami

No SCIM
ProvisioningNot Supported
Manual Cost$9,490/yr

Alkami, the digital banking platform used by banks and credit unions, does not offer SCIM provisioning or public SSO integrations. As an enterprise-only platform with custom pricing, Alkami appears to handle user management through direct account administration rather than standardized identity protocols. This creates significant challenges for financial institutions that need to integrate Alkami with their existing identity infrastructure—particularly problematic given the compliance requirements and security standards that banks must maintain. The lack of automated provisioning means IT teams at financial institutions must manually create, update, and deprovision user accounts in Alkami. For a platform handling sensitive financial data and customer information, this manual approach introduces compliance risks and operational overhead. Banks typically require seamless integration between their core identity systems and all applications accessing customer data.

View full guide