Stitchflow
SAP SuccessFactors logo

SAP SuccessFactors SCIM guide

Native SCIM

How to automate SAP SuccessFactors user provisioning, and what it actually costs

Native SCIM requires Enterprise plan

Summary and recommendation

SAP SuccessFactors supports SCIM provisioning through SAP Cloud Identity Services, but there's a critical timing issue: basic authentication is deprecated as of November 2026, requiring migration to X.509 certificates. This creates immediate technical debt for IT teams who must coordinate both the SCIM implementation and authentication migration within existing SAP infrastructure complexity.

The real challenge isn't just the technical migration—it's that SuccessFactors typically serves as an HR source system, meaning you're often provisioning from SuccessFactors to other applications rather than into it. This reverses the normal provisioning flow and requires specialized expertise in SAP's identity ecosystem, including Identity Authentication Service and Identity Provisioning Service components.

The strategic alternative

SAP SuccessFactors gates SCIM behind Enterprise. That can unlock provisioning, but it still does not complete the offboarding, access review, or license workflow across the rest of your stack. Stitchflow builds and maintains the IT workflows your team still runs manually, across every app, including the ones without APIs.

Quick SCIM facts

SCIM available?Yes
SCIM tier requiredEnterprise
SSO required first?Yes
SSO available?Yes
SSO protocolSAML 2.0
DocumentationOfficial docs

Supported identity providers

IdPSSOSCIMNotes
OktaOIN app with full provisioning
Microsoft Entra IDGallery app with SCIM
Google WorkspaceJIT onlySAML SSO with just-in-time provisioning
OneLoginSupported

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages SAP SuccessFactors accounts manually. Here's what that costs:

Source: Stitchflow aggregate data across apps with 2+ instances, normalized to 500 employees
Orphaned accounts (ex-employees with access)7
Unused licenses12
IT hours spent on manual management/year101 hours
Unused license cost/year$3,925
IT labor cost/year$6,088
Cost of compliance misses/year$1,741
Total annual financial impact$11,754

The SAP SuccessFactors pricing problem

SAP SuccessFactors gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Tier comparison

PlanPriceSSOSCIM
Professional$8/user/mo (1-100 users)
Performance & Goals$14/user/mo
Full Suite$28-38/user/mo
EnterpriseCustom pricing

Plan Structure

PlanPriceSCIM
Professional$8/user/mo (1-100 users)
Performance & Goals$14/user/mo
Full Suite$28-38/user/mo
EnterpriseCustom pricing✓ (via SAP Cloud Identity Services)

Note: SCIM provisioning requires Enterprise tier and must be implemented through SAP Cloud Identity Services, not directly with SuccessFactors.

What this means in practice

Implementation complexity: You can't provision directly to SuccessFactors. The required architecture involves: 1. Your IdP → SAP Cloud Identity Services 2. SAP Cloud Identity Services → SuccessFactors 3. Additional licensing and configuration for the intermediary service

Cost opacity: Enterprise pricing is custom and typically includes implementation fees of 100-125% of annual software costs. For a 500-person organization upgrading from Full Suite ($28/user/mo):

Base software cost
~$168,000/year
Implementation fees
~$168,000-210,000
Total first-year cost
~$336,000-378,000

Additional constraints

Third-party dependency
All SCIM flows require SAP Cloud Identity Services as an intermediary layer.
Authentication migration deadline
Basic authentication is deprecated as of November 2026. All existing implementations must migrate to X.509 certificates.
SAP ecosystem lock-in
Provisioning architecture ties you deeper into SAP's identity management stack.
Support complexity
Issues require coordination between your IdP vendor, SAP Cloud Identity Services, and SuccessFactors support teams.

Summary of challenges

  • SAP SuccessFactors supports SCIM but only at Enterprise tier (Custom pricing)
  • Google Workspace users get JIT provisioning only, not full SCIM
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What SAP SuccessFactors actually offers for identity

SAP SuccessFactors provides SCIM through SAP Cloud Identity Services, but this requires Enterprise pricing and SAP's broader identity ecosystem:

SCIM provisioning via SAP Identity Provisioning Service
SAML 2.0 single sign-on with IdP and SP initiation
SAP Identity Authentication with 2FA support
X.509 certificate authentication (required by Nov 2026)
Social sign-on capabilities
SPNEGO authentication
Integration with SAP Cloud Platform services

The challenge: you're not just buying SuccessFactors identity features—you're buying into SAP's entire Cloud Identity Services stack. Implementation fees typically run 100-125% of annual software costs, and you need Enterprise pricing to access SCIM at all. Basic authentication is deprecated in November 2026, forcing a migration to X.509 certificates.

For organizations just wanting straightforward SCIM provisioning, ~80% of SAP's identity bundle is enterprise overhead you don't need.

What IT admins are saying

Community sentiment on SAP SuccessFactors's SCIM implementation centers around SAP ecosystem complexity and authentication challenges. Common complaints:

  • Confusion over requiring SAP Cloud Identity Services for proper SCIM support
  • Frustration with the upcoming Basic authentication deprecation in November 2026
  • Complex implementation requirements with high consulting fees (100-125% of software costs)
  • Difficulty navigating SAP's overlapping identity services and documentation

SAP's identity stack is a maze - you need Identity Authentication, Identity Provisioning, and then figure out how it all connects to SuccessFactors. The documentation assumes you already know the SAP ecosystem.

Reddit, r/sysadmin

Basic auth is getting killed off next year and we have to migrate to X.509 certificates. Just another SAP complexity tax on top of everything else.

Spiceworks Community

The recurring theme

SAP SuccessFactors SCIM works, but the SAP identity ecosystem complexity and mandatory migrations create unnecessary operational overhead for IT teams.

The decision

Your SituationRecommendation
Need SCIM but not on Enterprise tierUse Stitchflow: avoid complex SAP ecosystem and Enterprise upgrade costs
Using basic auth, need to migrate before Nov 2026Use Stitchflow: skip X.509 certificate migration complexity
Already on Enterprise with SAP Cloud Identity ServicesConsider native SCIM: you have the infrastructure
HR-driven provisioning to other appsUse Stitchflow: simpler than SAP Identity Provisioning Service setup
Small HR team, minimal user changesManual may work: but plan for auth migration deadline

The bottom line

SAP SuccessFactors gates SCIM behind Enterprise. The upgrade may unlock provisioning, but the workflow still has to complete across the rest of your stack.

Close the SAP SuccessFactors workflow gap

SAP SuccessFactors gates SCIM behind Enterprise, but the bigger issue is the workflow around it. Stitchflow builds and maintains the offboarding, access review, or license workflow underneath.

Across every app in the workflow, including the ones without APIs
Built in less than a week, with roughly 2 hours from your team
You review the exceptions. Stitchflow maintains the workflow underneath
Start with the free gap diagnostic

Technical specifications

SCIM Version

2.0

Supported Operations

Create, Update, Deactivate, Groups

Supported Attributes

Not specified

Plan requirement

Enterprise

Prerequisites

SSO must be configured first

Key limitations

  • Use SAP Cloud Identity Services for SCIM
  • Basic auth deprecated Nov 2026 - migrate to X.509
  • Contact SuccessFactors support to enable SAML SSO

Configuration for Okta

Integration type

Okta Integration Network (OIN) app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Okta Admin Console → Applications → SAP SuccessFactors → Provisioning

Required credentials

SCIM endpoint URL and bearer token (generated in app admin console).

Configuration steps

Enable Create Users, Update User Attributes, and Deactivate Users.

Provisioning trigger

Okta provisions based on app assignments (users or groups).

Enterprise required for SCIM

SAP SuccessFactors gates SCIM behind Enterprise. The upgrade may unlock provisioning, but the workflow still has to complete across the rest of your stack.

Configuration for Entra ID

Integration type

Microsoft Entra Gallery app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Entra admin center → Enterprise applications → SAP SuccessFactors → Provisioning

Required credentials

Tenant URL (SCIM endpoint) and Secret token (bearer token from app admin console).

Configuration steps

Set Provisioning Mode = Automatic, configure SCIM connection.

Provisioning trigger

Entra provisions based on user/group assignments to the enterprise app.

Sync behavior

Entra provisioning runs on a scheduled cycle (typically every 40 minutes).

Enterprise required for SCIM

SAP SuccessFactors gates SCIM behind Enterprise. The upgrade may unlock provisioning, but the workflow still has to complete across the rest of your stack.

Close the workflow gap in
SAP SuccessFactors

SAP SuccessFactors gates SCIM behind Enterprise plan. That can unlock provisioning, but it still does not complete the offboarding, access review, or license workflow across your stack.

Start with the free gap diagnostic
Admin Console
Directory
Applications
SAP SuccessFactors logo
SAP SuccessFactors
via Stitchflow

Last updated: 2026-01-11

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

8x8 logo

8x8

SCIM Tax

UCaaS / Business Communications

SCIM StatusIncluded
Manual Cost$11,754/yr

8x8 supports SCIM 2.0 for automated user provisioning, but only on their quote-based X Series plans (previously $24-44/user/month range before they moved to custom pricing). While SCIM can create, update, and deactivate users, it has critical gaps that create ongoing manual overhead: license assignment must be done manually after every user is provisioned, users can't be deleted (only deactivated), and provisioned users don't automatically appear in the Company Directory. For IT teams managing a unified communications platform that typically covers all employees, these limitations defeat much of SCIM's purpose. You're still manually touching every user account to assign licenses and ensure directory visibility. The lack of user deletion support also creates compliance headaches when employees leave - accounts accumulate as "deactivated" rather than being properly removed.

View full guide
Absorb LMS logo

Absorb LMS

SCIM Tax

Learning Management System (LMS)

SCIM StatusIncluded
Manual Cost$11,754/yr

Absorb LMS supports native SCIM provisioning, but only on Enterprise plans with SSO as a required paid add-on. Even with SCIM enabled, the implementation has critical limitations: SAML provisioning only creates accounts on first login and never updates existing users, and full user provisioning requires the specific "Absorb 5 - New Learner Experience" version. For organizations managing compliance training across hundreds or thousands of learners, these gaps create ongoing manual work. The SSO-as-add-on model means you're paying extra fees on top of already custom Enterprise pricing ($6-12/user/month base, but varies significantly). For learning management systems handling external partners, contractors, and employees across different access levels, the inability to update existing user attributes through SAML provisioning forces IT teams into manual account management—exactly what automated provisioning should eliminate.

View full guide
Airbase logo

Airbase

SCIM Tax

Spend Management / Corporate Cards

SCIM StatusIncluded
Manual Cost$11,754/yr

Airbase supports SCIM provisioning, but only on Enterprise plans starting around $8,500/year. While SCIM works with all major identity providers (Okta, Entra ID, Google Workspace), the Enterprise requirement creates a significant barrier for smaller finance teams who need automated provisioning for spend management but can't justify enterprise-level spend management software costs. This creates a particular challenge in finance applications where rapid provisioning and deprovisioning is critical for corporate card access and financial controls. Manual user management means delayed access for new employees needing corporate cards, and more critically, potential security gaps when departing employees retain access to spend management systems. For finance teams handling sensitive financial data and corporate spending, these delays and oversights create both operational friction and compliance risks.

View full guide