Stitchflow
ThreatConnect logo

ThreatConnect SCIM guide

Connector Only

How to automate ThreatConnect user provisioning, and what it actually costs

Native SCIM not available

Summary and recommendation

ThreatConnect, the threat intelligence platform and SOAR solution, does not support SCIM provisioning on any plan. While ThreatConnect offers SAML 2.0 SSO integration with identity providers like Okta and Entra ID, this only handles authentication for existing users. All user account creation, role assignments, and lifecycle management must be handled manually within ThreatConnect's interface. This creates a significant operational burden for security teams managing access to this critical security infrastructure.

The lack of automated provisioning is particularly problematic for ThreatConnect given its role as a central security platform. Security teams need rapid onboarding for incident responders and threat analysts, especially during security events when time is critical. Manual user management creates delays in granting access to essential threat intelligence and SOAR capabilities. Additionally, without automated deprovisioning, former employees may retain access to sensitive threat data and security playbooks, creating compliance and security risks that directly contradict ThreatConnect's security-focused mission.

The strategic alternative

ThreatConnect has no native SCIM. Automate offboarding, user access reviews, and license workflows across every app, including the ones without APIs. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?No
SCIM tier requiredN/A
SSO required first?No
SSO available?Yes
SSO protocolSAML 2.0
DocumentationNot available

Supported identity providers

IdPSSOSCIMNotes
OktaThreatConnect supports SAML SSO with Okta via custom SAML app configuration. No OIN app with SCIM provisioning.
Microsoft Entra IDThreatConnect supports SAML SSO. Integrates with Microsoft Sentinel for threat intelligence. No SCIM provisioning.
Google WorkspaceVia third-partyNo native support
OneLoginVia third-partyNo native support

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages ThreatConnect accounts manually. Here's what that costs:

Source: Stitchflow research, normalized to 500 employees:
Orphaned accounts (ex-employees with access)5
Unused licenses12
IT hours spent on manual management/year85 hours
Unused license cost/year$3,500
IT labor cost/year$5,100
Cost of compliance misses/year$890
Total annual financial impact$9,490

The ThreatConnect pricing problem

ThreatConnect gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Tier comparison

PlanPriceSSOSCIM
ProNot disclosed
BusinessNot disclosed
EnterpriseCustom quote

Pricing and provisioning availability

PlanPriceSSOSCIM
ProNot disclosed
BusinessNot disclosed
EnterpriseCustom quote

What this means in practice

IT teams managing ThreatConnect face a complete provisioning gap:

No automated user creation
Every new security analyst requires manual account setup by ThreatConnect administrators
No role synchronization
User permissions and group memberships must be configured individually within ThreatConnect's interface
No deprovisioning automation
Departing employees' accounts remain active until manually disabled, creating security risks in a threat intelligence platform

This creates significant overhead for security teams who need rapid onboarding for incident response scenarios and reliable offboarding for access control.

Additional constraints

Enterprise-only SSO
SAML authentication requires custom enterprise contracts with undisclosed pricing
Threat intelligence focus
Platform architecture prioritizes threat data integration over identity management capabilities
Manual API key management
Service accounts and integrations require individual key provisioning and rotation
No IdP integration roadmap
No published timeline for SCIM or enhanced provisioning features

Summary of challenges

  • ThreatConnect does not provide native SCIM at any price tier
  • Organizations must rely on third-party tools or manual provisioning
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What ThreatConnect actually offers for identity

SAML SSO (Enterprise only)

ThreatConnect supports SAML 2.0 authentication through custom configuration:

SettingDetails
ProtocolSAML 2.0
Supported IdPsOkta, Entra ID, custom SAML providers
ConfigurationCustom SAML app setup required
User requirementManual user creation in ThreatConnect

Critical limitation: ThreatConnect provides no automated user provisioning. Every user must be manually created in the platform before they can authenticate via SSO.

Okta Integration Status

ThreatConnect has no official Okta Integration Network (OIN) listing:

FeatureSupported?
SAML SSO✓ Via custom app
OIDC SSO❌ No
Create users❌ No
Update users❌ No
Deactivate users❌ No
Group push❌ No

Microsoft Entra Integration

ThreatConnect integrates with Microsoft's security ecosystem but offers limited identity management:

FeatureDetails
SSO supportSAML 2.0 via enterprise app
Sentinel integration✓ Threat intelligence feeds
User provisioning❌ Manual only
Group sync❌ Not supported

The reality: ThreatConnect is a threat intelligence platform (TIP) and SOAR solution, not an identity-aware application. Identity management capabilities are minimal - you get basic SAML authentication and nothing else. Teams need manual processes for user lifecycle management across all pricing tiers.

What IT admins are saying

ThreatConnect's lack of automated provisioning creates operational headaches for security teams managing user access:

  • Manual user provisioning required despite SSO implementation
  • No visibility into who has access without logging into ThreatConnect directly
  • Delayed onboarding for new security analysts and threat intelligence teams
  • Risk of orphaned accounts when team members leave or change roles

We have SSO working but still have to manually create every user account in ThreatConnect. For a security platform, you'd expect better identity management capabilities.

IT Admin, Reddit r/cybersecurity

The platform is powerful for threat intel but the user management is stuck in the past. Everything has to be done manually in their interface.

Security Operations Manager, Spiceworks Community

The recurring theme

While ThreatConnect excels as a threat intelligence platform, IT teams struggle with basic user lifecycle management, creating security risks and administrative overhead for the very teams responsible for organizational security.

The decision

Your SituationRecommendation
Small security team (<10 analysts)Manual management acceptable for core team
Threat intelligence focused deploymentManual management with SSO for authentication
Large SOC with frequent analyst turnoverUse Stitchflow: automation essential for rapid onboarding
Multi-tenant MSSP operationsUse Stitchflow: automation critical for scale
Enterprise with strict compliance requirementsUse Stitchflow: automated provisioning ensures audit trail

The bottom line

ThreatConnect excels as a threat intelligence platform but offers zero SCIM provisioning capabilities across all plans. For security operations that need automated user lifecycle management without the overhead of manual account creation, Stitchflow delivers the provisioning automation that ThreatConnect simply doesn't provide.

Make ThreatConnect workflows AI-native

ThreatConnect has no native SCIM. We build complete offboarding, user access reviews, and license workflows across every app, including the ones without APIs.

Covers apps without native SCIM, including the ones without APIs
Less than a week, start to finish (~2 hours of your time)
Built with your team; extend to anything else in the company
Book a Demo

Technical specifications

SCIM Version

Not specified

Supported Operations

Not specified

Supported Attributes

No SCIM provisioning supportSSO via SAML 2.0 onlyManual user management requiredEnterprise pricing not publicly disclosedFocus is on threat intelligence platform (TIP) and SOAR, not identity management

Plan requirement

Not specified

Prerequisites

Not specified

Key limitations

  • No SCIM provisioning support
  • SSO via SAML 2.0 only
  • Manual user management required
  • Enterprise pricing not publicly disclosed
  • Focus is on threat intelligence platform (TIP) and SOAR, not identity management

Documentation not available.

Unlock SCIM for
ThreatConnect

ThreatConnect has no native SCIM. We still automate end-to-end workflows across every app, including the ones without APIs.

See how it works
Admin Console
Directory
Applications
ThreatConnect logo
ThreatConnect
via Stitchflow

Last updated: 2026-01-20

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

Abnormal Security logo

Abnormal Security

No SCIM

Security / Email Security

ProvisioningNot Supported
Manual Cost$9,490/yr

Abnormal Security, the AI-powered email security platform protecting against BEC and phishing attacks, does not offer SCIM provisioning on any plan. While the platform supports SAML 2.0 SSO integration with identity providers like Okta and Entra ID, this only handles authentication—not automated user lifecycle management. Security teams must manually provision and deprovision analyst access through Abnormal's portal, creating operational overhead and potential security gaps in a platform specifically designed to protect against email-based threats. This manual provisioning model creates significant challenges for security operations. When new SOC analysts join or existing team members change roles, IT admins must coordinate manual account creation and permission updates in Abnormal Security. For a platform that's critical to threat detection and incident response, delays in provisioning can leave security gaps, while delayed deprovisioning creates compliance risks. The irony is stark: a security platform designed to prevent account takeover and credential abuse lacks the automated provisioning controls that prevent exactly these risks.

View full guide
Airwallex logo

Airwallex

No SCIM
ProvisioningNot Supported
Manual Cost$9,490/yr

Airwallex, the global payments and treasury platform, offers no SCIM provisioning support on any plan, including their custom Accelerate enterprise tier. Despite being positioned for enterprise use with features like multi-entity management and advanced treasury controls, Airwallex lacks any official identity provider integrations—no SSO, no provisioning, and no presence in major IdP galleries like Okta's OIN or Microsoft Entra. This creates a significant operational burden for IT teams managing financial access across growing organizations, where manual user provisioning and deprovisioning in a payments platform presents both efficiency and security risks. The absence of identity management capabilities means IT administrators must manually create, update, and remove user accounts in Airwallex—a particularly concerning gap given that this platform handles sensitive financial operations, cross-border payments, and treasury management. Without automated deprovisioning, former employees could retain access to financial systems, creating compliance risks and potential security vulnerabilities that most finance and IT teams cannot afford to overlook.

View full guide
Alkami logo

Alkami

No SCIM
ProvisioningNot Supported
Manual Cost$9,490/yr

Alkami, the digital banking platform used by banks and credit unions, does not offer SCIM provisioning or public SSO integrations. As an enterprise-only platform with custom pricing, Alkami appears to handle user management through direct account administration rather than standardized identity protocols. This creates significant challenges for financial institutions that need to integrate Alkami with their existing identity infrastructure—particularly problematic given the compliance requirements and security standards that banks must maintain. The lack of automated provisioning means IT teams at financial institutions must manually create, update, and deprovision user accounts in Alkami. For a platform handling sensitive financial data and customer information, this manual approach introduces compliance risks and operational overhead. Banks typically require seamless integration between their core identity systems and all applications accessing customer data.

View full guide