Stitchflow
Wiz logo

Wiz SCIM guide

Native SCIM

How to automate Wiz user provisioning, and what it actually costs

Native SCIM requires Enterprise plan

Summary and recommendation

Wiz supports native SCIM 2.0 provisioning, but only on their Enterprise tier with custom pricing. Teams on lower tiers have no automated provisioning option, forcing IT admins to manually manage user accounts in what's typically a critical security platform. Additionally, SSO must be configured before SCIM can be enabled, adding deployment complexity.

This creates a significant gap for growing security teams. Without automated provisioning, new hires can't immediately access security dashboards and alerts, while departing employees may retain access longer than policy allows. For a security platform that's meant to protect your entire cloud infrastructure, manual user management introduces exactly the kind of access control risks Wiz is designed to prevent.

The strategic alternative

Wiz gates SCIM behind Enterprise. Skip the Enterprise plan upgrade and automate complete outcomes across your stack. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?Yes
SCIM tier requiredEnterprise
SSO required first?Yes
SSO available?Yes
SSO protocolSAML 2.0
DocumentationNot available

Supported identity providers

IdPSSOSCIMNotes
OktaOIN app with full provisioning
Microsoft Entra IDSSO only
Google WorkspaceJIT onlySAML SSO with just-in-time provisioning
OneLoginSupported

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages Wiz accounts manually. Here's what that costs:

Source: Stitchflow research, normalized to 500 employees:
Orphaned accounts (ex-employees with access)5
Unused licenses12
IT hours spent on manual management/year85 hours
Unused license cost/year$3,500
IT labor cost/year$5,100
Cost of compliance misses/year$890
Total annual financial impact$9,490

The Wiz pricing problem

Wiz gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Plan Structure

PlanPriceSSOSCIM
ProN/A
BusinessN/A
EnterpriseCustom

Note: Wiz doesn't publish pricing for any tier, but Enterprise represents their highest-cost offering with comprehensive cloud security features bundled alongside SCIM access.

What this means in practice

Without published pricing, organizations face:

Lengthy sales cycles
Custom Enterprise pricing requires multiple meetings, technical demos, and negotiation rounds that can extend procurement by months.
Feature bundling
SCIM comes packaged with advanced compliance, governance, and support features that smaller teams may not need but must pay for.
Minimum commitments
Enterprise contracts typically include multi-year terms and minimum user/spend requirements that lock organizations into significant financial commitments.
Budget unpredictability
Custom pricing makes it difficult to budget accurately or compare costs against alternatives during planning cycles.

Additional constraints

SSO prerequisite
SCIM configuration requires SSO to be set up first, adding another layer of Enterprise-tier dependency.
IdP limitations
While Okta supports full SCIM 2.0 provisioning, Microsoft Entra lacks native SCIM support in their gallery integration, forcing Entra customers into custom connector builds or third-party solutions.
All-or-nothing access
Unlike some platforms that offer tiered SCIM features, Wiz provides no provisioning capabilities below Enterprise level.

Summary of challenges

  • Wiz supports SCIM but only at Enterprise tier (Custom)
  • Google Workspace users get JIT provisioning only, not full SCIM
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What the upgrade actually includes

Wiz doesn't sell SCIM à la carte. It's bundled with Enterprise features at custom pricing:

SCIM 2.0 automated provisioning
SAML single sign-on (SSO) - required prerequisite
Advanced security policies and governance
Custom integrations and API access
Priority support and dedicated success management
Advanced compliance reporting
Custom SLA agreements

Stitchflow Insight

The Enterprise tier is designed for large organizations with complex security operations. If you just need automated user provisioning for your security team, you're paying enterprise rates for capabilities like custom compliance frameworks and dedicated support that smaller teams rarely use. We estimate ~60% of Enterprise features are overkill for teams that simply want to automate Wiz user management.

What IT admins are saying

Community sentiment on Wiz's SCIM availability is mixed, with cost concerns dominating discussions. Common complaints:

  • Enterprise-only SCIM forces expensive upgrades for basic provisioning
  • Custom pricing model lacks transparency for budget planning
  • SSO prerequisite creates unnecessary complexity for some deployments
  • Limited provisioning options outside of Okta ecosystem

We wanted to automate user provisioning but hit the Enterprise paywall. For a security tool, they sure make it expensive to implement security best practices.

Reddit r/sysadmin

The lack of SCIM in Azure AD gallery is frustrating. We're an Entra shop and don't want to manage separate provisioning workflows just for Wiz.

IT Community Forum

The recurring theme

Wiz gates essential identity automation behind enterprise pricing, creating barriers for teams that need cloud security tooling with automated user management but can't justify enterprise costs.

The decision

Your SituationRecommendation
On Pro/Business tier, need SCIM provisioningUse Stitchflow: avoid the Enterprise upgrade and custom pricing negotiations
Already on Enterprise with SCIM enabledUse native SCIM: you're paying enterprise prices for the full feature set
Using Microsoft Entra ID as your IdPUse Stitchflow: no native Entra SCIM support in gallery
Small security team, infrequent user changesManual provisioning may work: but monitor for access governance gaps
Need Enterprise security features beyond SCIMEvaluate Enterprise upgrade: SCIM comes bundled with advanced capabilities

The bottom line

Wiz restricts SCIM to Enterprise tier with custom pricing, creating a significant barrier for smaller security teams that need automated provisioning. For organizations on Pro or Business plans, or those using Entra ID, Stitchflow delivers SCIM-level provisioning without the enterprise upgrade or pricing negotiations.

Make Wiz workflows AI-native

Wiz gates SCIM behind Enterprise. We build complete offboarding, user access reviews, and license workflows without that SCIM Tax upgrade.

No Enterprise upgrade required
Less than a week, start to finish (~2 hours of your time)
We maintain the integration layer underneath
Book a Demo

Technical specifications

SCIM Version

2.0

Supported Operations

Create, Update, Deactivate, Groups

Supported Attributes

Not specified

Plan requirement

Enterprise

Prerequisites

SSO must be configured first

Key limitations

  • Enterprise tier required for SCIM
  • SSO must be configured before SCIM
  • Custom pricing only

Documentation not available.

Configuration for Okta

Integration type

Okta Integration Network (OIN) app with SCIM provisioning

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Okta Admin Console → Applications → Wiz → Provisioning

Required credentials

SCIM endpoint URL and bearer token (generated in app admin console).

Configuration steps

Enable Create Users, Update User Attributes, and Deactivate Users.

Provisioning trigger

Okta provisions based on app assignments (users or groups).

Full SCIM 2.0 provisioning support

Wiz gates SCIM behind Enterprise. Stitchflow automates complete workflows without that SCIM Tax upgrade.

Unlock SCIM for
Wiz

Wiz gates SCIM behind Enterprise plan. We automate complete offboarding and access reviews across your stack without that SCIM Tax upgrade.

See how it works
Admin Console
Directory
Applications
Wiz logo
Wiz
via Stitchflow

Last updated: 2026-01-20

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

Alteryx logo

Alteryx

SCIM Tax
SCIM StatusIncluded
Manual Cost$9,490/yr

Alteryx supports native SCIM 2.0 provisioning, but only on Enterprise plans with custom pricing (7+ users minimum). The feature requires SSO (SAML or OIDC) to be configured first and completely overrides manual user management. For teams on Professional ($5,000/user/year) or Business ($10,000-$20,000/user/year) plans, accessing SCIM means upgrading to Enterprise - often a significant cost increase for functionality that should be table stakes. This creates a provisioning gap for most Alteryx deployments. Without automated user lifecycle management, IT teams face manual onboarding/offboarding workflows, delayed access provisioning, and compliance risks around orphaned accounts. The high per-user costs make Alteryx particularly expensive to scale, and forcing an Enterprise upgrade just for basic provisioning automation compounds that challenge.

View full guide
Atlan logo

Atlan

SCIM Tax
SCIM StatusIncluded
Manual Cost$9,490/yr

Atlan supports native SCIM 2.0 provisioning with full user and group management capabilities. However, SCIM is only available on Enterprise tier, which requires custom pricing negotiations. Additionally, SSO must be enabled before SCIM can be configured, and Atlan's pricing tiers (Starter, Premier, Enterprise) are not publicly disclosed, making cost planning difficult for IT teams. This creates a significant barrier for organizations wanting automated provisioning without committing to enterprise-level contracts. For data teams evaluating Atlan, the lack of transparent pricing means you can't budget for provisioning capabilities upfront. The SSO prerequisite also forces organizations into a specific implementation sequence that may not align with their rollout timeline.

View full guide
Benchling logo

Benchling

SCIM Tax
SCIM StatusIncluded
Manual Cost$9,490/yr

Benchling supports SCIM provisioning, but only on Enterprise plans with custom pricing that typically starts at $1M+ annually. This creates a massive barrier: organizations on Professional plans ($20,000+/year) face a 50x+ price increase to unlock automated user provisioning. Even mid-sized life sciences teams end up paying enterprise-level licensing just to automate basic user lifecycle management. The pricing gap is so extreme that most organizations either stick with manual provisioning or delay Benchling adoption entirely. This creates a significant operational burden for IT teams managing researchers across multiple lab environments. Manual user provisioning in a platform that handles sensitive R&D data introduces compliance risks and delays researcher onboarding. When a scientist joins or leaves, IT must manually coordinate access across Benchling's complex permission structure for notebooks, entities, and workflows. For organizations with frequent collaborator access or seasonal research teams, this becomes unmanageable.

View full guide