Stitchflow
Zenefits logo

Zenefits SCIM guide

Connector Only

How to automate Zenefits user provisioning, and what it actually costs

Summary and recommendation

Zenefits offers SCIM provisioning integration with major identity providers like Okta, Azure AD, and OneLogin, but only starting from their Growth plan ($16-20/employee/month). While the SCIM implementation supports full user lifecycle management including creation, updates, deactivation, and group provisioning, Azure AD users specifically require Premium P1/P2 licensing for SCIM functionality. The platform also supports using Zenefits as a profile source for other applications through Okta's Group Linking feature.

For organizations below the Growth tier or those using Azure AD without Premium licensing, this creates a significant provisioning gap. Manual user management in an HR platform defeats the purpose of centralized identity governance, especially when Zenefits often serves as the authoritative source for employee data across the organization. The compliance risk is substantial—without automated deprovisioning, terminated employees could retain access to sensitive benefits and payroll information.

The strategic alternative

Zenefits has no native SCIM. Automate offboarding, user access reviews, and license workflows across every app, including the ones without APIs. We maintain the integration layer underneath. You focus on judgment, not plumbing.

Quick SCIM facts

SCIM available?No
SCIM tier requiredN/A
SSO required first?Yes
SSO available?Yes
SSO protocolSAML 2.0
DocumentationNot available

Supported identity providers

IdPSSOSCIMNotes
OktaSupports Group Linking and Schema Discovery. Can use Zenefits as profile source for other apps.
Microsoft Entra IDAzure AD Premium P1/P2 required for SCIM provisioning.
Google WorkspaceVia third-partyNo native support
OneLoginVia third-partyNo native support

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages Zenefits accounts manually. Here's what that costs:

Source: Stitchflow aggregate data across apps with 2+ instances, normalized to 500 employees
Orphaned accounts (ex-employees with access)7
Unused licenses12
IT hours spent on manual management/year101 hours
Unused license cost/year$3,925
IT labor cost/year$6,088
Cost of compliance misses/year$1,741
Total annual financial impact$11,754

The Zenefits pricing problem

Zenefits gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Tier comparison

PlanPriceSSOSCIM
Essentials$8-10/employee/month
Growth$16-20/employee/month
Zen$27-33/employee/month

Pricing and provisioning requirements

PlanPriceSSOSCIM
Essentials$8-10/employee/month
Growth$16-20/employee/month
Zen$27-33/employee/month

Annual pricing with 20% discount available

What this means in practice

For a 200-employee company, upgrading from Essentials to Growth solely for SCIM access costs an additional $19,200-$24,000 annually. This represents a 100% price increase just to enable basic user provisioning.

The provisioning capabilities themselves are limited:

Azure AD
Requires Premium P1/P2 licensing ($6-$9/user/month additional cost)
Google Workspace
No SCIM support available
Schema limitations
Basic user attributes only, limited custom field mapping

Additional constraints

IdP vendor lock-in
Different provisioning capabilities across Okta, Azure AD, and OneLogin create inconsistent experiences
HR system complexity
As a benefits platform, Zenefits often needs to sync WITH other HR systems, creating circular dependency issues
Manual group management
Limited group provisioning means role-based access requires ongoing manual intervention
No automated offboarding
Deactivated users may retain access to sensitive benefits information until manually removed

Summary of challenges

  • Zenefits does not provide native SCIM at any price tier
  • Organizations must rely on third-party tools or manual provisioning
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What the upgrade actually includes

SCIM Provisioning (Growth tier and above)

Zenefits includes user provisioning capabilities starting with the Growth plan:

FeatureSupported
Create users✓ Yes
Update user attributes✓ Yes
Deactivate users✓ Yes
Group provisioning✓ Yes
Schema discovery✓ Yes
Bidirectional sync✓ Yes (can serve as profile source)

The Growth tier starts at $16-20 per employee per month (with 20% discount for annual billing). For a 100-person company, you're looking at $15,360-19,200 annually just to access SCIM provisioning.

What else you're paying for

The Growth plan bundles SCIM with extensive HR and benefits administration features:

Advanced benefits administration and enrollment
Performance management tools
Advanced reporting and analytics
Compliance management
Time and attendance tracking
Payroll integrations

Reality check: If you just need identity provisioning for Zenefits, roughly 80% of what you're paying for consists of HR features your IT team will never touch.

IdP compatibility requirements

While Zenefits supports multiple identity providers, there are specific prerequisites:

Identity ProviderSCIM SupportAdditional Requirements
Okta✓ Full supportGroup Linking and Schema Discovery included
Microsoft Entra ID✓ SupportedAzure AD Premium P1/P2 required
OneLogin✓ SupportedStandard connector available
Google Workspace❌ Not supportedNo direct SCIM integration

Hidden cost alert: If you're using Microsoft Entra ID, you'll need Premium P1 ($6/user/month) or P2 ($9/user/month) licenses on top of Zenefits Growth pricing.

What IT admins are saying

Zenefits's SCIM provisioning has mixed reception among IT teams, with pricing and IdP limitations creating barriers:

  • Azure AD users hit a paywall - Premium P1/P2 required just for basic SCIM provisioning
  • Growth plan requirement ($16-20/employee/month minimum) puts automation out of reach for smaller teams
  • Google Workspace organizations are completely locked out - no SCIM support available
  • HR teams want Zenefits as the identity source, but limited IdP support complicates the flow

Azure AD Premium P1/P2 required for SCIM provisioning

Microsoft Entra documentation

The recurring theme

While Zenefits offers solid SCIM functionality through major IdPs like Okta, the combination of premium licensing requirements and limited Google Workspace support means many organizations end up managing user accounts manually despite having an HR platform that could serve as their identity source.

The decision

Your SituationRecommendation
Small HR team (<25 employees) on Essentials planManual management is acceptable
Growth plan with stable workforceUse native SCIM if you have Azure AD Premium P1/P2
Large organization (100+ employees)Use Stitchflow: automation essential for HR onboarding/offboarding
Multi-IdP environment or using Google WorkspaceUse Stitchflow: broader IdP support than native options
HR system as identity source for other appsUse Stitchflow: critical for downstream provisioning workflows

The bottom line

Zenefits offers solid SCIM support starting with the Growth plan, but it requires Azure AD Premium licensing and lacks Google Workspace integration. For organizations using Zenefits as their HR system of record or managing complex identity workflows, Stitchflow provides the automation and flexibility needed without IdP restrictions.

Make Zenefits workflows AI-native

Zenefits has no native SCIM. We build complete offboarding, user access reviews, and license workflows across every app, including the ones without APIs.

Covers apps without native SCIM, including the ones without APIs
Less than a week, start to finish (~2 hours of your time)
Built with your team; extend to anything else in the company
Book a Demo

Technical specifications

SCIM Version

Not specified

Supported Operations

Not specified

Supported Attributes

Azure AD Premium P1/P2 required for SCIM provisioning

Plan requirement

Not specified

Prerequisites

Not specified

Key limitations

  • Azure AD Premium P1/P2 required for SCIM provisioning

Documentation not available.

Configuration for Okta

Integration type

Okta Integration Network (OIN) app

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Okta Admin Console → Applications → Zenefits → Sign On

Supports Group Linking and Schema Discovery. Can use Zenefits as profile source for other apps.

Use Stitchflow for automated provisioning.

Unlock SCIM for
Zenefits

Zenefits has no native SCIM. We still automate end-to-end workflows across every app, including the ones without APIs.

See how it works
Admin Console
Directory
Applications
Zenefits logo
Zenefits
via Stitchflow

Last updated: 2026-01-11

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

6sense logo

6sense

No SCIM

B2B Revenue Intelligence / ABM

ProvisioningNot Supported
Manual Cost$11,754/yr

6sense, the B2B revenue intelligence platform, has paused SCIM provisioning for new customers until Q4 2026. While existing customers with SCIM enabled can continue using it, new implementations are limited to JIT (Just-In-Time) provisioning through SAML SSO. This creates a significant gap for IT teams managing revenue intelligence access, as JIT only creates users on first login and provides minimal attribute mapping (email, first name, last name only). For an enterprise platform with typical pricing of $55,000-$130,000 annually, the absence of automated user lifecycle management is a substantial limitation. The lack of SCIM until Q4 2026 forces IT teams into manual provisioning workflows for a platform handling sensitive revenue data. While SAML SSO handles authentication, it doesn't address user lifecycle events like role changes, department transfers, or offboarding. This creates compliance risks in revenue teams where access to prospect data and sales intelligence must be tightly controlled. The nearly two-year wait for SCIM restoration means organizations implementing 6sense today face manual user management for the foreseeable future.

View full guide
Aha! logo

Aha!

No SCIM

Product Management / Roadmapping

ProvisioningNot Supported
Manual Cost$11,754/yr

Aha! Roadmaps, the product roadmapping platform, does not support SCIM provisioning on any plan. While Aha! offers SAML 2.0 SSO integration with identity providers like Okta, Entra ID, and OneLogin, this only handles authentication through JIT (Just-In-Time) provisioning. The critical limitation: JIT provisioning creates user accounts with no default role or access permissions, requiring administrators to manually configure access for each user after they first sign in. For product teams managing strategic roadmaps and stakeholder access, this creates significant operational overhead. Since product roadmaps contain sensitive strategic information and stakeholder access typically varies by product area, IT administrators must manually assign appropriate roles and workspace permissions after each user is provisioned. There's no automatic deprovisioning when users leave the organization, creating potential security gaps. This manual process becomes particularly problematic for larger product organizations where dozens of stakeholders across different business units need carefully managed access to specific roadmaps.

View full guide
Appcues logo

Appcues

No SCIM

Product Adoption / User Onboarding

ProvisioningNot Supported
Manual Cost$11,754/yr

Appcues, the product adoption platform used by product managers and growth teams, explicitly does not support SCIM provisioning on any plan—not even Enterprise. While Appcues offers SAML 2.0 SSO integration starting at the Enterprise tier with just-in-time (JIT) provisioning, this only creates users during first login and provides no automated deprovisioning capabilities. For product teams where access needs change frequently as people move between projects or leave the company, this creates a significant security gap. The lack of SCIM means IT teams must manually manage user lifecycle for Appcues accounts, even though the platform handles sensitive product analytics and user flow data. When employees leave or change roles, their Appcues access remains active until manually revoked—a compliance risk that's particularly problematic given Appcues' role in tracking user behavior and product metrics. With MAU-based pricing starting at $300/month and scaling significantly with usage, paying for orphaned accounts also creates unnecessary cost bloat.

View full guide