Enterprise / Directory sync
SCIM Provisioning
Create, update, and deactivate MemorySync accounts automatically from your directory using the SCIM 2.0 protocol.
Lifecycle
What each directory change does
A MemorySync account is created with your default role, so the person can sign in without anyone filing a ticket.
Compatibility
Supported providers
These are the provisioning options available in Settings → SCIM. Each one is configured with a dedicated provisioning token and the SCIM base URL shown during setup.
OktaAzure ADOneLogin
Operations
Keeping provisioning healthy
- Use a dedicated token
- Provisioning authenticates with its own bearer token, separate from your API keys, so it can be rotated independently.
- Watch sync health
- The dashboard reports recent provisioning runs and failures. A failing sync usually means a revoked token or a changed directory permission.
- Deactivation over deletion
- Directory removal deactivates the account rather than erasing history, which is what auditors expect.
- Combine with SSO
- SCIM manages who has an account; SSO manages how they authenticate. Most organizations enable both.
Was this page helpful?