SSO is not offboarding: why SCIM has a separate job.
Connect your application to a customer's identity provider. Test sign-in, roles and the account lifecycle separately.
Read the German originalDistinguish sign-in from account management
Central sign-in establishes how a person authenticates. SCIM standardises the provisioning and management of identity data between systems. An application can support SSO while still retaining outdated accounts or groups.
Ask the business customer about their complete process: joining, changing roles and leaving. The authoritative source for group membership must also be clear. Only then can you choose the right combination of interfaces.
Follow deactivation through to the session
When an account is disabled, previously issued sessions may remain valid. Define when and how these sessions end or are checked again. Merely importing a deactivation flag is not a sufficient acceptance test.
Also test a role change and assignment to the wrong tenant. An external group name must not grant broad permissions without validation. Unknown mappings should be visible and retain only limited access.
Test one customer tenant completely
A pilot connects one application with one identity provider. Acceptance testing covers joining, changes, leaving and an outage of the remote system. Any documented emergency access needs its own responsibilities and rules.
After a successful pilot, further customers can follow. Their protocol profiles and role models still require a focused comparison. In operation, pay particular attention to missing synchronisation and approaching certificate changes.
What does this look like in your work?
We can turn the idea into a sensible next step with you.
SSO & SCIM for business customers · Packages