doc: added tip for SCIM

This commit is contained in:
Sheen Capadngan
2024-11-23 03:11:06 +08:00
parent 7c62a776fb
commit 63fac39fff
+19 -10
View File
@@ -3,11 +3,15 @@ title: "SCIM Overview"
description: "Learn how to provision users for Infisical via SCIM." description: "Learn how to provision users for Infisical via SCIM."
--- ---
<Note>
SCIM provisioning can only be enabled when either SAML or OIDC is setup for
the organization.
</Note>
<Info> <Info>
SCIM provisioning is a paid feature. SCIM provisioning is a paid feature. If you're using Infisical Cloud, then it
is available under the **Enterprise Tier**. If you're self-hosting Infisical,
If you're using Infisical Cloud, then it is available under the **Enterprise Tier**. If you're self-hosting Infisical, then you should contact [email protected] to purchase an enterprise license
then you should contact [email protected] to purchase an enterprise license to use it. to use it.
</Info> </Info>
You can configure your organization in Infisical to have users and user groups be provisioned/deprovisioned using [SCIM](https://scim.cloud/#Implementations2) via providers like Okta, Azure, JumpCloud, etc. You can configure your organization in Infisical to have users and user groups be provisioned/deprovisioned using [SCIM](https://scim.cloud/#Implementations2) via providers like Okta, Azure, JumpCloud, etc.
@@ -24,9 +28,14 @@ SCIM providers:
**FAQ** **FAQ**
<AccordionGroup> <AccordionGroup>
<Accordion title="Why do SCIM-provisioned users have to finish setting up their account?"> <Accordion title="Why do SCIM-provisioned users have to finish setting up their account?">
Infisical's SCIM implementation accounts for retaining the end-to-end encrypted architecture of Infisical because we decouple the **authentication** and **decryption** steps in the platform. Infisical's SCIM implementation accounts for retaining the end-to-end
encrypted architecture of Infisical because we decouple the
For this reason, SCIM-provisioned users are initialized but must finish setting up their account when logging in the first time by creating a master encryption/decryption key. With this implementation, IdPs and SCIM providers cannot and will not have access to the decryption key needed to decrypt your secrets. **authentication** and **decryption** steps in the platform. For this
</Accordion> reason, SCIM-provisioned users are initialized but must finish setting up
</AccordionGroup> their account when logging in the first time by creating a master
encryption/decryption key. With this implementation, IdPs and SCIM providers
cannot and will not have access to the decryption key needed to decrypt your
secrets.
</Accordion>
</AccordionGroup>