mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-05 18:26:42 +00:00
doc: added tip for SCIM
This commit is contained in:
@@ -3,11 +3,15 @@ title: "SCIM Overview"
|
|||||||
description: "Learn how to provision users for Infisical via SCIM."
|
description: "Learn how to provision users for Infisical via SCIM."
|
||||||
---
|
---
|
||||||
|
|
||||||
|
<Note>
|
||||||
|
SCIM provisioning can only be enabled when either SAML or OIDC is setup for
|
||||||
|
the organization.
|
||||||
|
</Note>
|
||||||
<Info>
|
<Info>
|
||||||
SCIM provisioning is a paid feature.
|
SCIM provisioning is a paid feature. If you're using Infisical Cloud, then it
|
||||||
|
is available under the **Enterprise Tier**. If you're self-hosting Infisical,
|
||||||
If you're using Infisical Cloud, then it is available under the **Enterprise Tier**. If you're self-hosting Infisical,
|
then you should contact [email protected] to purchase an enterprise license
|
||||||
then you should contact [email protected] to purchase an enterprise license to use it.
|
to use it.
|
||||||
</Info>
|
</Info>
|
||||||
|
|
||||||
You can configure your organization in Infisical to have users and user groups be provisioned/deprovisioned using [SCIM](https://scim.cloud/#Implementations2) via providers like Okta, Azure, JumpCloud, etc.
|
You can configure your organization in Infisical to have users and user groups be provisioned/deprovisioned using [SCIM](https://scim.cloud/#Implementations2) via providers like Okta, Azure, JumpCloud, etc.
|
||||||
@@ -24,9 +28,14 @@ SCIM providers:
|
|||||||
**FAQ**
|
**FAQ**
|
||||||
|
|
||||||
<AccordionGroup>
|
<AccordionGroup>
|
||||||
<Accordion title="Why do SCIM-provisioned users have to finish setting up their account?">
|
<Accordion title="Why do SCIM-provisioned users have to finish setting up their account?">
|
||||||
Infisical's SCIM implementation accounts for retaining the end-to-end encrypted architecture of Infisical because we decouple the **authentication** and **decryption** steps in the platform.
|
Infisical's SCIM implementation accounts for retaining the end-to-end
|
||||||
|
encrypted architecture of Infisical because we decouple the
|
||||||
For this reason, SCIM-provisioned users are initialized but must finish setting up their account when logging in the first time by creating a master encryption/decryption key. With this implementation, IdPs and SCIM providers cannot and will not have access to the decryption key needed to decrypt your secrets.
|
**authentication** and **decryption** steps in the platform. For this
|
||||||
</Accordion>
|
reason, SCIM-provisioned users are initialized but must finish setting up
|
||||||
</AccordionGroup>
|
their account when logging in the first time by creating a master
|
||||||
|
encryption/decryption key. With this implementation, IdPs and SCIM providers
|
||||||
|
cannot and will not have access to the decryption key needed to decrypt your
|
||||||
|
secrets.
|
||||||
|
</Accordion>
|
||||||
|
</AccordionGroup>
|
||||||
|
|||||||
Reference in New Issue
Block a user