> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.simplyprint.io/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# SCIM provisioning: automatically sync users from your identity provider

# SCIM provisioning: automatically sync users from your identity provider

SCIM lets your identity provider keep your SimplyPrint members in sync automatically. When you add, change, or remove someone in your directory, that change flows into SimplyPrint on its own - no manual inviting, no CSV uploads, no leftover accounts. This guide covers what SCIM does, what you need, where to set it up, and how to read the activity log when something looks off. For step-by-step instructions in your specific provider, follow one of the provider guides linked below.

|| SCIM provisioning is part of the School and Enterprise plans, alongside single sign-on. If you used SSO on a Print Farm plan before it moved to Enterprise, your access is kept.

| SCIM is the automatic, ongoing way to manage members. If you just need a one-time bulk add, see [Importing users from a CSV or directory export](https://help.simplyprint.io/en/article/importing-users-from-a-csv-or-directory-export-1gptsxc/). To tidy up members who are already in your account, see [Cleaning up and removing users from your account](https://help.simplyprint.io/en/article/cleaning-up-and-removing-users-from-your-account-1e2a42y/).

## What you'll find here
- What SCIM does in SimplyPrint
- Requirements and which providers are supported
- Where to set it up
- Connection details and tokens
- Provider setup guides
- What gets synced
- Controlling deprovisioning (the grace period)
- The activity log
- Troubleshooting

## What SCIM does
SCIM (System for Cross-domain Identity Management) is an open standard that directories use to push user data to other apps. With SCIM connected, your identity provider automatically:

- **Creates** a SimplyPrint member when you assign someone to the SimplyPrint app in your directory.
- **Updates** their name and email when those change in your directory.
- **Deactivates** them (blocks sign-in) when you disable them in your directory.
- **Removes** them from your account when you unassign or delete them.
- **Syncs groups**, so your directory groups can drive SimplyPrint user groups, and (on school accounts) become classes.

Members provisioned through SCIM sign in through your single sign-on, so they never set a SimplyPrint password.

## Requirements
||| SCIM needs single sign-on set up and active first. SCIM provisions the accounts; SSO is how those people actually sign in. Set up SAML or OIDC before you start here.

- **SAML or OIDC single sign-on** is connected and active for your account. Start with [Set up Single sign-on (SSO) for SimplyPrint](https://help.simplyprint.io/en/article/set-up-single-sign-on-sso-for-simplyprint-4coj1g/) if you haven't yet.
- **A School or Enterprise plan** (the plans that include SSO).
- **Permission to manage user-registration settings** for your account. Full account administrators have this, and it can also be granted on its own.
- **An identity provider that can push via SCIM** - see below.

### Which providers can push via SCIM
SimplyPrint's SCIM server works with the providers that support SCIM provisioning to custom apps:

- **Microsoft Entra ID** (formerly Azure AD)
- **Okta**
- **OneLogin**

| **Using Google Workspace?** Google cannot push to custom SCIM apps. Instead, either let SAML or OIDC create accounts automatically the first time each person signs in, or do a one-time bulk add with [Importing users from a CSV or directory export](https://help.simplyprint.io/en/article/importing-users-from-a-csv-or-directory-export-1gptsxc/) - Google's user export is auto-detected.

|| **Danish institutions using UniLogin** don't need SCIM. SimplyPrint syncs your roster automatically from UniLogin (STIL), so provisioning is already handled for you.

## Where to set up SCIM
1. Go to **Settings → Organization → User registration**.
2. With SAML or OIDC active, find the **User provisioning** section.
3. Click **Set up SCIM provisioning**.

The SCIM window opens with a tab for each provider (**Microsoft Entra ID**, **Okta**, **OneLogin**, and **Other**) at the top - pick yours for an in-app summary of the steps and a link to its full guide. Below the tabs are two sections: **Connection details** and **Activity**.

## Connection details and tokens
The **Connection details** section is where you get the two things your identity provider needs: the SCIM base URL and a bearer token.

Your SCIM base URL (also called the tenant or connector URL) is shown with a copy button:

https://api.simplyprint.io/scim/v2

| Always copy the base URL from the Connection details section rather than typing it - copy the exact value shown for your account.

Your identity provider authenticates to SimplyPrint with a bearer token. In the same **Connection details** section:

1. Enter a name (for example, "Entra ID") so you can tell tokens apart later.
2. Click **Create token**.
3. Copy the token immediately - it's shown only once and can't be retrieved again.
4. Paste it into your identity provider as the secret / bearer token.

The Connection details section lists each token's name, prefix, when it was last used, and the client that used it. You can keep up to five active tokens at once; if you reach the limit, revoke one you no longer use. To cut off a provider's access, click **Revoke** next to its token - access stops immediately. If a token is ever exposed, revoke it and create a new one.

## Provider setup guides
Pick your provider's tab in the SCIM window for the short version, or follow the full step-by-step guide:

- [Set up SCIM provisioning with Microsoft Entra ID](https://help.simplyprint.io/en/article/set-up-scim-provisioning-with-microsoft-entra-id-for-simplyprint-s2alvw/)
- [Set up SCIM provisioning with Okta](https://help.simplyprint.io/en/article/set-up-scim-provisioning-with-okta-for-simplyprint-1ffupsi/)
- [Set up SCIM provisioning with OneLogin](https://help.simplyprint.io/en/article/set-up-scim-provisioning-with-onelogin-for-simplyprint-15gr2mf/)

Any other SCIM 2.0 provider works too: point it at the base URL above, authenticate with a bearer token, and enable user and group provisioning.

## What gets synced
Once provisioning is on, your directory drives these in SimplyPrint:

- **Accounts** are created, updated, deactivated, and removed to match your directory.
- **Groups** pushed from your directory can map to SimplyPrint user groups (which set permissions) through your SSO group mappings.
- **On school accounts, pushed groups become classes.** Group membership can also drive teacher status, again through your SSO group mappings.

For how group names turn into user groups, permissions, and teacher status, see [SAML single sign-on: user groups, group mapping, and teacher mapping](https://help.simplyprint.io/en/article/saml-single-sign-on-user-groups-group-mapping-and-teacher-mapping-lfgz7/). The same mappings apply to SCIM-provisioned users.

## Controlling deprovisioning
Back in **Settings → Organization → User registration → User provisioning**, the toggle **Automatically create and remove user accounts from your identity provider's directory** governs whether directory changes add and remove members here.

When it's on, you can set a grace period: **Remove users [N] days after they disappear from your directory** (anywhere from 0 to 90 days; 0 removes them immediately). This gives you a window to catch mistaken removals before a member loses access.

Two directory actions behave differently:

- **Deactivating** a user in your directory blocks their sign-in but keeps their membership. This is reversible - reactivate them in your directory and they're back.
- **Deleting or unassigning** a user removes them from your SimplyPrint account after the grace period.

||| Removal takes a member out of this account only. It does not delete their SimplyPrint account or any other account they belong to.

## The activity log
The **Activity** section of the SCIM window is your provisioning history. Every operation your directory performs - create, update, deactivate, remove, and group sync - is logged with a timestamp, the operation, who it affected, the source, and whether it succeeded. A failed operation shows a red icon; hover it to see the error.

If you're not sure why someone was or wasn't provisioned, this is the first place to look.

## Troubleshooting
- **"Test connection" fails in your provider:** double-check the base URL is the exact value from the Connection details section and that the token was pasted without extra spaces. If in doubt, create a fresh token and try again.
- **A user wasn't created:** confirm they're assigned to the SimplyPrint app in your directory, and that single sign-on is still active. Check the Activity section for a failed create operation and its error.
- **Groups aren't mapping to user groups or classes:** group sync has to be enabled in your provider (for example, Okta's "Push Groups"), and your SSO group mappings have to match the group names your directory sends. See [SAML single sign-on: user groups, group mapping, and teacher mapping](https://help.simplyprint.io/en/article/saml-single-sign-on-user-groups-group-mapping-and-teacher-mapping-lfgz7/).
- **Someone was removed who shouldn't have been:** increase the grace period so you have longer to react, and remember that deactivating (rather than deleting) in your directory keeps the membership.
- **Provisioning stopped working after a token change:** if you revoked or rotated a token, update your provider with the new one - the old token no longer has access.

## Related articles
- [Set up SCIM provisioning with Microsoft Entra ID](https://help.simplyprint.io/en/article/set-up-scim-provisioning-with-microsoft-entra-id-for-simplyprint-s2alvw/)
- [Set up SCIM provisioning with Okta](https://help.simplyprint.io/en/article/set-up-scim-provisioning-with-okta-for-simplyprint-1ffupsi/)
- [Set up SCIM provisioning with OneLogin](https://help.simplyprint.io/en/article/set-up-scim-provisioning-with-onelogin-for-simplyprint-15gr2mf/)
- [Set up Single sign-on (SSO) for SimplyPrint](https://help.simplyprint.io/en/article/set-up-single-sign-on-sso-for-simplyprint-4coj1g/)
- [SAML single sign-on: user groups, group mapping, and teacher mapping](https://help.simplyprint.io/en/article/saml-single-sign-on-user-groups-group-mapping-and-teacher-mapping-lfgz7/)
- [Importing users from a CSV or directory export](https://help.simplyprint.io/en/article/importing-users-from-a-csv-or-directory-export-1gptsxc/)
- [Cleaning up and removing users from your account](https://help.simplyprint.io/en/article/cleaning-up-and-removing-users-from-your-account-1e2a42y/)