SCIM Provisioning: Automate User Management in Sprout Social
Table of Contents
SCIM (System for Cross-domain Identity Management) lets your IT or Sprout admin team manage Sprout user accounts directly from your identity provider (IdP). Instead of adding, updating, and removing users manually in Sprout, you control access centrally in Okta or Microsoft EntraID, and Sprout stays in sync automatically.
With SCIM enabled, you can:
- Automatically create Sprout accounts when you add someone to a group in your IdP
- Keep Org Roles and Profile Permission Sets up to date by managing group membership, not by editing users in Sprout
- Automatically deactivate or remove Sprout access when someone leaves a group or is offboarded in your IdP
SCIM builds on top of an existing SSO connection, so SSO must already be configured for Sprout Social in your identity provider before you set up provisioning.
Choose your identity provider
Setup steps, attribute mappings, and sync timing differ by provider. Select the guide that matches your organization's IdP:
- Configuring SCIM Provisioning with Okta
- SCIM Provisioning with Microsoft Azure Active Directory / EntraID
Each guide walks through prerequisites, preparing your Sprout Roles and Profile Permission Sets, enabling SCIM in Sprout, configuring the connection in your IdP, mapping groups, testing before go-live, and troubleshooting common sync errors.
Was this article helpful?