Add SCIM provisioning documentation for HCP#2561
Conversation
Add comprehensive documentation for SCIM (System for Cross-domain Identity Management) provisioning feature, enabling automated user and group lifecycle management from identity providers. New documentation pages: - scim.mdx: Complete SCIM provisioning guide with setup instructions for Microsoft Entra ID, Okta, Ping ID, and IBM Verify - troubleshoot-scim.mdx: Troubleshooting guide for common SCIM issues Updated existing pages: - docs-nav-data.json: Added SCIM navigation entries after Troubleshoot SSO - sso/index.mdx: Added SCIM references in introduction and guidance sections - users.mdx: Added user provisioning methods section explaining manual vs SCIM - invite-users.mdx: Updated note about SCIM impact on manual invitations - manage-users.mdx: Added section on managing SCIM-provisioned users - groups.mdx: Added group provisioning methods and SCIM management sections - changelog.mdx: Added June 30, 2026 entry for SCIM GA release Key features documented: - Provider-specific setup with attribute mapping tables - SCIM provisioning statuses and conflict handling - Quotas and limits (10K users, 5K groups, 5K members per group) - Deactivation/reactivation behavior - Comprehensive troubleshooting for sync failures, attribute errors, and provider-specific issues Release: GA on June 30, 2026 Supported providers: Microsoft Entra ID, Okta, Ping ID, IBM Verify
Vercel Previews Deployed
|
Broken Link CheckerThis PR contains broken links, but won't be blocked. Use this report to improve content quality: Quick Actions
Need Help?
Internal LinksExternal LinksSummary
Errors per inputErrors in content/hcp-docs/content/docs/changelog.mdx
Errors in content/hcp-docs/content/docs/hcp/iam/sso/index.mdx
Errors in content/hcp-docs/content/docs/hcp/iam/sso/scim.mdx
Errors in content/hcp-docs/content/docs/hcp/iam/sso/troubleshoot-scim.mdx
Redirects per inputRedirects in content/hcp-docs/content/docs/changelog.mdx
Redirects in content/hcp-docs/content/docs/hcp/iam/sso/index.mdx
Redirects in content/hcp-docs/content/docs/hcp/iam/sso/scim.mdx
Redirects in content/hcp-docs/content/docs/hcp/iam/sso/troubleshoot-scim.mdx
|
|
|
||
| ### For users | ||
|
|
||
| If a user with the same email address exists in both HCP and your identity provider, the identity provider user takes precedence. The lifecycle of that user is now managed by your identity provider instead of HCP. |
There was a problem hiding this comment.
I think this is not true. I think the email/pass user@example.com would continue to exist while the SSO user@example.com would live along side.
|
|
||
| When you enable SCIM provisioning, HCP checks your identity provider directory to determine if users or groups already exist in HCP: | ||
|
|
||
| - **For users** - If a user with the same email address exists in both HCP and your identity provider, the identity provider user takes precedence |
There was a problem hiding this comment.
What does precedence mean here?
aimeeu
left a comment
There was a problem hiding this comment.
Thanks for porting this content into the docs. I left some suggestions.
| - A Microsoft Entra tenant | ||
| - A custom application with SAML SSO enabled for your HCP organization | ||
|
|
||
| #### Configuration steps |
There was a problem hiding this comment.
Trevor - We don't normally tell readers how to do something in an external system or application because we don't maintain those docs. It's too easy for our content to become wrong when the external product updates its docs.
However, I spent too much time trying to find the exact instructions you replicated so we could link to them. Closest I came was a question/answer post. So I think in this case, it's OK to leave these instructions in our docs. But I do have concerns on who is going to maintain this content and make sure Azure hasn't changed.
There was a problem hiding this comment.
You made a good oberservation. We can remove if you think its best. Let me know.
These instructions came from an internal user guide . But I agree, they will be hard to keep up to date.
There was a problem hiding this comment.
@rselbach , the plan is to remove this section. But do you feel there is anything we should highlight to users at all?
| - A custom application with SAML SSO enabled for your HCP organization | ||
|
|
||
| #### Configuration steps | ||
|
|
There was a problem hiding this comment.
Question - these instructions match what's in our internal SCIM Provisioning User Guide, but they don't match what's in the Okta page you linked to in the supported providers section. Do the instructions not exist in the Okta docs?
punctuation Co-authored-by: Aimee Ukasick <Aimee.Ukasick@ibm.com>
rewording Co-authored-by: Aimee Ukasick <Aimee.Ukasick@ibm.com>
Co-authored-by: Aimee Ukasick <Aimee.Ukasick@ibm.com>
Removed SCIM provisioning details and simplified user management instructions.
Clarified group creation process when SCIM provisioning is enabled.
Clarified the precedence of SCIM-managed groups over HCP groups in case of name conflicts.
Clarified SCIM provisioning behavior for user management.
Clarified user lifecycle management for SCIM provisioning.
Add comprehensive documentation for SCIM (System for Cross-domain Identity Management) provisioning feature, enabling automated user and group lifecycle management from identity providers.
New documentation pages:
Updated existing pages:
Key features documented:
Release: GA on June 30, 2026
Supported providers: Microsoft Entra ID, Okta, Ping ID, IBM Verify
Description
🎫 [Jira ticket]
Requested review scope:
Review urgency:
All updates:
I have:
labelapplied (hcp+product name)Content checklist (optional)
Please do these things before requesting a review. I have:
hashicorp-education/teamNameto any additional code or example repos as repo admin