Skip to main content
Version: Version 22

SCIM (User Synchronization)

SCIM (System for Cross-domain Identity Management) is an open standard for automated user synchronization between identity providers and service providers. SCIM communicates user data between an Identity Provider (e.g. Okta, Azure AD) and a Service Provider (e.g. Fortes Change Cloud).

Note: SCIM works in combination with Single Sign-On (SSO). Make sure SSO is configured before setting up SCIM.


Why Use SCIM?​

  • Security: User data management is centralized and automated, reducing the risk of errors.
  • Efficiency: IT departments no longer need custom integrations to connect directories to external tools and apps.
  • Consistency: User data is stored in a consistent manner across all connected systems.
  • Scalability: As organizations grow, SCIM handles the increasing number of user additions, removals, and permission changes without manual effort.

Setting Up SCIM​

Configuration is required on both the Identity Provider side and the Service Provider (Fortes Change Cloud) side.

1. Enable SCIM in Fortes Change Cloud​

As of version 12.1, Fortes Change Cloud supports SCIM for user synchronization. To enable it:

  1. Contact support@fortes.nl to activate the SCIM module. There are no additional costs.
  2. Once enabled, navigate to the Configuration menu in Fortes Change Cloud.
  3. On the SCIM settings page, find the primary and secondary tokens used to establish the link.

Note: The primary and secondary tokens are unique per customer. If you are already using the primary token, you can use the secondary token for a second system. Click Refresh token to generate new tokens.

2. Create a Test Setup​

Before going to production, test the link in a test setup. For example:

  • Use a test Identity Provider.
  • Test with a single user first.

This reduces the risk of issues in production.

3. Configure SCIM at the Identity Provider​

Each Identity Provider has a different configuration process. Refer to the relevant documentation:

ProviderDocumentation Link
Azure ADhttps://docs.microsoft.com/nl-nl/azure/active-directory/saas-apps/fortes-change-cloud-provisioning-tutorial
Oktahttps://help.okta.com/en/prod/Content/Topics/Apps/Apps_App_Integration_Wizard_SCIM.htm
Amazon AWShttps://docs.aws.amazon.com/singlesignon/latest/userguide/scim-profile-saml.html
OneLoginhttps://developers.onelogin.com/scim

4. Synchronize User Data​

When data changes at the Identity Provider (e.g. first name, email address, or username), the data is automatically synchronized with Fortes Change Cloud.

The Identity Provider can also read data from Fortes and correct incorrect values. Check which unique field is used for matching: typically the username or email address.

When employees join or leave the company:

  • New employee: A user is created or activated in Fortes Change Cloud.
  • Departing employee: The user is archived. No data is lost, and employees who return can be reactivated without losing historical data.

FAQ​

Q: Does enabling SCIM have additional costs? A: No. There are no additional costs associated with enabling SCIM. Contact support@fortes.nl to get started.

Q: What happens to user data when an employee leaves? A: The user is archived in Fortes Change Cloud. Historical data is preserved, and the user can be reactivated if the employee returns.

Q: Which unique field is used for matching users? A: Typically the username or email address. Verify this with your Identity Provider configuration.


Support​

For questions about setting up SCIM, contact support@fortes.nl.