Cloudflare Access SCIM Support Beta

Hello!

I am excited to announce the initial beta of SCIM (System for Cross Domain Identity Management) support in Cloudflare Access.

The initial implementation of SCIM will support:

  1. Revoke Access and WARP tokens on user deactivation
  2. Auto-populate identity provider group values in Access policies
  3. Force a user re-authentication if their identity provider group membership changes

We are supporting AzureAD and Okta in the initial beta period. In the coming months, we will add support for additional identity providers.

If you would like to be part of the beta, please respond here or fill out this form: https://forms.gle/XAPrBUh55RUTErdy9

4 Likes

We’re now in open beta! SCIM is available across all plans.

More information: https://blog.cloudflare.com/access-and-gateway-with-scim/
Developer Docs: Azure AD® · Cloudflare Zero Trust docs
Okta · Cloudflare Zero Trust docs

2 Likes

Hi there! I have a question about adding the SSO login method to our new instance in Cloudflare. To complete the configuration, we would like to enable SCIM and Azure AD Policy Sync. However, these two features are currently in beta mode. Using beta features in Production does not align with our policies. Does anyone have any information or timelines for when these two features will reach general availability? Thank you in advance

thumbnail_image

Hello from the Access product team! SCIM should be coming out of Beta in the next month or two. We are doing some final testing and fixing a few lingering issues that will allow us to call it “Generally Available.”

AD Policy sync has been a bit more of an experimental feature. I don’t think we will be able to move that into GA until early next year. But I can keep this thread updated as it progresses!

Hi @kjohnson1, thanks for the update; I appreciate the quick reply. It’s great to hear that SCIM will be coming out of beta in the next month or two. Please keep us updated on its progress. Thank you!

SCIM for Okta and Entra (AzureAD) are officially out of beta!

1 Like

@kjohnson1

It’s very unclear what the status is now. We use Google Workspaces and all the SCIM toggles appear when adding Google Workspaces as an iDP for a CF Access protected app in CF admin console. However it doesn’t seem to work. More strange I can’t see how you auto-provisioned this in Google. Unlike other vendors adopting SCIM for Google Workspaces it appears Cloudflare isn’t listed here Configure automated user provisioning for your app - Google Workspace Admin Help and despite exhaustive searching I can’t see how its possible to configure custom SCIM endpoints.

I would really appreciate an update here, was the adding of SCIM toggles to the iDP config for Google Workspaces an accident?

If not please share how I would update SCIM secret on Google Workspaces if I regenerate the secret in IdP config on Cloudflare.

1 Like