SCIM (System for Cross-domain Identity Management) is an industry standard that automatically synchronizes user accounts between your identity provider (e.g. Microsoft Entra ID) and Masterplan. Instead of manually creating, maintaining, or deactivating accounts, your identity provider handles this automatically.
What SCIM takes care of:
- Automatically creating new user accounts
- Automatically updating existing user data
- Automatically deactivating accounts (e.g. during offboarding)
SCIM is offered in combination with SAML 2.0 (SSO), so that both login (SSO) and account management (SCIM) run through your identity provider.
Important note on invitation emails: When a new user account is created via SCIM, Masterplan automatically sends an invitation email right away. This automatic invitation cannot currently be disabled on a company-wide basis. Plan accordingly if you'd like to set up user groups or departments beforehand, before activating the SCIM connection.
Matching existing accounts: Existing Masterplan users are typically matched against incoming SCIM data via their email address or username. Which attribute is used for matching depends on the configuration on your identity provider's side.
How do I get SCIM set up?
Setup isn't self-service; it's handled together with our team. Reach out to your Masterplan contact or our support team to request a SCIM integration (potentially alongside SAML 2.0 for SSO). Implementation time varies case by case.
Can I connect the same Active Directory to two separate Masterplan instances?
Yes, this is possible, for example if you use two separate Masterplan instances for different parts of your organization (such as one for HR/general use and another for a single team). The following conditions must be met:
- The connection must be set up via two separate Enterprise Apps in your identity provider (e.g. Microsoft Entra ID), one per Masterplan instance
- On the Masterplan side, these must also be two separate companies
- Individual users (identified by the same email address) should not have access to both instances at the same time, as this can cause conflicts in user matching
As long as these conditions are met, both SCIM integrations can run independently of one another without conflicts.
For developers / your IT department: Technical documentation for the User Management API (authorization, schemas, endpoints for creating, updating, and deleting users and user groups) is available in our Developer Portal.