Skip to content
huub.Huub home

Connect your identity provider

Three separate mechanisms, often confused. They solve different problems and are worth keeping distinct.

What it doesWhy it matters
SAML 2.0Sign-in against your existing identity providerNo second directory to maintain
SCIMProvisions and deprovisions accountsOffboarding stops being a manual checklist
EMMEnforces device posture before a session opensAn approved user on an unapproved device is still a risk

Why SCIM is the one to prioritise

SAML is the visible one, but SCIM is where the risk sits. SCIM provisions and deprovisions without anyone creating a password, which means a leaver's access ends when your directory says it ends, rather than when somebody remembers to go and remove it.

EMM enforces before, not after

Device posture is checked before a session opens. A check that runs after the session is established has already lost.

Availability

SAML and SCIM are on Business and Enterprise. EMM is Enterprise.

Where to go next

We use essential cookies only. The booking calendar on our demo page is Calendly's, and sets its own.