Connect your identity provider
Three separate mechanisms, often confused. They solve different problems and are worth keeping distinct.
| What it does | Why it matters | |
|---|---|---|
| SAML 2.0 | Sign-in against your existing identity provider | No second directory to maintain |
| SCIM | Provisions and deprovisions accounts | Offboarding stops being a manual checklist |
| EMM | Enforces device posture before a session opens | An approved user on an unapproved device is still a risk |
Why SCIM is the one to prioritise
SAML is the visible one, but SCIM is where the risk sits. SCIM provisions and deprovisions without anyone creating a password, which means a leaver's access ends when your directory says it ends, rather than when somebody remembers to go and remove it.
EMM enforces before, not after
Device posture is checked before a session opens. A check that runs after the session is established has already lost.
Availability
SAML and SCIM are on Business and Enterprise. EMM is Enterprise.
Where to go next
- SAML · SCIM · EMM — the reference page
- Native data loss prevention — what protects the data once someone is in