What Is It?

Google has officially launched inbound SCIM (System for Cross-domain Identity Management) support for Google Workspace. This feature allows IT administrators to synchronize their Google Workspace directory in real-time with any SCIM-compliant Identity Provider (IdP), HR Information System (HRIS), or custom-built application. By acting as a SCIM Service Provider, Google Workspace can now automatically ingest, update, and deprovision user accounts and groups, replacing the need for fragile, custom-coded API integrations.

What Is the Impact?

info
The introduction of inbound SCIM marks a significant leap in administrative efficiency. By automating the identity lifecycle, IT teams are liberated from the repetitive, manual tasks of creating individual user accounts or updating profile details. This not only reduces operational overhead but also minimizes the risk of human error, which is often the primary cause of misconfigured access rights in growing organizations.

From a security perspective, this update is a game-changer. Instant deprovisioning is now a reality; the moment an employee leaves the company or changes departments in the HR system, their access to Workspace and downstream apps like Gemini Enterprise is revoked in real-time. This eliminates the security vulnerabilities associated with 'orphaned' accounts, significantly simplifying your compliance audits and internal governance.

Finally, the user experience is dramatically improved. New hires are granted the correct access privileges the moment they join, ensuring they have immediate access to all necessary productivity tools. This frictionless onboarding process allows employees to be productive from day one, reflecting a modern, professional IT environment that supports organizational growth.

Who Is It For?

This feature is designed for forward-thinking organizations, including:

  • check_circleIT Administrators looking to reduce manual directory management.
  • check_circleOrganizations using central identity providers like Okta, OneLogin, or Azure AD.
  • check_circleEnterprises requiring strict compliance controls for user offboarding.
  • check_circleCompanies managing complex, multi-application IT environments.

When Will It Roll Out?

The rollout commences on July 9, 2026. It is a gradual deployment, meaning it may take up to 15 days for the feature to become visible across both Rapid Release and Scheduled Release domains.

What Should You Do?

To leverage this new functionality, follow these configuration steps in your Admin console:

1
Step 1
Log in to the
Admin consolearrow_forward_iosDirectoryarrow_forward_iosUsersarrow_forward_iosManage external directories
.
2
Step 2
Initiate a new SCIM connection to generate the unique authentication token for your IdP.
3
Step 3
Copy the endpoint URL and token into your external identity provider’s dashboard.
4
Step 4
Test the synchronization to ensure that user and group attributes are mapping correctly.
settingsPro Tip
Use the admin controls to 'lock' synced groups. This prevents manual changes within the Google Admin console that might otherwise conflict with your source of truth.

SCIM Google Workspace

Background & Context

Identity lifecycle management has traditionally been a fragmented process involving custom scripts and manual oversight. By adopting the open SCIM protocol, Google is enabling a more interoperable ecosystem. This move reflects a broader industry shift towards zero-trust security architectures, where identity is the primary perimeter. By standardizing how identities flow into the Google cloud, organizations can maintain a consistent security posture across their entire SaaS stack.

Conclusion

Inbound SCIM is more than just a convenience; it is a structural improvement for your identity management strategy. By automating provisioning and deprovisioning, you free up your IT team for higher-value tasks while ensuring your security posture remains airtight. If you need assistance navigating these new configurations, the Cloud Captains team is here to help.