What Is It?
Google has officially launched inbound SCIM (System for Cross-domain Identity Management) support for Google Workspace. This feature allows IT administrators to synchronize their Google Workspace directory in real-time with any SCIM-compliant Identity Provider (IdP), HR Information System (HRIS), or custom-built application. By acting as a SCIM Service Provider, Google Workspace can now automatically ingest, update, and deprovision user accounts and groups, replacing the need for fragile, custom-coded API integrations.
What Is the Impact?
From a security perspective, this update is a game-changer. Instant deprovisioning is now a reality; the moment an employee leaves the company or changes departments in the HR system, their access to Workspace and downstream apps like Gemini Enterprise is revoked in real-time. This eliminates the security vulnerabilities associated with 'orphaned' accounts, significantly simplifying your compliance audits and internal governance.
Finally, the user experience is dramatically improved. New hires are granted the correct access privileges the moment they join, ensuring they have immediate access to all necessary productivity tools. This frictionless onboarding process allows employees to be productive from day one, reflecting a modern, professional IT environment that supports organizational growth.
Who Is It For?
This feature is designed for forward-thinking organizations, including:
- IT Administrators looking to reduce manual directory management.
- Organizations using central identity providers like Okta, OneLogin, or Azure AD.
- Enterprises requiring strict compliance controls for user offboarding.
- Companies managing complex, multi-application IT environments.
When Will It Roll Out?
The rollout commences on July 9, 2026. It is a gradual deployment, meaning it may take up to 15 days for the feature to become visible across both Rapid Release and Scheduled Release domains.
What Should You Do?
To leverage this new functionality, follow these configuration steps in your Admin console:

Background & Context
Identity lifecycle management has traditionally been a fragmented process involving custom scripts and manual oversight. By adopting the open SCIM protocol, Google is enabling a more interoperable ecosystem. This move reflects a broader industry shift towards zero-trust security architectures, where identity is the primary perimeter. By standardizing how identities flow into the Google cloud, organizations can maintain a consistent security posture across their entire SaaS stack.
Conclusion
Inbound SCIM is more than just a convenience; it is a structural improvement for your identity management strategy. By automating provisioning and deprovisioning, you free up your IT team for higher-value tasks while ensuring your security posture remains airtight. If you need assistance navigating these new configurations, the Cloud Captains team is here to help.