Feature Request: Native SCIM Provisioning Support for Okta
I would like Adobe Admin Console to officially support SCIM provisioning from Okta.
Adobe currently supports SAML SSO with Okta for Federated IDs, but it does not provide native user and group provisioning from Okta to Adobe Admin Console. Automating user lifecycle management therefore requires Microsoft Entra ID Sync, User Sync Tool, or a custom implementation using Okta Workflows and the Adobe User Management API.
For organizations that already use Okta as their primary identity provider and lifecycle management platform, introducing another directory or building custom workflows solely for Adobe provisioning creates unnecessary complexity and operational overhead.
We would like Adobe to support the following capabilities:
- SCIM 2.0 user creation, updates, and deactivation from Okta
- User group synchronization through Okta Group Push
- Mapping between Okta groups and Adobe user groups or product profiles
- Automatic license removal when a user is removed from a group
- Deprovisioning when a user is unassigned or deactivated in Okta
- Audit logs showing provisioning results and errors
Frankly, it is disappointing that a company of Adobe’s scale and influence in the enterprise software market does not support a standard SCIM integration with Okta, one of the leading identity management platforms.
SAML SSO alone is no longer sufficient for enterprise identity management. Organizations need an officially supported integration that uses Okta as the source of truth for the complete user lifecycle—including onboarding, role changes, offboarding, and license management.
Please provide Okta with native provisioning capabilities equivalent to those currently available through Microsoft Entra ID Sync.
[Moved to Enterprise & Teams by a moderator]
