Identity and access
Authenticate members with SSO and automate their lifecycle with SCIM
Probo separates authentication from user provisioning. Use SAML single sign-on (SSO) to authenticate organization members through your identity provider, and use SCIM to create, update, and deactivate their access.
How the capabilities work together
Section titled “How the capabilities work together”SSO verifies a member’s identity when they sign in, but it does not create or remove organization memberships. SCIM manages those memberships and user records, but it does not authenticate users. Organizations commonly configure both against the same identity provider so that assignment controls access and SSO protects authentication.
Recommended rollout
Section titled “Recommended rollout”- Verify the email domain used by organization members.
- Configure SSO as optional and test both service-provider and identity-provider initiated sign-in.
- Configure SCIM with a limited group and confirm provisioning, updates, and deprovisioning.
- Expand the SCIM assignment to the intended population.
- Require SSO only after confirming that expected members can sign in and that a recovery path is available.
Probo provides setup guides for Google Workspace, Microsoft Entra ID or Microsoft 365, and Okta under the SSO and SCIM sections.
Related access controls
Section titled “Related access controls”Use access reviews to periodically verify accounts and permissions in Probo and connected applications. Access reviews record reviewer decisions; they do not provision, deprovision, or change authentication policies.