SCIM 2.0
Nova's SCIM 2.0 connector provisions any cloud application that exposes a standard SCIM interface, with no need for a dedicated connector per system.
What Nova does with SCIM 2.0
- Creates user accounts in the target application and removes them on offboarding
- Assigns and removes group memberships via SCIM PatchOp operations; removing a membership that is already gone is tolerated
- Activates and deactivates accounts via the active flag and sets passwords where the target application supports it
- Checks during recertification whether accounts actually exist and are active in the target application
- Imports the target application's existing groups as entitlements into the Nova catalog through a background job
- Updates user attributes via PatchOp; the last logon can be read from a configurable attribute, since the SCIM standard does not define one
Technical integration
Nova acts as a SCIM client against the /scim/v2 endpoint under a configurable base URL, authenticating with a bearer token, basic auth, or no authentication. SCIM is also the documented route to cloud-hosted SAP systems, for example via SAP Cloud Identity Services (IPS).
In the identity lifecycle
Accounts in the target application follow the lifecycle in Nova: joiners are created, leavers are deactivated via the active flag. Approved requests are provisioned as group memberships, and recertification checks account existence and status directly in the application.
All product names, logos and brands mentioned are property of their respective owners. They are referenced solely to describe compatibility and do not imply any partnership or endorsement.