For organizations using a cloud identity provider, Kisi, Brivo, and Verkada are the best-fit physical access control systems. These providers natively support SCIM, enabling automatic synchronization of user identities and group memberships. This automation ensures that as you add or remove employees in your identity software, their door access rights are updated instantly, eliminating manual administrative work.
KisiKisi is a strong choice for teams needing seamless SCIM integration. It is specifically designed to work with providers like Okta and Entra ID to automatically update user access rights based on your current directory status.
82%
2BrivoBrivo provides reliable SCIM-based automation, frequently used for syncing employee directories from Entra ID and Okta. It is an ideal fit if your organization manages security through standardized cloud identity catalogs.58%
3VerkadaVerkada is well-suited for enterprise security teams requiring full SCIM synchronization. Its cloud-native platform allows you to keep users and groups aligned across regional infrastructure and identity accounts.56%
Several modern, cloud-managed physical access control systems (PACS) natively support SCIM (System for Cross-domain Identity Management) provisioning from major cloud identity providers like Microsoft Entra ID (formerly Azure AD), Okta , and JumpCloud.
Popular physical access control platforms that support SCIM-based user and group provisioning include:
Verkada – Integrates via SCIM with Microsoft Entra ID, Okta, and Google Workspace to sync user profiles, groups, and phone numbers directly into Verkada Command . Details can be found via Command Documentation.
Kisi – Offers robust, native SCIM provisioning supporting Okta, Microsoft Entra ID, JumpCloud, and OneLogin, allowing complete automated user lifecycle sync and group membership mapping. Setup steps are outlined in the Kisi SCIM Documentation.
Genea Access Control – Supports automated push-based SCIM provisioning with Microsoft Entra ID and Okta, enabling user and group management (including mobile keys and card number assignments) directly from your IdP. Learn more on the Genea Help Center.
Brivo – Uses dedicated Identity Connectors/SCIM integrations for Microsoft Entra ID and Okta to handle directory synchronization and group-based access alignments. Guides are accessible through the Brivo Support Portal.
Note: While these platforms automate user creation, deactivation, and group mapping via SCIM, most of them explicitly restrict administrator account provisioning via SCIM for security auditing reasons, requiring admin roles to be assigned natively inside the physical security dashboard.
Which cloud identity provider (e.g., Okta, Microsoft Entra ID, or JumpCloud) are you currently using, and are you looking for a system that also supports mobile credentials out of the box?
Yes. Several cloud physical access-control platforms can take users/groups from an identity provider via SCIM and use them to control physical doors.
Platform
SCIM
Documented IdPs
Physical-door provisioning
Kisi
Yes, SCIM 2.0
Okta, Microsoft Entra ID, JumpCloud, OneLogin
Users/groups sync into Kisi and can drive door access groups
Verkada Access
Yes
Okta, Microsoft Entra ID, Google Workspace
SCIM users/groups can be mapped to access groups controlling doors
Brivo Access
Yes, via Brivo Identity Connector
Okta, Microsoft Entra ID, Google Workspace
SCIM provisions users, groups and lifecycle changes into Brivo physical access
Envoy
Yes
Okta, particularly documented for employee/admin provisioning
SCIM keeps the Envoy employee directory synchronized; its platform also handles workplace/door-related workflows
An important distinction
There are two different things vendors sometimes call "SCIM":
SCIM → access-control users — creates/deactivates the person's account in the physical-access platform.
SCIM → access groups/entitlements — also lets IdP group membership determine which doors the person can enter.
For example, Verkada explicitly supports SCIM groups becoming access groups, after which those groups can be assigned access levels to doors. Verkada Help Kisi similarly supports provisioning/deprovisioning and group-membership synchronization.
Brivo is particularly explicit about the lifecycle model: its Identity Connector uses SCIM to push user creation, updates, deactivation and group membership from Entra ID or Okta into Brivo Access, with the resulting permissions applied to physical doors.
If you tell me which cloud IdP you use (Okta, Entra ID, Google Workspace, JumpCloud, OneLogin, etc.), I can narrow this down to the systems that support it and compare SCIM capabilities, door hardware, mobile credentials, APIs, and approximate enterprise pricing.
Several modern cloud-first and hybrid physical door access control systems support automated SCIM (System for Cross-domain Identity Management) provisioning from major cloud identity providers like Okta and Microsoft Entra ID (Azure AD).
The leading physical access control platforms supporting native SCIM provisioning include:
Kisi – Offers robust out-of-the-box SCIM support for both Okta and Microsoft Entra ID , allowing automated user and group synchronization, lifecycle updates, and immediate offboarding.
Brivo – Uses the Brivo Identity Connector via a SCIM endpoint to sync identities, groups, and permission states seamlessly from cloud directories like Okta and Entra ID straight into the Brivo Security Suite.
Genea – Features built-in SCIM provisioning integrations with Microsoft Entra ID and Okta, enabling user creation, automated mobile key dispatch, and instant deprovisioning directly from your identity provider dashboard.
If you can share which specific cloud identity provider (e.g., Okta, Entra ID, Google Workspace) and approximate scale or hardware ecosystem you are working with, I can provide more details on implementation steps or compatibility.
Yes. Several modern cloud-managed physical access control platforms support SCIM provisioning from a cloud IdP, with the exact capabilities depending on the IdP and whether you want to provision door users, groups/access levels, or just administrative accounts.
Access-control system
SCIM
IdPs / directory support
What can be provisioned
Kisi
Yes
Okta, Microsoft Entra ID, JumpCloud, OneLogin
Users; identities can be synchronized into Kisi, with group/access management
Verkada Access Control
Yes
Okta, Microsoft Entra ID, Google Workspace
Users and groups; SCIM groups can become access groups assigned to doors/access levels
People, groups, group assignments, active/inactive status
A couple of important distinctions
Verkada is particularly explicit about SCIM reaching the physical-access layer: SCIM users/groups are provisioned into Command, and a SCIM group can be converted into an access group and assigned access levels for doors.
Kisi supports SCIM 2.0 from multiple IdPs, including Entra ID, Okta, JumpCloud and OneLogin. Its documentation describes the integration as identity provisioning rather than merely SSO.
Brivo uses its Identity Connector as the bridge between the IdP and Brivo Access. Its current documentation specifically describes SCIM synchronization of users/groups and lifecycle changes, including deactivation of physical permissions when an identity is disabled.
LenelS2 Elements is worth considering if you're looking for a more traditional enterprise physical-access platform rather than a newer access-control vendor; Okta documents SCIM synchronization of people, groups, assignments, and status.
If you tell me which cloud IdP you use (Okta, Entra ID, Google Workspace, JumpCloud, OneLogin, etc.), I can narrow this down to systems that support it and compare SCIM → users → groups → door/access-level assignment → automatic offboarding, including which ones work with existing badge readers/controllers.
Yes. Several modern cloud-managed physical access-control platforms support SCIM-based user lifecycle provisioning from a cloud IdP. The clearest options I found are:
Access-control system
SCIM
IdPs explicitly documented
Physical-door integration
Kisi
Yes, SCIM 2.0
Microsoft Entra ID, Okta, OneLogin, JumpCloud
Cloud-managed door controllers/readers
Verkada Access
Yes
Okta, Microsoft Entra ID
Verkada access controllers/readers
Brivo
Yes via Brivo Identity Connector
Okta and other IAM systems
Brivo cloud/on-prem access controllers
Kisi
Kisi has particularly explicit SCIM support. Its documentation says SCIM 2.0 can provision users from Microsoft Entra ID, JumpCloud, Okta, and OneLogin, and SCIM can manage users and their permissions.
For example, with Entra ID, Kisi supports creating/removing users, synchronizing attributes, and provisioning groups/group memberships.
Verkada supports SCIM for Access Control. Its documentation specifically describes provisioning users and groups through SCIM and turning SCIM groups into access groups that can be assigned access levels to doors. Okta and Microsoft Entra ID are explicitly supported.
Brivo has Brivo Identity Connector, which provides SCIM-based provisioning and lifecycle synchronization between an IAM directory and Brivo's physical access system. Brivo says this can keep users, roles, door access, and mobile credentials synchronized.
Okta's integration catalog confirms SCIM provisioning/deprovisioning, group push/linking, create/update/deactivate, and other lifecycle functions for Brivo Identity Connector.
If by "SCIM provisioning" you mean IdP → access-control system → actual door permissions, rather than merely provisioning an account used to log into the access-control console, the three above are good candidates. Kisi and Verkada, in particular, document the relationship between synchronized groups and physical-door access.
If you tell me which IdP you use (Okta, Entra ID, JumpCloud, OneLogin, Google Workspace, etc.) and roughly how many doors/users, I can narrow this to the systems that support your exact provisioning workflow and compare SCIM capabilities, group-to-door mapping, badges/mobile credentials, APIs, and controller hardware.
Several modern, cloud-managed physical door access control systems (PACS) natively support SCIM (System for Cross-domain Identity Management) v2.0 for automated user provisioning and deprovisioning from cloud identity providers like Okta, Microsoft Entra ID (Azure AD), JumpCloud, and Google Workspace.
The primary physical access control platforms that support SCIM provisioning include:
Kisi : Features robust native SCIM v2.0 integration supporting group sync, user creation, updates, and automatic deprovisioning . It connects cleanly with identity providers such as Kisi Identity Management Documentation for Okta, Microsoft Entra ID, JumpCloud, and OneLogin.
Brivo : Utilizes the Brivo Identity Connector and SCIM-based provisioning to mirror directory records straight from your enterprise IAM into physical door access, mobile credentials, and admin logs.
Verkada : Supports automated user provisioning and group mapping via SCIM, with specific configuration documentation for Verkada User Provisioning Documentation covering Okta, Microsoft Entra ID, and a subset of attributes for Google Workspace.
Genea (Access Control) : Offers native SCIM endpoints that integrate smoothly with identity platforms like Microsoft Entra ID and Okta to handle automated employee lifecycle syncing.
Smart MasterKey : Built natively around identity-driven access, supporting SCIM provisioning across major directory services like Okta and Microsoft Entra ID to map role changes directly to physical door permissions.
Which cloud identity provider (e.g., Okta, Entra ID, JumpCloud) are you currently using, and do you need help mapping specific attributes or groups for your doors?
Several modern, cloud-managed physical door access control systems support SCIM (System for Cross-domain Identity Management) v2.0 provisioning. This allows you to automatically provision, deprovision, and sync user profiles and groups directly from cloud identity providers (IdPs) like Microsoft Entra ID (formerly Azure AD), Okta, JumpCloud, and OneLogin.
Leading physical access control platforms offering built-in SCIM provisioning include:
Kisi : Offers native SCIM 2.0 and SAML SSO integration, enabling seamless user lifecycle syncing, automatic deactivation, and group membership updates straight from providers like Entra ID, Okta, and JumpCloud. You can check out their setup guides in the Kisi SCIM Documentation.
Brivo (Brivo Access) : Uses dedicated identity connectors for platforms like Okta and Microsoft Entra ID to push user creation, profile updates, and group-based door permissions in real time. It even supports automated credential automation (such as Brivo Mobile Passes or Wallet passes) via attribute mapping. More details are available via the Brivo Support for Azure Identity Connector.
Genea (Genea Access Control / Sequr) : Features robust native SCIM integrations with Okta and Microsoft Entra ID, allowing automatic user onboarding, profile syncing, group pushes, and instant credential deactivation the moment an employee is removed or modified in your IdP. Implementation steps can be reviewed in the Genea Microsoft Entra ID Integration Guide.
Ubiquiti Access (UniFi) : Offers built-in SCIM provisioning support to sync users and groups directly from enterprise cloud identity environments like Microsoft Entra ID.
Smart MasterKey : Specifically architected around identity-driven physical access, supporting full SCIM lifecycle provisioning with Okta, Microsoft Entra ID, and ADFS.
If you can share which specific Cloud Identity Provider (e.g., Okta, Microsoft Entra ID, JumpCloud) and approximate scale/hardware preferences you are working with, I can help narrow down which of these platforms integrates most cleanly with your existing stack.
Yes. Several cloud physical-access platforms support SCIM-based user/group provisioning from major IdPs:
Kisi — SCIM 2.0 with Microsoft Entra ID, Okta, JumpCloud, and OneLogin.
Verkada Access — SCIM with Okta and Microsoft Entra ID; SCIM groups can become door-access groups.
Brivo — Brivo Identity Connector provides SCIM-based provisioning, including an Entra integration.
Avigilon Alta/Openpath — supports IdP-based provisioning through its cloud access platform; Okta documents the Openpath integration.
If you tell me which IdP you use (Okta, Entra ID, Google Workspace, etc.), I can narrow this to systems with native SCIM support and compare their provisioning capabilities.
Several modern, cloud-managed physical door access control systems support SCIM (System for Cross-domain Identity Management) provisioning from major cloud identity providers like Microsoft Entra ID (formerly Azure AD), Okta, and JumpCloud.
The leading physical access control platforms offering built-in SCIM support include:
Verkada (via Verkada Command) – Integrates cleanly with Microsoft Entra ID and Okta using SCIM token management to synchronize users and group memberships automatically.
Kisi – Supports SCIM v2.0 alongside SAML SSO, allowing complete user lifecycle management (provisioning, deprovisioning, and group updates) from providers like Okta, Microsoft Entra ID, JumpCloud, and OneLogin.
Brivo (via Brivo Access / Identity Connector) – Utilizes SCIM 2.0 endpoints to bridge corporate directories like Entra ID and Okta directly into your physical hardware provisioning flows.
Genea Access Control – Offers a dedicated push-based SCIM integration (compatible with Entra ID and Okta) that treats your cloud IdP as the source of truth for employee records and access rights.
If you share which cloud identity provider you are using (e.g., Okta, Microsoft Entra ID, JumpCloud) and your preferred access control vendor , I can provide the exact integration steps or documentation requirements.
Yes. Several modern cloud-managed physical access-control platforms support SCIM provisioning from an identity provider, so you can automate joiner/mover/leaver workflows rather than manually creating badge/door-access accounts.
Strong options
Kisi — Explicit SCIM 2.0 support. Kisi documents provisioning from Okta, Microsoft Entra ID, JumpCloud, and OneLogin, including users and groups. Groups can be mapped to access teams/groups that determine door permissions.
Verkada Access Control — Supports SCIM with Okta and Microsoft Entra ID. SCIM users/groups can be turned into access groups, which can then be assigned access levels to doors.
Brivo — Brivo Identity Connector provides SCIM-based provisioning, syncing users and roles from an existing IAM/directory into physical access, including door access and mobile credentials.
Ubiquiti UniFi Access — Ubiquiti states that its Identity Enterprise offering supports SCIM provisioning/deprovisioning of users and groups from an IdP. I'd verify the exact SCIM capabilities and licensing for the particular UniFi Access deployment before selecting it.
Important distinction
Don't just look for "SSO with Okta/Entra". SAML/OIDC SSO normally controls logging into the access-control management application; SCIM is what provisions/deprovisions identities and groups. For your use case, the ideal architecture is:
For example, Verkada explicitly allows SCIM groups to become physical-access groups that are assigned door access levels.
If you tell me which cloud IdP you're using (Okta, Entra ID, Google Workspace, JumpCloud, OneLogin, etc.) and roughly how many doors/users, I can narrow this to the best 3–5 systems and compare SCIM capabilities, group-to-door mapping, deprovisioning behavior, hardware, and pricing/licensing.