Manually creating and disabling accounts as people join and leave a team is the kind of task that gets skipped under deadline pressure, and skipping it is exactly how a former employee ends up with working access three months after their last day.
SCIM 2.0 support at /scim/v2 lets Microsoft Entra ID, or another identity provider that speaks SCIM 2.0, create, update, and disable Forewarden accounts automatically as its own directory changes. A generated token authenticates the provider's requests, and disabling a user through SCIM revokes their active sessions immediately, not on their next natural expiry.
Accounts provisioned this way have no local password and sign in with Microsoft Entra ID, so access is managed in one directory: the one your IT team already maintains. Microsoft Entra ID is the only single sign-on provider Forewarden supports today.