Data as of Aug 25, 2026 · Based on 273 AI responses from ChatGPT Search and Google AI Mode · See how Parse measures this
For organizations using a cloud identity provider, Kisi,
Brivo, and
Verkada are the best-fit physical access control systems. These providers natively support SCIM, enabling automatic synchronization of user identities and group memberships. This automation ensures that as you add or remove employees in your identity software, their door access rights are updated instantly, eliminating manual administrative work.
Brands AI recommends here
Kisi is a strong choice for teams needing seamless SCIM integration. It is specifically designed to work with providers like Okta and Entra ID to automatically update user access rights based on your current directory status.
Brivo provides reliable SCIM-based automation, frequently used for syncing employee directories from Entra ID and Okta. It is an ideal fit if your organization manages security through standardized cloud identity catalogs.
Verkada is well-suited for enterprise security teams requiring full SCIM synchronization. Its cloud-native platform allows you to keep users and groups aligned across regional infrastructure and identity accounts.
Several cloud-managed and hybrid physical door access control systems natively support System for Cross-domain Identity Management (SCIM 2.0) for automated user provisioning and de-provisioning from major cloud identity providers (such as Microsoft Entra ID, Okta, and Google Workspace).
The primary physical access control platforms that support SCIM provisioning include:
Which cloud identity provider (e.g., Microsoft Entra ID, Okta, Google Workspace) are you currently using, and do you need help comparing how these systems handle group-to-door role mapping?
Yes. A growing number of cloud-managed physical access control systems (PACS) support SCIM provisioning from identity providers (IdPs) such as Okta, Microsoft Entra ID (Azure AD), and others. In practice, SCIM is usually used to automate badge/mobile credential account lifecycle (create users, update attributes, remove access), while the PACS handles door controllers, readers, and permissions. SCIM itself is a standard for exchanging user/group lifecycle data between an identity provider and a service provider.
Examples of physical door access systems with SCIM support or documented identity-provider provisioning integrations:
| Access control platform | SCIM / IdP support | Notes |
|---|---|---|
| Kisi | Yes | Supports automatic user and group provisioning from Microsoft Entra ID using SCIM-based provisioning. Supports creating/removing users, syncing attributes, and provisioning groups/group memberships. Microsoft Learn |
| Brivo | Yes (via identity integrations) | Commonly used with enterprise identity providers; verify the exact SCIM capabilities for your IdP and Brivo subscription tier. |
| Openpath / Avigilon Alta | Yes (identity integrations) | Designed around cloud identity workflows; confirm current SCIM availability for your deployment. |
| Envoy access integrations | Partial / ecosystem-based | Often used as an identity-to-building workflow layer rather than a full PACS SCIM endpoint. |
| HID Global cloud products | Varies | HID has multiple platforms; SCIM availability depends on the specific cloud service (for example, credential management vs. PACS). |
| LenelS2 | Varies | Enterprise PACS deployments often integrate through middleware, directories, or custom connectors rather than native SCIM. |
| Genetec | Varies | Typically integrated through enterprise identity connectors and automation workflows; check the specific Security Center/cloud offering. |
A few things to check before selecting one:
SCIM object support
Users only?
Groups?
Group-to-door-access-role mapping?
Deactivation/removal behavior?
Provisioning direction
IdP → PACS is the common model.
Some systems also support importing users back into the IdP.
Access model
The best integrations usually let you map: - IdP group → building/site
IdP group → access level
HR status → badge/mobile credential status
Credential lifecycle
SCIM normally manages the person record and permissions.
It may not issue physical badges, encode cards, or manage every credential workflow automatically.
If you tell me your cloud identity provider (Okta, Entra ID, Google Workspace, Ping, JumpCloud, etc.) and whether you need office doors, data center mantraps, campuses, or coworking-style access, I can narrow this to systems with confirmed native integrations.
Several modern, cloud-managed physical door access control systems (PACS) natively support SCIM (System for Cross-domain Identity Management) provisioning from major cloud identity providers like Microsoft Entra ID (formerly Azure AD), Okta, and Google Workspace.
The leading physical access control platforms that support SCIM-based user provisioning include:
To help narrow down the best fit, could you share:
Yes. If by “support SCIM provisioning” you mean the physical-access platform can receive SCIM 2.0 lifecycle events from your cloud IdP—creating, updating, and deactivating people and/or groups that ultimately control door access—there are several credible options.
| Physical access platform | SCIM | IdPs explicitly documented | Door/access impact |
|---|---|---|---|
| Kisi | Yes, SCIM 2.0 | Microsoft Entra ID, Okta, OneLogin, JumpCloud | Users/groups can be provisioned and mapped to access permissions |
| Brivo Access / Brivo Identity Connector | Yes | Okta, Microsoft Entra ID, Google Workspace | Users, groups and lifecycle changes sync into physical access |
| Verkada Access | Yes | Okta, Microsoft Entra ID | SCIM users/groups can become access groups assigned to doors; credentials can also be SCIM-synced |
| Rhombus Access Control | Yes, SCIM 2.0 | Okta, Microsoft Entra ID | User creation, updates and deactivation; roles/access can follow directory changes |
| Swiftlane | Yes | Okta, Google Workspace, Microsoft Entra ID | Automated provisioning tied to employee lifecycle |
| Avigilon Alta Access | Yes | Okta | SCIM sync for users, groups and roles |
getkisi.com is probably the cleanest example if SCIM is a major requirement. Its current documentation explicitly lists SCIM 2.0 with Entra ID, JumpCloud, Okta and OneLogin, and its platform is specifically cloud physical access control.
brivo.com is another strong enterprise candidate. Brivo's Identity Connector uses a SCIM endpoint to synchronize users and groups from systems such as Entra ID and Okta into Brivo Access, including lifecycle/deactivation changes.
verkada.com goes a step further in tying SCIM to actual physical credentials. Its documentation says SCIM users/groups can be turned into access groups and assigned access levels to doors, and Verkada has documented syncing physical credential information from Okta/Entra SCIM.
rhombus.com currently advertises native SCIM 2.0 lifecycle automation with Okta and Entra ID, including creation, updates and deactivation.
swiftlane.com explicitly supports automated SCIM provisioning with Okta, Google Workspace and Entra ID.
avigilon.com advertises SCIM for Okta, including synchronization of users, groups and roles.
Don't assume that “SCIM supported” means SCIM directly controls door permissions. Vendors implement this differently:
For example, Verkada explicitly documents the group → access-group → door-access chain, while Brivo says its connector synchronizes lifecycle and physical permissions.
If you tell me which cloud IdP you use (Okta, Entra ID, Google Workspace, JumpCloud, OneLogin, etc.) and roughly how many doors/users, I can narrow this to the best 3–5 systems and compare SCIM capabilities, badge provisioning, group-to-door mapping, deprovisioning behavior, existing-hardware compatibility, and pricing model.
verkada.com goes a step further in tying SCIM to actual physical credentials. Its documentation says SCIM users/groups can be turned into access groups and assigned access levels to doors, and Verkada has documented syncing physical credential information from Okta/Entra SCIM.
rhombus.com currently advertises native SCIM 2.0 lifecycle automation with Okta and Entra ID, including creation, updates and deactivation.
Yes. A number of modern cloud-managed physical access control systems (PACS) support SCIM-based lifecycle provisioning from a cloud identity provider (IdP) such as Okta, Microsoft Entra ID, Google Workspace, Ping, JumpCloud, or OneLogin. In practice, SCIM usually provisions users, groups, roles, and lifecycle states into the access-control platform; the PACS then maps those identities to doors, sites, and access policies. SCIM itself is an identity synchronization standard for create/update/deactivate workflows.
Examples of physical door access platforms with SCIM support:
| Access control system | SCIM support / notes |
|---|---|
| Kisi | Supports SCIM 2.0 provisioning and deprovisioning, including user/group synchronization. Documented IdP integrations include Microsoft Entra ID, Okta, OneLogin, and JumpCloud. docs.kisi.io |
| Brivo | Brivo Identity Connector supports SCIM-based user provisioning and lifecycle synchronization between IAM systems and Brivo access control. www.brivo.comenvoy.helpwww.avigilon.comcommunity.ui.com |
| Envoy | Envoy supports SCIM provisioning for directory synchronization (for example, Microsoft Entra ID and SailPoint SCIM integrations). It is often used alongside workplace access workflows rather than as a traditional PACS-only product. envoy.help |
| Avigilon Alta (formerly Openpath) | Cloud-native access control platform; confirm SCIM availability for your specific tenant/package because features vary by product generation and licensing. www.avigilon.com |
| UniFi Identity Enterprise | Community/vendor responses indicate SCIM provisioning support for users and groups; verify current enterprise documentation and supported IdPs before selecting. community.ui.com |
A few enterprise PACS vendors historically rely more on SAML SSO, LDAP/AD sync, proprietary APIs, or HR integrations rather than native SCIM. For those, you may need an identity bridge:
When evaluating a system, check specifically for:
If you tell me your IdP (Okta, Entra ID, Google, Ping, etc.) and whether you need employee door access only or also badges, visitors, contractors, and elevators, I can narrow the list to systems that fit.
Several modern, cloud-managed physical door access control systems (ACS) natively support SCIM 2.0 provisioning from major cloud identity providers like Microsoft Entra ID (Azure AD), Okta, JumpCloud , and OneLogin.
The primary physical access control platforms offering built-in SCIM integration include:
If you can share which specific Cloud Identity Provider (e.g., Microsoft Entra ID, Okta, Google Workspace) and approximate scale/number of doors you're managing, I can outline the exact setup documentation or highlight any licensing prerequisites for these platforms.
Modern cloud-managed physical door access control systems (PACS) increasingly support SCIM (System for Cross-domain Identity Management) provisioning to sync users and groups automatically from major cloud identity providers like Microsoft Entra ID (Azure AD), Okta, and Google Workspace.
The primary physical access control platforms that natively support SCIM provisioning include:
If you can share which specific Cloud Identity Provider you use (e.g., Okta, Microsoft Entra ID, or Google Workspace) and an approximate door count , I can help you verify the licensing tier requirements or setup complexity for these platforms.
Yes. A few modern cloud physical-access platforms support direct SCIM provisioning from a cloud IdP, meaning your IdP can create, update, group, and/or deactivate people in the access-control platform rather than relying on custom API glue.
| Access-control platform | SCIM | IdPs explicitly supported | Physical-access effect |
|---|---|---|---|
| Brivo Access | Yes | Microsoft Entra ID, Okta | Provisions users, groups/roles and lifecycle changes into Brivo; access rights can track directory membership. www.brivo.comlearn.microsoft.comwww.getkisi.com |
| Kisi | Yes | Microsoft Entra ID; also supports SCIM-based identity management generally | Users/groups can be provisioned and deprovisioned, with identity-driven access extending to doors/facilities. learn.microsoft.comwww.getkisi.com |
| Verkada Access | Yes | Okta, Microsoft Entra ID | SCIM users/groups can become access groups, which are then assigned to doors/access levels. help.verkada.com |
| Genea Access Control | Yes | Okta, Microsoft Entra ID, OneLogin | SCIM provisions/deprovisions employees and groups; groups can drive location/door permissions, and SCIM can even populate keycard information. help.getgenea.com |
Brivo, Kisi, Verkada, and Genea are the clearest choices if SCIM itself is a hard requirement. They don't merely offer SSO: their documentation describes SCIM as the mechanism for provisioning identities into the physical-access system. Microsoft Entra, for example, operates as the SCIM client and can create/update/deprovision users and groups in these applications.
Don't confuse SCIM with an access-control integration. For example, Envoy integrates with Brivo, Kisi, Verkada, Genetec, LenelS2 and others, but that is primarily visitor/access-event integration—not necessarily SCIM provisioning from your IdP.
I'd shortlist them based on what you actually want the IdP to control:
If you tell me which cloud IdP you're using (Okta, Entra ID, Google Workspace, OneLogin, JumpCloud, etc.) and whether you need groups/access levels and badge provisioning in addition to user lifecycle, I can narrow this to the best 3–5 systems and compare their SCIM capabilities.
Yes. A few modern physical access-control platforms support SCIM provisioning directly from a cloud IdP, meaning your IdP can create/deactivate users and, in some cases, synchronize groups that determine which doors they can access.
| Physical access system | SCIM | IdPs explicitly documented | Door/access-group provisioning |
|---|---|---|---|
| Verkada Access | ✅ | Okta, Microsoft Entra ID, Google Workspace | Yes — SCIM groups can become access groups and control door access |
| Kisi | ✅ | Okta, Entra ID, JumpCloud, OneLogin | Yes, with some limitations |
| Brivo | ✅ | Via Brivo Identity Connector / IAM integrations | Yes — users and roles can be synchronized into physical access |
| Avigilon Alta (Openpath) | Likely via integrations | Varies by IdP/integration | Worth evaluating, but I'd verify the exact SCIM workflow for your IdP before selecting it |
Verkada is particularly straightforward if you're using Okta or Microsoft Entra ID. Verkada documents SCIM support for both and explicitly lets synchronized SCIM groups become access groups that are assigned to doors/access levels.
Kisi has a dedicated SCIM implementation and currently documents integrations with Okta, Microsoft Entra ID, JumpCloud, and OneLogin. Its documentation says SCIM handles provisioning/deprovisioning of organization members. One caveat: Kisi currently allows only one SCIM provider per organization, and its Okta implementation has a limitation around automatic deletion of users.
Brivo is another strong enterprise option. Brivo's current Identity Connector specifically advertises SCIM-based provisioning, synchronization of users and roles, and using the existing IAM directory as the source of truth for physical door access.
I'd separate these into two capabilities:
SCIM → user lifecycle
IdP creates/deactivates the person's account in the access-control system.
SCIM → access authorization
IdP groups/attributes determine which doors the person gets access to.
The second is considerably more useful for an enterprise deployment. For example:
Entra group: Engineering-NC → Access-control group: Engineering → Doors: Lab + Engineering floor
Verkada explicitly supports this group-to-access-group model.
If you tell me which cloud IdP you use (Okta, Entra ID, Google Workspace, JumpCloud, etc.) and roughly how many doors/users, I can narrow this to the best 3–5 systems and compare SCIM capabilities, hardware, mobile credentials, and likely licensing.
Several modern cloud-managed physical door access control systems (PACS) support native SCIM 2.0 (System for Cross-domain Identity Management) provisioning from major cloud identity providers like Microsoft Entra ID (Azure AD), Okta, and JumpCloud.
Popular physical access control platforms that explicitly support SCIM provisioning include:
Could you tell me which cloud identity provider (e.g., Okta, Microsoft Entra ID, Google Workspace) and approximate scale (number of doors/locations) you are working with? I can provide more tailored configuration recommendations or check specific group-mapping capabilities for your setup.