Troubleshooting: SCIM Sends the User's Password in Plain Text During Provisioning

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: 22.12+
     
     

    Overview

    When SecureAuth sends a POST request to provision or update a user through a SCIM integration, the user's password appears in plain text in the request payload.

     

    Cause

    This is expected behavior, not a defect. RFC 7643 (System for Cross-domain Identity Management: Core Schema) defines the password attribute as a plain string, and many SCIM providers require it in this form to create or update an account. SecureAuth includes the password in the SCIM payload by default to comply with this specification.

     

    Resolution:

    As of IdP 24.4.7, the SCIM configuration includes an option to exclude the password from the outgoing payload entirely. Enabling it stops SecureAuth from sending the password field during provisioning. Some SCIM providers require a password to create an account, so enabling this option may cause user creation to fail with those providers.

    Contact SecureAuth Support for help applying release update 24.4.7 if your environment does not yet have it.


     

    Special Considerations

    If you are on a release update prior to 24.4.7, you can achieve a similar result by mapping a static, blank value to the SCIM password attribute. This overwrites the outgoing password field with an empty value instead of the user's real password.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.