Protect what matters – even after you're gone. Make a plan for your digital legacy today.
scim
214 TopicsSCIM bridge deployment on Azure with private endpoint
Hi, I have setup a 1Password SCIM bridge successfully on Azure using the json template aca-op-scim-bridge-template.json. What I noticed is that the SCIM bridge is using a public URL which is also used with the Entra integration. Azure SCIM service is using the public URL and a bearer token to make connection to the 1Password SCIM bridge. I do see that it is possible to setup IP restriction on the URL but the problem is that the Azure SCIM service is using changing IP's. My first thought is using a private endpoint on the SCIM bridge and disallow public access. Does anyone already realized that? Is there a template for? Or am I thinking to difficult? Thanks in advance, Wim11Views0likes0CommentsREST APIs for managing users
hi Team, I know that 1Password has CLI and SCIM bridge to manage users but it does not fit my use cases, I want to ask if there is any way I can use REST APIs to manage users. 1Password Version: Not Provided Extension Version: Not Provided OS Version: Not Provided Browser: Not Provided385Views0likes2CommentsSCIM Bridge Fails Sync
We're running SCIM Bridge 2.9.9 and the only method to achieve a successful sync and subsequent provisioning of accounts, is by logging into the Bridge and manually executing the "Sync Groups" function. All 5 status indicators in the Bridge are green and state "Connected", the Google Workspace User Provisioning integration within our 1Password console reflects "Good" health, successful connection with the bridge, and Provisioning users and groups is enabled. There is an error in the SCIM log about a certificate, but it does not prohibit a successful sync with the "Sync Groups" groups function in the bridge. Log snippet with IP Address redacted: "certificate is not allowed for server name xxx.xxx.xxx.xxx: certificate for 'xxx.xxx.xxx.xxx' is not managed","domain":"xxx.xxx.xxx.xxx","time":"2025-04-11T00:05:55Z","message":"certificate manager error while getting certificate" There are no other errors in the log. Please advise86Views0likes2CommentsSCIM - What happens when deactivating Google Workspace provisioning?
As the title says, I’d like to confirm my understanding of what happens when deactivating a Google Workspace provisioning setup in 1Password. Background: we've had a Google Workspace integration provisioning our 1Password user list for several months. It worked well, but our SCIM bridge recently ran into issues. While we work on fixing this, we still need to handle day-to-day user management, so I was thinking of deactivating the Google Workspace provisioning until then. The goal is to regain control over the user list in 1Password, so we can manually add and deactivate users again. What we absolutely don't want is for the large group of users that got provisioned through the Google Workspace SCIM to get deactivated or suspended in bulk. Can you please confirm that deactivating this provisioning will behave as I expect until we manage to reactivate the SCIM bridge? - give me back the manual control over the user list - without disabling hundreds of 1Password user accounts Thank you in advance!Solved38Views0likes1CommentProgramatically enable SCIM groups from Google Workspace?
I'm trying to automate our Google Workspace and 1Password integration via the SCIM bridge, which is currently working really well for syncing users and groups across both platforms. However, the final manual step for us is enabling certain groups in the SCIM bridge. Is there any way to achieve this via a script or external integration such as zapier, make or n8n? Ideally I'd be able to include a script in a new project workflow which simply checks the boxes in the SCIM bridge for the known groups we'd definitely like to sync. Possible?72Views0likes2CommentsCloudFlare's proxying & the 1Password SCIM bridge
I'm looking for a definitive answer to the question "Is there any way to use CloudFlare's proxying with the 1Password SCIM bridge?" From my own personal experience, all signs seem to point to "no", but surely there must be a way? Any time I've enabled proxying on the SCIM bridge's `A` record, it always causes trouble with the `certificate-manager`, which results in certs not being renewed, which then causes the bridge to stop working completely. So is proxying completely out of the question? Or is there some way to get it working? Thanks!54Views0likes2CommentsSCIM Bridge
Why is the SCIM Bridge needed? If I already have to create an Enterprise Application in Azure, then the SCIM bridge really becomes an unnecessary and overcomplicated step. I should not have to register a new domain or spin up a separate VM just to get an integration to pull accounts automatically. As an MSP and reselling this to potentially 50 different organizations, this step becomes very time-consuming and wasteful.194Views2likes4Comments