Manage Accounts with SCIM

BETA FEATURE: This feature is only for Enterprise teams that have Single Sign-On (SSO) set up.

To keep your team’s SurveyMonkey accounts up to date with information stored in an identity provider (IdP), such as Azure Active Directory, you can link the systems using the System for Cross-Domain Identity Management (SCIM). This helps your IT department keep track of accounts across multiple platforms.

If you have data stored in our European Data Center, this feature isn't available. You can see if this applies to you by checking your Account Details.

When you set up account provisioning with SCIM, some account management features will change. Here’s what will be mapped, synced, and managed for each user in the identity provider:

  • When someone joins or leaves your organization
  • Username
  • First and last name
  • Email address
  • Divisions (if set up for your team)

Primary Admins and Admins will continue to manage the following within SurveyMonkey:

  • Account reassignment
  • Role and seat assignments
  • Accounts that don’t have SSO enabled
  • Account deletion

TIP! Deactivate the team user through your IdP before reassigning or deleting the account.

Only the Primary Admin can set up SCIM provisioning for your organization. To make sure SCIM is a good fit for your IdP, the Primary Admin should check in with their SurveyMonkey Customer Success Manager (CSM) and their organization’s IT department.

Once the team is aligned, the Primary Admin can:

  1. Go to Settings.
  2. Select User provisioning with SCIM.
  3. Copy the SCIM endpoint link and provide it to your IT partner.
  4. Select Generate token. Treat this unique token as you would your Primary Admin password and only give it to your IT partner.

Your organization’s IT partner will use the SCIM endpoint link and access token during set up of the IdP. They will also need to adjust the default mapping for your team’s needs.

  • Mapping guide

To confirm SCIM is set up properly, your IT partner should manually provision one user through the IdP. Then, have the Primary Admin check the SurveyMonkey Activity page to see if the provision is there.

If you need to disconnect Surveymonkey from your IdP so the systems no longer sync, the Primary Admin can revoke SCIM provisioning. As long as SSO is enabled, there will be no impact to users who have already been synced.

To revoke the SCIM provisioning:

  1. Go to Settings.
  2. Select User provisioning with SCIM.
  3. Next to the access token, select Revoke.

Below are common questions with potential solutions to help resolve them.

  • Why can’t I delete an account?
  • Why are former employees shown as active in my Enterprise team?
  • Do deactivated accounts take up a license (seat)?
  • Why do I see so many invited users on the Manage Users page? 
  • Why are members of my Enterprise team still showing as an invited user?