Identity integration & provisioning

Connect identity once.
Control it throughout the lifecycle.

MAITS designs federation, single sign-on, provisioning and API integration across SaaS, custom, cloud and legacy applications.

Sign-in is only half the integration

Federation answers who is authenticating. Provisioning determines whether an account exists, which attributes arrive and when access is removed.

Integration patterns

Use the right boundary for authentication, authorisation and lifecycle.

IDENTITY PROVIDERMicrosoft Entra / trusted IdP
OIDCOAuth 2.0SAMLSCIMGraphREST
RELYING SYSTEMSSaaS · custom apps · APIs · legacy platforms

Capability

Integration that remains operable after go-live.

FEDERATION

OIDC and SAML SSO

Design trust, claims, signing, sessions and application registration for modern and established federation patterns.

AUTHORISATION

OAuth 2.0 and API access

Define resource, scope, consent, client and workload identity patterns without confusing tokens with business permission.

PROVISIONING

SCIM lifecycle

Create, update and remove application identities through standards-based provisioning and controlled attribute mapping.

MICROSOFT

Microsoft Graph integration

Use supported Graph interfaces for identity automation where Graph is the correct platform boundary.

LEGACY

Bridges and gateways

Connect systems that rely on LDAP, SQL, custom APIs or older authentication without disguising their constraints.

ASSURANCE

Testing and monitoring

Validate matching, duplicate handling, claims, deprovisioning, retries, quarantine, logs and support ownership.

Provisioning architecture

Carry lifecycle intent all the way to the application.

The interface can be SCIM, Microsoft Graph, a REST API or a carefully governed custom boundary. The control outcome remains consistent.

Application provisioning lifecycleAn authoritative source passes identity through an identity platform and transformation boundary to a SCIM, Microsoft Graph or API connector, then to an application.SOURCEAuthoritative eventHR · directory · partnerCONTROLIdentity platformScope · policy · stateBOUNDARYTransform & mapMatch · reconcile · retryCONNECTSCIM · Graph · APIStandard or customTARGETApplicationAccount · group · roleCREATEUPDATEGROUPDEACTIVATE
Provisioning is an operating lifecycle: identity matching, attribute ownership, failure handling and deactivation matter as much as the connector.

SCIM engineering

A standard endpoint still needs production discipline.

LIFECYCLE

Users & groups

Create, update, deactivate, lookup and manage supported group membership operations with clear lifecycle states.

SCHEMA

Attributes & extensions

Map standard attributes and explicitly agreed schema extensions without presenting proprietary behaviour as SCIM.

BEHAVIOUR

Filtering & pagination

Implement supported lookup, paging, matching, idempotency and error responses that behave predictably at scale.

ASSURANCE

Security & reconciliation

Protect the endpoint, reconcile drift, handle retries and quarantine, and make failed deprovisioning visible.

Custom connectors

Build a clean identity boundary around a non-standard system.

Not every application offers native SCIM, modern federation or a usable lifecycle API. MAITS can design custom SCIM façades, REST or Graph integrations, provisioning middleware, event-driven interfaces and transitional file or database patterns where appropriate.

The design makes transformation, reconciliation, retry, security and support ownership explicit. It does not pretend that a legacy platform has become standards-compliant merely because a connector sits in front of it.

Custom SCIMREST APIGraphEventsECMA connectorsReconciliation

Federation & authorisation

Authenticate with modern protocols. Authorise with a real access model.

OIDC

Modern web sign-in

Design issuer trust, clients, redirect and logout behaviour, claims, sessions and token validation for applications.

OAUTH 2.0

Delegated and application access

Define clients, resources, scopes, consent and workload patterns without treating an access token as a complete business permission model.

SAML

Established enterprise federation

Configure metadata, identifiers, claims, signing, encryption and session behaviour for applications that remain on SAML.

LEGACY

Federation modernisation

Plan the controlled retirement of WS-Federation or older identity providers where application capability and risk justify change.

End-to-end flow

Source → provision → authenticate → authorise → remove.

A reliable integration starts with an authoritative identity and finishes with timely access removal. Attribute ownership, matching, conflict resolution and failure handling must be explicit between those points.

MAITS helps teams select patterns based on protocol support, security, portability and operating effort — not on a preference for custom code.

Microsoft application provisioning overview

Delivery method

Make every interface and owner visible.

01

Discover

Map identity sources, repositories, protocols, attributes, accounts and business owners.

02

Design

Define trust, data, lifecycle, authorisation, failure and support boundaries.

03

Connect

Configure or build the smallest maintainable integration that fits the target.

04

Prove

Test normal, duplicate, delayed, failed and deprovisioning scenarios with evidence.

Start a conversation

Bring order to the identity hand-offs.

MAITS can help with a single difficult application, a custom connector or a repeatable enterprise federation and provisioning pattern.