By Cassa Niedringhaus Posted February 3, 2020
Just-in-Time (JIT) provisioning can play a key role in automating IT workflows and saving time. We’ll examine what it is, how it works, and why it’s a boon to IT admins.
Just-in-Time Provisioning Defined
JIT provisioning is a method of automating user account creation for web applications. It uses the SAML (Security Assertion Markup Language) protocol to pass information from the identity provider to web applications.
So, when a new user tries to log in to an authorized app for the first time, they trigger the flow of information from the identity provider to the app that’s needed to create their account.
How JIT SAML Provisioning Works
In establishing JIT provisioning, admins need to configure a single sign-on (SSO) connection between the identity provider and the target service provider (web application) and ensure they’ve included the user attributes the service provider requires.
Then, when new users try to log in to the application for the first time, they will trigger the creation of their account automatically, rather than requiring an admin or manager to create the account for them during onboarding. The service provider receives the information it needs from the identity provider via SAML assertions.
Admins can implement this workflow through a centralized cloud identity provider or an SSO provider layered on top of their legacy directory. During configuration, they need to make sure the intended service provider also supports JIT provisioning. Examples of popular service providers that support JIT provisioning include Salesforce®, the Atlassian® suite, and Slack®.
Implementing JIT provisioning directly from a cloud identity provider is the most streamlined approach to take because admins can then set application permissions by role or group and revoke application access from one central place.
Benefits of JIT Provisioning
The process of creating application accounts for a handful of employees might be manageable, but scaling organizations should automate workflows rather than doing the process manually ad nauseum.
JIT is a powerful feature to allow IT admins to offload a tedious and perpetual task and save time for other needs (Read more…)