SCIM groups map to Auth0 roles; self-service provisioning added
We’re pleased to announce that support for Groups within Auth0’s [Inbound SCIM](https://auth0.com/docs/authenticate/protocols/scim/configure-inbound-scim) for Enterprise Connections capability is now Generally Available (GA)! This release closes the loop between identity provisioning and access control by allowing you to natively map synced groups to Auth0 roles at two levels: globally at the tenant level, or scoped specifically to an organization based on the user’s login context. Additionally, developers can now accelerate B2B onboarding by empowering their enterprise customers to self-configure SCIM provisioning for groups directly. __What’s new in GA:__ Building on our [Early Access](https://auth0.com/changelog#6osxJFJUB5gsCePUpSanRQ) capabilities, this release introduces the following enhancements to deliver out-of-the-box B2B delegated administration: - __Associate tenant-level RBAC roles with Enterprise Groups__: For global access, you can assign Auth0 tenant-level roles directly to SCIM-provisioned groups. Any member of the synced group will automatically inherit these roles globally. - __Assign Organization scoped roles to Enterprise Groups__: You can now assign organization scoped roles to SCIM-provisioned groups. In tandem with [Auto-Membership](https://auth0.com/docs/manage-users/organizations/configure-organizations/grant-just-in-time-membership), your customers' users will automatically inherit workspace-scoped permissions the moment they log in. - __Self-Service Enterprise Configuration__: Empower your enterprise customers (or their IdP administrators) to configure SCIM provisioning for users and groups on their own through the [Self-Service](https://auth0.com/docs/authenticate/enterprise-connections/self-service-enterprise-configuration/manage-self-service-enterprise-config) flow, accelerating B2B onboarding and removing your support team from the loop. __How to get started:__ This feature will be rolled out to all public cloud environments over the next few days and to private cloud environments as per their release pipeline. SCIM Groups is available for all tenants whose Auth0 plan includes Enterprise Connections. To enable it, navigate to the Auth0 Dashboard, go to __Authentication > Enterprise__, select your SAML, OpenID Connect, Okta Workforce, or Microsoft Entra ID connection, and toggle __Sync user profiles using SCIM__ to __On__ under the __Provisioning__ tab. __Learn more:__ - [Configure Inbound SCIM](https://auth0.com/docs/authenticate/protocols/scim/configure-inbound-scim) - [Assign Roles to Enterprise Groups](https://auth0.com/docs/manage-users/access-control/configure-core-rbac/rbac-users/assign-roles-to-groups) - [Self-Service Enterprise Configuration](https://auth0.com/docs/authenticate/enterprise-connections/self-service-enterprise-configuration#self-service-enterprise-configuration-workflow) - [Group Events using the Eventing Platform](https://auth0.com/docs/events)
Fetched June 6, 2026



