[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-just-in-time-provisioning::en":3,"gloss-cluster-just-in-time-provisioning::en":20,"gloss-next-just-in-time-provisioning::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"just-in-time-provisioning","security","Just-in-Time Provisioning","Just-in-time provisioning creates a user account in an application at the moment that user first signs in through the identity provider, rather than requiring the account to be created ahead of time. The SSO assertion carries the attributes the application needs — email, name, sometimes group or role claims — and the account is built from them on the spot. It is the fastest way to roll an application out to a whole organisation: nobody imports a user list, nobody grants access individually, and people simply arrive. JIT is often confused with SCIM, and the difference is the one that matters for governance. JIT is login-triggered and creation-only: it can make an account and, in richer implementations, update attributes or group membership at each login, but nothing happens when a person leaves, because a departed employee never logs in again. SCIM is directory-driven and bidirectional: the identity provider pushes creates, updates and — critically — deactivations, so disabling someone centrally disables them in the application. A deployment running JIT alone therefore accumulates exactly the problem seat sprawl describes, and the accounts it accumulates are billable and still hold access to whatever they touched. Two practical rules follow. Treat JIT as an onboarding convenience, not as identity lifecycle management, and pair it with SCIM wherever the vendor supports it. Where SCIM is not available, compensate deliberately: schedule an access review, make the identity provider the only login route so that disabling SSO access at least blocks entry, and confirm what happens to data and licences on a deactivated account. Also check whether JIT assigns a default role, since a permissive default quietly grants everyone in the directory more than they need.","JIT provisioning creates a user's account on their first SSO login instead of in advance — convenient to set up, and it never removes anyone.",null,[11,14,17],{"slug":12,"name":13},"saml","SAML (Security Assertion Markup Language)",{"slug":15,"name":16},"scim","SCIM (System for Cross-domain Identity Management)",{"slug":18,"name":19},"sso","Single Sign-On (SSO)",[21,25,29,33,36,39,42,45,48,51,54,57],{"slug":22,"category":5,"name":23,"updated_at":24},"audit-log","Audit Log (Audit Trail)","2026-08-24T02:46:37+00:00",{"slug":26,"category":5,"name":27,"updated_at":28},"blast-radius","Blast Radius","2026-08-24T03:30:02+00:00",{"slug":30,"category":5,"name":31,"updated_at":32},"break-glass-access","Break-Glass Access","2026-08-24T02:46:38+00:00",{"slug":34,"category":5,"name":35,"updated_at":32},"bridge-letter","Bridge Letter",{"slug":37,"category":5,"name":38,"updated_at":32},"business-associate-agreement","Business Associate Agreement (BAA)",{"slug":40,"category":5,"name":41,"updated_at":24},"byok","Bring Your Own Key (BYOK)",{"slug":43,"category":5,"name":44,"updated_at":32},"cve","CVE (Common Vulnerabilities and Exposures)",{"slug":46,"category":5,"name":47,"updated_at":28},"data-classification","Data Classification",{"slug":49,"category":5,"name":50,"updated_at":32},"data-loss-prevention","Data Loss Prevention (DLP)",{"slug":52,"category":5,"name":53,"updated_at":32},"data-minimization","Data Minimization",{"slug":55,"category":5,"name":56,"updated_at":32},"data-poisoning","Data Poisoning",{"slug":58,"category":5,"name":59,"updated_at":32},"data-processing-agreement","Data Processing Agreement (DPA)"]