TL;DR: SAML just-in-time provisioning automates first-login account creation through an identity provider, but it only works when the service application supports SAML and when teams understand its limits versus SCIM and just-in-time privilege, according to Zluri. The governance issue is not speed alone, but whether onboarding automation is being mistaken for lifecycle control.
Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “Just In Time Provisioning: Simplifying User Account Creation”.
Key questions
Q: What breaks when teams treat JIT provisioning as full lifecycle management?
A: They create a governance gap between first-login account creation and the rest of the identity lifecycle.
Q: When should organisations prioritise SCIM over JIT provisioning?
A: Prioritise SCIM when the organisation needs pre-provisioning, updates, or deprovisioning in addition to account creation.
Q: What are the best practices for separating JIT provisioning from JIT privilege?
A: Treat them as different controls in policy and operations.
Practitioner guidance
- Separate account creation from lifecycle governance Document JIT provisioning as a first-login account creation control, then map which applications still need SCIM, manual updates, or deprovisioning workflows.
- Inventory SAML support before standardising JIT Check each SaaS application for SAML JIT support and record where JIT cannot operate, so teams do not assume the same onboarding pattern works everywhere.
- Keep JIT provisioning distinct from JIT privilege Write policy language that treats account creation and time-bound access as separate controls, because they answer different governance questions.
Bottom line: SAML JIT provisioning streamlines first-login account creation, but it does not manage updates or removal across the identity lifecycle.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
JIT provisioning is an onboarding mechanism, not a lifecycle control. The article describes a first-login account creation workflow that reduces manual effort, but it does not manage the rest of the identity lifecycle. That distinction matters because lifecycle governance is about creation, change, and removal, not only whether a username can be minted at login. Practitioners should treat JIT as a narrow enablement pattern, not an operating model.
A few things that frame the scale:
- Over 70% of organisations lack automated access risk analysis, user access reviews and provisioning and deprovisioning, according to Pathlock's 2025 Digital Transformation and Access Risk Report.
A question worth separating out:
Q: How can security teams tell whether an application is suitable for SAML JIT provisioning?
A: Start with application support and identity source quality. The application must support SAML JIT provisioning, and the identity data sent by the IdP must be accurate enough to create the right account attributes at first login. If either side is weak, the control will fail or create inconsistent records.
👉 Read our full editorial: Just-in-time provisioning clarifies where SSO account creation fits