Correct Answer: SAML-based SSO for authentication with verified trust relationships, SCIM-based automated provisioning and deprovisioning tied to identity provider group membership, credential protection for the SCIM integration, and periodic review of both trust relationships and provisioning rules
Explanation: Combining SAML SSO, SCIM automated lifecycle management, protected scoped credentials, and periodic review together provides a secure, efficient identity experience, unlike fully manual processes, SSO without provisioning automation, provisioning without SSO, unrestricted SCIM credentials, or never reviewing configurations after deployment.
Correct Answer: SAML-based SSO for authentication with verified trust relationships, SCIM-based automated provisioning and deprovisioning tied to identity provider group membership, credential protection for the SCIM integration, and periodic review of both trust relationships and provisioning rules
Explanation: Combining SAML SSO, SCIM automated lifecycle management, protected scoped credentials, and periodic review together provides a secure, efficient identity experience, unlike fully manual processes, SSO without provisioning automation, provisioning without SSO, unrestricted SCIM credentials, or never reviewing configurations after deployment.