SCIM Provisioning - Okta
SCIM provisioning allows automated group management via the SCIM protocol. This topic explains the steps to set up SCIM provisioning using Okta.
This topic walks you through SCIM configuration for IdPs on a high level. Refer to the relevant IdP documentation for setting up SCIM provisioning based on your organization's requirements.
Important
Ensure you note the following information before setting up SCIM provisioning for Okta:
- SCIM provisioning supports only SAML-based authentication.
- To use SCIM provisioning, ensure that external authentication is set up and is active. For more information, refer to Okta Authentication (SAML).
- Ensure to create separate groups for app assignments and group push before configuration. Okta does not support using the same group for app assignments and group push.
- App assignments are used to create users in downstream applications. Group push is used to create groups and manage group membership in downstream applications.
-
Ensure the users in app assignments and group push are the same for SCIM provisioning to work as expected in Ivanti Neurons.
Configure & Enable SCIM Provisioning
- In Ivanti Neurons, navigate to Admin > Authentication.
The Authentication page appears. - In the SCIM Provisioning section, click Configure & Enable.
The SCIM Configuration page appears. This displays the credentials and URLs to set up SCIM provisioning.
Do not close the SCIM Configuration page. You can copy these parameters when provisioning the configuration at Step 3 - Create New Provisioning Configuration.
- Log in to Okta Admin Console as an Administrator.
- In the sidebar menu, expand the Applications section and select Applications.
The Applications page appears. - Select the app integration that you created, then navigate to the General tab, click Edit, select SCIM under the App Settings section, and click Save.
The Provisioning tab is now added to the application.
- Go to the Provisioning tab, select Integration and click Edit.
- Under the SCIM Connection section:
- In the Unique Identifier field for users field, enter userName.
- Enable all the options for Supported provisioning actions.
- Select the OAuth 2 option from the Authentication Mode drop-down list.
The OAuth 2 section appears. - Select the Client Credentials option from the Grant Type drop-down list.
- Copy and paste the parameters from Ivanti Neurons from Step 1 - Get SCIM Provisioning Parameters. Refer to the table below to understand the field mapping between Ivanti Neurons and Okta Admin Console.
Okta Admin Console SCIM Configuration Pane (Ivanti Neurons) SCIM connector base URL Neurons SCIM Url Access token endpoint URI Neurons Auth Url Client ID Client ID Client secret Client Secret
- Click Save.
The connection will be tested automatically. - Under the Provisioning tab, select To App and click Edit.
- Enable Create Users, Updated User Attributes, and Deactivate Users options. Then, click Save.
- Navigate to the Assignments tab.
- Select the Assign to Groups option from the Assign drop-down list.
The Assign Groups pane appears. - Click Assign next to the group you want to include, then click Done. Then, click Save and Go Back.
- Click Done.
The selected group(s) are assigned to the application and you can see them under the Assignments tab.
Once a group is assigned, the member of the group are listed under the People section.
- Navigate to the Push Groups tab.
- Select the Find groups by name option from the Push Groups drop-down list.
The Push Groups page appears. - Under the Push groups by name section, search and select a group to assign it as a push group.
- Click Save.
Alternatively, click Save & Add Another to add more push groups.
This action pushes the group, and you can see the push status.
Once the push is complete, the group(s) are created under the SCIM Auto-Provisioning Overview section in Ivanti Neurons on the Authentication module.
To assign roles, follow these steps:
- Navigate to Admin > Access Control.
- Go to the Groups tab.
This displays the list of existing and newly added groups.The Member column shows the number of users who have logged in from a group with roles and the number of directly invited members in that group.
The Population column indicates the number of users in that group, irrespective of whether the group has been assigned a role.Ensure you note the following information to interpret the count under the Member column:
A group has a non-zero member count only if the group is assigned a role and the users in that group have logged in.
When a directly invited member (including an unaccepted invite) is a user of a group with roles, they are included in the member count.
- On the Groups tab, you can do the following:
- To assign role-based access control (RBAC): Select the required group, then click Assign Role to Group option, select roles that you want to assign, and click Save.
- To authenticate member login via Ivanti Neurons: Enable the check-box under the Can Authenticate column for a group, and click Save Authentication Settings.
- To deny access to all members in a group: Disable the check-box under the Can Authenticate column for the group.
Once the changes are saved, the users can log in based on:
Users from groups with the Can Authenticate option enabled can authenticate via Ivanti Neurons and log in.
If the group has roles assigned, the Can Authenticate option will be enabled automatically. Users in groups with roles can log in and access Ivanti Neurons with those roles.
If a group has the Can Authenticate option enabled but no roles assigned, users in that group can log in, but their access to Ivanti Neurons content is restricted.
If the group has the Can Authenticate option disabled, users from that group will not have access to Ivanti Neurons.
After users log in with assigned roles, the Members page will list users from groups with roles.