SCIM Provisioning - PingOne
SCIM provisioning allows automated group management via the SCIM protocol. This topic explains the steps to set up SCIM provisioning using PingOne.
This topic walks you through SCIM configuration for IdPs on a high level. Refer to the relevant IdP documentation for setting up SCIM provisioning based on your organization's requirements.
To use SCIM provisioning, ensure that external authentication is set up and is active. For more information, refer to PingOne Authentication (SAML) and PingOne Authentication (OIDC).
Configure & Enable SCIM Provisioning
- In Ivanti Neurons, navigate to Admin > Authentication.
The Authentication page appears. - In the SCIM Provisioning section, click Configure & Enable.
The SCIM Configuration page appears. This displays the credentials and URLs to set up SCIM provisioning.
Do not close the SCIM Configuration page. You can copy these parameters when provisioning the configuration at Step 4 - Create New Provisioning Configuration.
- Log in to PingOne Console as an Administrator.
- In the sidebar menu, expand Integrations and click Provisioning.
The Provisioning page appears. - Click
(New Connection).
The Create a New Connection pane appears. - Select the Identity Store option to proceed.
- Search and select the SCIM Outbound option and click Next.
- Enter a name and description for the connection, then click Next.
- On the Configure Authentication step, select OAuth 2 Client Credentials from the Authentication Method drop-down list.
- Copy and paste the parameters from Ivanti Neurons from Step 1 - Get SCIM Provisioning Parameters.
Refer to the table below to understand the field mapping between Ivanti Neurons and PingOne Console.PingOne Console SCIM Configuration Pane (Ivanti Neurons) SCIM BASE URL Neurons SCIM Url Oauth Token Request Neurons Auth Url Oauth Client ID Client ID Oauth Client secret Client Secret - Select the Bearer option from the Auth Type Header drop-down list.
- Click Test Connection.
- After a successful connection, click Next.
- (Optional) On the Configure Preference step, select required options.
- Click Save.
Once saved, close this pane to view the newly created connection on the Provisioning page under the Connections tab.
The connection becomes active when a rule is assigned to it. By default, the connection is disabled.
- On the Provisioning page, go to the Rules tab.
- Click
and select New Rule.
Add Rule pane appears. - Set the PingOne as Source option as the Sync Direction.
- Search for or select the connection to add it as a target, then click Continue.
- Enter a name and description for the rule on the Rule Detail step. Then, click Next.
- On the Directory Configuration step.
- Click Add Groups under the Groups section. Select one or more groups from the list, and click Save.
- Click Add Condition under the User Filter section to define provisioning to users based on the condition.
Add attributes to filter users and click Save to add a condition.
After adding groups and conditions, a new rule is created. The pane name is updated based on the rule name.
- To enable the rule, switch the toggle to On in the top-right corner of the pane. Then, close the pane.
- On the Rules tab, enable the new rule you created.
This syncs the user groups, and you can view the sync status.
To assign roles, follow these steps:
- Navigate to Admin > Access Control.
- Go to the Groups tab.
This displays the list of existing and newly added groups.The Member column shows the number of users who have logged in from a group with roles and the number of directly invited members in that group.
The Population column indicates the number of users in that group, irrespective of whether the group has been assigned a role.Ensure you note the following information to interpret the count under the Member column:
A group has a non-zero member count only if the group is assigned a role and the users in that group have logged in.
When a directly invited member (including an unaccepted invite) is a user of a group with roles, they are included in the member count.
- On the Groups tab, you can do the following:
- To assign role-based access control (RBAC): Select the required group, then click Assign Role to Group option, select roles that you want to assign, and click Save.
- To authenticate member login via Ivanti Neurons: Enable the check-box under the Can Authenticate column for a group, and click Save Authentication Settings.
- To deny access to all members in a group: Disable the check-box under the Can Authenticate column for the group.
Once the changes are saved, the users can log in based on:
Users from groups with the Can Authenticate option enabled can authenticate via Ivanti Neurons and log in.
If the group has roles assigned, the Can Authenticate option will be enabled automatically. Users in groups with roles can log in and access Ivanti Neurons with those roles.
If a group has the Can Authenticate option enabled but no roles assigned, users in that group can log in, but their access to Ivanti Neurons content is restricted.
If the group has the Can Authenticate option disabled, users from that group will not have access to Ivanti Neurons.
After users log in with assigned roles, the Members page will list users from groups with roles.