Connect your company’s identity platform (idP) to our platform so that user accounts can be provisioned and deprovisioned automatically in to the platform. A member of your IT team should manage this process.
Who can use this feature?
- Organization administrators
- Customers with SSO
On this page:
- What is SCIM?
- Configure SCIM provisioning in the platform
- Configure SCIM in the Azure IdP
- Configure SCIM in the Okta IdP
What is SCIM?
System for cross-domain identity management (SCIM) is a standard to manage user identities between your identity provider (IdP) and software products. SCIM automates the user provisioning process, and increases security. Once SCIM is configured, your IdP syncs with the platform every 40 minutes to update user provisioning. Connect the platform to your IdP for secure and automated user provisioning.
Note: A member of your IT team should manage this process.
Before you begin, note the following guidelines:
- Single Sign-on must be configured.
- We currently support SCIM with Okta and Microsoft Azure Entra ID.
- If using Microsoft Azure Entra ID, we do not support user attribute groups.
- You can't remove SCIM-provisioned users using the Level Access Platform dashboard.
Note: Existing accounts, created manually, need to be managed manually, and can't be inherited by the SCIM process.
Configure SCIM provisioning in the platform
To configure SCIM provisioning in the Level Access Platform:
- Navigate to the organizational level.
- Under Manage, select Tools & Integrations, and then SCIM.
- Toggle on Activate SCIM in our platform.
- Select Generate SCIM URL and API.
- Use the SCIM URL and API key to configure SCIM in your IdP.
Once SCIM is configured, an organization administrator must assign the new users to the appropriate user groups. Proceed to assign any new users to their user groups.
Configure SCIM with the Azure IdP
For your convenience, we've provided example procedures that explain how to configure SCIM with the Azure IdP. For most recent documentation updates, refer to the manufacturer's documentation.
Use the following procedures to configure SCIM for Microsoft Azure:
- Add provisioning
- Assign your SCIM app to your user/group
- Enable provisioning, logging, and manual provisioning
- Paused provisioning (Quarantine)
Add provisioning
- Go to Enterprise applications, then All applications, and then select your application.
- Select Provisioning.
- Select Provisioning again, and then fill out the form.
- Ensure that the Provisioning Mode is set to Automatic.
- Fill out the Admin Credentials with this information:
- Your SCIM URL (see Configure SCIM provisioning in the platform).
- SCIM API Key.
- Test the connection and if successful, click Create to save the changes.
Assign your SCIM app to your user/group
- Go to your application and select Assign users and groups.
- Go to Add user/group.
- Assign the application to your user/group.
Enable provisioning, logging, and manual provisioning
After the initial setup is complete, Azure automatically provisions users every 40 minutes. However, you can also manually trigger provisioning, as well as review logs.
- Go back to the Enterprise App, and then Provisioning.
- Select Start provisioning. This starts the 40-min interval automatic provisioning.
- Alternatively, select Provision on demand, to manually provision users/groups.
Paused provisioning (Quarantine)
You might get a message informing you that provisioning has been paused because it’s in quarantine. This occurs when provisioning is stuck on an error. This can happen if you set up Attribute Groups.
Automatic provisioning does not occur in quarantine. However, you can still use manual provisioning.
Configure SCIM for the Okta IdP
For your convenience, we've provided example procedures that explain how to configure SCIM for Okta. For most recent documentation updates, refer to the manufacturer's documentation.
Use the following procedures to configure SCIM for Okta IdP:
- Prerequisites for configuring SCIM for Okta
- Setting up OKTA provisioning
- Assign users to their user groups in the platform
Prerequisites for configuring SCIM for Okta
Meet the following prerequisites:
- SCIM is only supported for SAML integrations.
- Enable SCIM on the organization portal
- Get the organization SCIM URL and SCIM token.
Setting up Okta provisioning
- Log in to the Okta administrator dashboard, and then navigate to Applications.
- Search for the SAML application integrated with the Level Access Platform. Select the SAML application to edit it.
- In the General tab, under App Settings, ensure that Provisioning is set to SCIM.
- Change to the Provisioning tab within the same SAML application.
- Under Settings > Integration, edit the configuration.
- Set the SCIM connector base URL to the Level Access SCIM URL.
- Set the Unique identifier field for users to userName.
- Select all checkboxes, under Supported provisioning actions.
- Set Authentication Mode to HTTP Header.
- Set the HTTP Header > Authorization Token field to the SCIM token, retrieved from the Level Access Platform.
- Select Test Connector Configuration. If you see the Connector configured successfully dialog box, the configuration has been set correctly.
- Select Close.
- Select Save to save the SCIM settings.
- In the Provisioning tab, under Settings > To App > Provisioning to App, select the Edit button, and then the following options:
- Create Users
- Update User Attributes
- Deactivate Users.
- Select Save to save the provisioning settings.
Assign users to their user groups in the platform
- In Okta, go to the Directory, and then People.
- Find a user account and assign it to the Level Access application for which you have enabled SCIM. Select Assign, next to the application name.
- Open the platform and confirm that you can find the user. Go to Organization settings, and then Users, and then Unassigned users. The user name is added to the list.
- Proceed to assign any new users to the appropriate user groups in the platform.
Comments
0 comments
Article is closed for comments.