Set up SCIM with Okta
Automate the provisioning and deprovisioning of Okta users
読み終わるまでの所要時間 3 分最終更新 15日前
This page covers the Okta side of setting up SCIM provisioning. It supplements Provision users with SCIM, which describes the Unity side and applies to every identity provider (IdP).
Prerequisites
Meet the prerequisites of the general guide, and these Okta prerequisites:
- An Okta instance exists and manages your users.
- An existing Okta application is set up with Unity SSO.
1. Configure a service account
Okta authenticates to Unity's SCIM service as a Unity service account, using basic authentication with an API key. Create the account and its key as described in Configure a service account for SCIM, and keep the key ID and secret key: you need both in step 3.
2. Fetch the SCIM connector URL for your organization
-
On a new tab, go to the Unity Dashboard.
-
Switch to the organization for which you want to set up SCIM.
-
Go to Administration > SSO & SCIM.
-
On the SCIM Provisioning & Enforcement tab, under step 2, Configure SCIM Provisioning, copy the SCIM base connector URL from the Unity card.Your IdP service requires this information.
3. In Okta, turn on SCIM for the provisioning of users
-
On a new tab, sign in to your Okta admin instance with an admin account.
-
Go to Applications > Applications, and then select your Unity SSO application.
-
On the General tab, select Edit next to App Settings.
-
Turn on SCIM for the provisioning of users, and then select Save.
-
In Okta, go to the Provisioning tab.
-
In the Integration section, select Edit next to SCIM Connection.
-
Set this configuration:
- SCIM base connector URL: the value that you have copied from Unity Cloud
- Unique identifier field for users:
email - Supported provisioning actions: and
Push New UsersPush Profile Updates - Authentication mode:
Basic Auth - Username: the ID of the key that you have generated for the service account
- Password: the secret of the key that you have generated for the service account
-
Select Save.Okta verifies the setup and informs you of any errors.
4. In Okta, set up the provisioning of users through SCIM
-
In Okta, go to the To App settings page.
-
On the Provisioning tab, select Edit next to Provisioning to App.
-
Turn on these provisioning actions:
- Create users
- Update user attributes
- Deactivate users
-
Select Save.
-
In the Attribute Mappings section, set these attributes:
-
userName: set this attribute to the user's primary email address that is set in the sign-on settings.
-
givenName: enter. You'll include this variable in the displayName expression.
user.firstName -
familyName: enter. You'll include this variable in the displayName expression.
user.lastName -
displayName: enter this expression:
user.firstName \+ " " \+ user.lastNameOkta doesn't accept smart quotes. If you can't paste the quotes, enter them. -
locale: enter.
user.locale -
email: enter. The userName attribute uses the email attribute.
user.email
Set all these attributes so that Okta applies their mapping for the creation or update of a user profile in Unity. -
-
On the Sign On tab, in the Credentials Details section, verify that Update application username on is set to.
Create and update
5. Select Okta users for automated provisioning
-
In Okta, go to the Assignments tab.
-
Select the users for whom you want to automate provisioning in Unity. Select the users individually or select a user group.When you select users, Unity automatically provisions them.
-
To provision these users, select Provision User.
-
To provision these non-provisioned users, use one of these methods:
- To provision users individually, select Provision User next to a user.
- To provision all non-provisioned users, select Sync All in the Okta notification.
6. Enable SCIM in Unity
Your Okta configuration is now complete, but no syncing happens until you enable SCIM in Unity. Go back to the general guide and enable SCIM.