기술 자료

Set up SCIM with JumpCloud

Automate the provisioning and deprovisioning of JumpCloud users
읽는 시간 2분최근 업데이트: 14일 전

This page covers the JumpCloud side of setting up SCIM provisioning. It supplements Provision users with SCIM, which describes the Unity side and applies to every identity provider (IdP).

Prerequisites

Meet the prerequisites of the general guide, and these JumpCloud prerequisites:
  • A JumpCloud instance exists and manages your users.
  • An existing JumpCloud SSO application is set up with Unity SSO.

1. Configure a service account

JumpCloud authenticates to Unity's SCIM service as a Unity service account, using an API key. Create the account and its key as described in Configure a service account for SCIM, and keep the authorization header value: you need it in step 3.

2. Fetch the SCIM connector URL for your organization

  1. On a new tab, go to the Unity Dashboard.
  2. Switch to the organization for which you want to set up SCIM.
  3. Go to Administration > SSO & SCIM.
  4. On the SCIM Provisioning & Enforcement tab, under step 2, Configure SCIM Provisioning, copy the SCIM base connector URL from the Unity card.
    Your IdP service requires this information.

3. In JumpCloud, turn on SCIM for the provisioning of users

  1. On a new tab, sign in to your JumpCloud admin instance with an admin account.
  2. Go to Access > SSO Applications, and then select your Unity SSO application.
  3. On the Identity Management tab, set this configuration:
    • API type:
      SCIM API
      .
    • SCIM version:
      SCIM 2.0
      .
    • Authentication method:
      API Key
      .
    • Base URL: the SCIM base connector URL that you have copied from Unity Cloud.
    • Authorization header name:
      Authorization
      .
    • Authorization header value: the value of the authorization header that you have copied from Unity Cloud.
      Don't paste the full authorization header, but only the part of the authorization header after the string
      Authorization:
      . The value has this format:
      Basic <Base64(key ID:secret key)>
      .
    • Test user email: an email address that isn't currently in Unity or in JumpCloud.
      This email must be within a domain that you have validated for SSO with Unity.
  4. Select Test Connection.
  5. Don't enable group management.
  6. After your connection has been tested, select Activate.

4. Select JumpCloud users for automated provisioning

  1. In JumpCloud, on the User Groups tab, select the user groups for whom you want to automate provisioning in Unity.
    Unity automatically provisions the users in the group.
  2. Select Save.

5. Enable SCIM in Unity

Your JumpCloud configuration is now complete, but no syncing happens until you enable SCIM in Unity. Go back to the general guide and enable SCIM.

Next steps