Configuring SCIM User Provisioning with Okta
The Clumio service can integrate with Okta for SCIM Provisioning. Please follow the steps below to configure SCIM Provisioning with Okta.
Supported features
- Push users
- Update user attributes
- Deactivate users
- Push Groups
Currently, Clumio does not support the following Okta provisioning features:
-
Remove users
-
Sync password
-
Enhanced group push
Prerequisites
-
Okta account with admin privileges
-
Clumio account with Super Admin Role
- SSO with Okta enabled
Configure SCIM provisioning
In Okta
- Open the Okta Admin console.
- Go to Applications > Clumio
-
In the Sign On tab, ensure that Application username format is set to Email
- Navigate to the Provisioning tab, and click on Configure API Integration.
- Check the Enable API Integration checkbox.
- Get the SCIM Connector Base URL, and the SCIM API token from Clumio (See step 5), and copy it here.
- Under Provisioning to App settings, enable Create Users, Update User Attributes, and Deactivate Users.
- Next, you need to push groups. Navigate to the Push Groups tab.
- Push the groups - including for the user currently logged in to Clumio. There are two ways of selecting groups, either by name or by using a rule.
-
Ensure the current user’s sync was successful in the previous step.
In Clumio
- Log on to Clumio.
- Navigate to Settings > Access Management > Auto user provisioning.
- Click Get Started and type a rule name, select the conditions to apply the rule, give the group a name, select the Super Admin Role, and assign that role to an OU.
- Click Configure SCIM.
- Copy the SCIM base URL, and generate and download the SCIM API token. These will be needed for the IdP side setup. Once done, click Close.
- Now click Provisioning method (optional), and toggle on SCIM Provisioning.
- Ensure that the logged-in user is a part of the group that is assigned the Super Admin role, and groups have been pushed from Okta (see step 14 above).
- Click Enable Auto User Provisioning.
- You can now create additional rules per your requirements by clicking Create Auto User Provisioning Rule.
Once Auto User Provisioning is enabled, all users are evaluated per the rules you created and any changes to users within Okta will automatically reflect within Clumio.
Troubleshooting
Please contact support@clumio.com in case of any clarifications or questions.
Comments
0 comments
Please sign in to leave a comment.