This topic walks you through the process of setting up SCIM in Okta.
Before you begin, you must complete the following prerequisite tasks:
- Set up SSO with Okta. You must configure SSO before you start setting up SCIM.
- Define the groups in Alida to map to your Okta groups.
- Set the default user auto-provisioning group. A default group is required before you generate a token.
-
Generate an authentication token. Ensure that you have access to
the following settings from the Alida
User Auto-Provisioning page:
- Base URL: The Alida SCIM API endpoint URL.
- Token: The API token for authentication with the Alida SCIM API endpoints.
Note: You can reuse an Okta group that you already use for SSO app assignment
as the SCIM assignment group. Do not use that same group as a Push Group.
Okta does not support using the same group for both app assignment and as a Push Group.
Important: SCIM synchronization starts in a paused
state. Complete Okta provisioning, assignments, and Push Groups while SCIM sync
remains paused in Alida. Do not click Resume Sync until setup
is complete. If you resume sync before users and groups are correctly configured,
Alida may remove existing user accounts. For more information, see Pause or resume SCIM sync.
After you resume sync, Alida applies provisioning changes from Okta.
To provision a user, complete these actions in Okta in this order:
- Add the user to the assignment group (for example, Alida_All_Users).
- Add the user to their Push Group (for example, Alida_Analyst or Alida_PowerUser).
To deprovision a user, complete these actions in this order:
- Remove the user from their Push Groups.
- Remove the user from the assignment group.
For more information, see Okta documentation on app assignments and Group Push.