Set up SSO and SCIM with OneLogin
This topic walks you through the process of setting up SCIM and SSO in OneLogin.
- If you want to set up SSO without configuring SCIM, see Set up SSO with OneLogin.
- If you previously
configured SSO using the
Set up SSO with OneLogin
instructions, you should follow this workflow to configure SSO and SCIM in a
single OneLogin application:
- Complete all of the tasks below to configure SSO and SCIM in a single OneLogin application.
- Reassign users from the existing OneLogin SSO-only application to the new SSO and SCIM application.
- Remove the initial SSO-only tile.
Create a OneLogin application
In this part of the workflow, you are creating the application tile that end-users will click to access the Alida platform.
Copy SSO configuration settings from your app
After you create the application tile, you need to copy SSO configuration values. You will enter these values into Alida's SSO Setup page in the next section.
Configure SSO in your Community
Enter the SSO configuration values from your OneLogin app into Alida's SSO Setup page.
Add and verify a domain
Add the registered domain that your company owns and that you use for employees' email addresses.
Add a user auto-provisioning group
Configure a group for each category of Alida user you want to provision with access to the Alida platform.
You must set up SSO before you can access the User Auto-Provisioning page where you complete this task. The sequence of configuration tasks depends on your Identity Provider (IdP):
-
For Azure and Okta, you must complete the SSO set up for your IdP (Set up SSO with Azure or Set up SSO with Okta) before starting this task.
-
For OneLogin, you will complete this task as part of the procedure for configuring SSO and SCIM in your IdP (Set up SSO and SCIM with OneLogin).
Set the default user auto-provisioning group
Specify the default group to use if an issue occurs mapping your Identity Provider (IdP) groups to Alida auto-provisioning groups.
The group you set as the default group should be the group you have defined with the least privileges. For example, if you are an Analytics customer assigning a group with the Dashboard Viewer role, users provisioned to this group are restricted to viewing dashboards.
This ensures that user provisioning defaults to a non-sensitive group with restricted access if the mapping between an IdP group and the Alida provisioning group fails.
The workflow you need to follow to change a group if a token is active is:
- Delete any active tokens in the User Auto-Provisioning page.
- Select the new group as the default group.
- Generate a new token.
- Update the token in your IdP.
Generate a SCIM authentication token
You can manage the credentials your identity provider (IdP) needs to authenticate with the Alida platform.
You must set up SSO before you can access the User Auto-Provisioning page where you complete this task. The sequence of configuration tasks depends on your IdP:
-
For Azure and Okta, you must complete the SSO set up for your IdP (Set up SSO with Azure or Set up SSO with Okta) before starting this task.
-
For OneLogin, you will complete this task as part of the procedure for configuring SSO and SCIM in your IdP (Set up SSO and SCIM with OneLogin).
You can access the two pieces of information required to authenticate with the AIida SCIM API in the User Auto-Provisioning page:
- Base URL: This is the URL your Identity Provider (IdP) will use to connect to the Alida SCIM API endpoints. You will copy this value and configure it in your IdP as part of the SCIM provisioning setup.
- Tokens: You need to generate a unique token that enables you to securely access the Alida SCIM API and configure it in your IdP.
- You can delete tokens
that you are no longer using. If you delete a token that is in use, your IdP
will no longer be able to access the SCIM API.
To delete a token, click Remove next to the token, and click Delete in the confirmation dialog.
- You can edit the name of
a token, but you cannot modify the expiration date after it has been generated.
To edit the token name, click Edit next to the token, and then enter a unique name in the Token Name text box and click Update.
Configure SCIM in OneLogin
This topic walks you through the process of setting up SCIM in OneLogin.
- Log in to OneLogin.
- Click Administration.
- Select .
- Click the application you want to configure (for example, Alida).
-
Enable provisioning:
-
Enable provisioning and configure provisioning rules:
-
Map attributes:
-
Assign your SCIM app to user roles: