<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Configure Salesforce REST API Provisioning Integration in Okta

Okta Integration Network
Okta Classic Engine
Okta Identity Engine

Overview

Administrators can integrate Salesforce provisioning in Okta by creating an external client application in Salesforce and configuring the API integration in the Okta Admin Console. This configuration utilizes the Salesforce REST API to manage user data and synchronize accounts between Okta and Salesforce.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Salesforce OAuth Provisioning Integration
  • Okta Integration Network (OIN)

Solution

Review the linked video for a demonstration of this solution. 



 

How is the Salesforce external client application configured?

Configure the Salesforce external client application by creating an administrator account, setting the OAuth parameters, and generating the consumer key and secret.

  1. Create an administrator account in Salesforce. This account generates the OAuth Consumer Key and Consumer Secret used in the Salesforce REST integration. Contact the Salesforce Support Team for further assistance if necessary.
  2. Create a new external client application or migrate an existing connected application by following the instructions in Create an External Client App or Migrate Connected App to External Client App.
  3. Configure the external client application OAuth settings in the App settings section using the following values:
  4. Enable the following options in the Security section:
    • Require secret for Web Server Flow
    • Require secret for Refresh Token Flow
    • Require Proof Key for Code Exchange (PKCE) extension for Supported Authorization Flows
    • Enable Refresh Token Rotation
  5. Configure the following values in the Policies tab:
    • Permitted Users: All users can self-authorize
    • Refresh Token Policy: Refresh token is valid until revoked
  6. Navigate to the Settings tab.
  7. Select Consumer Key and Secret under OAuth SettingsApp Settings.
  8. Copy the Consumer Key and Consumer Secret values for use during the Okta configuration.

 

NOTE: Salesforce requires up to 10 minutes to replicate these changes. Wait 10 minutes before proceeding to the Okta configuration.

How is the Salesforce REST integration authenticated in Okta?

Authenticate the Salesforce REST integration in Okta by entering the generated consumer key and secret into the application provisioning settings and granting access.

  1. Navigate to Applications > Applications in the Okta Admin Console.
  2. Select the Salesforce application.
  3. Select the Provisioning tab and choose Integration in the Settings list.
  4. Enter the configuration values:
    • OAuth Consumer Key: Paste the Salesforce consumer key.
    • OAuth Consumer Secret: Paste the Salesforce consumer secret.
    • PKCE Enabled: Select this checkbox.
  5. Select Authenticate with Salesforce.com.
  6. Enter the administrator username and password used to create the external client application in the new Salesforce window.
  7. Select Allow to grant Okta access to the external client application.
  8. Select Save to save the OAuth configuration.

 

NOTE: If the Salesforce Enable API Integration section requests a username and password, contact Okta Support. The newer version operates on Salesforce REST Version 45 and addresses the Salesforce Platform API Versions 21.0 through 30.0 Retirement.

Related References

Loading
Configure Salesforce REST API Provisioning Integration in Okta | Okta Support