Map an Attribute from Okta to a SAML or SCIM Application
Last Updated:
Overview
Administrators can map an attribute from Okta to an application by configuring the attribute in the Okta user profile and mapping it via a Security Assertion Markup Language (SAML) assertion or the System for Cross-domain Identity Management (SCIM) protocol. Enable provisioning and configure the attribute mappings in the Profile Editor to ensure Okta sends the correct user data to the target application.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- System for Cross-domain Identity Management (SCIM)
- Security Assertion Markup Language (SAML)
- Provisioning
- Mappings
Solution
What are the prerequisites for mapping an attribute?
Verify the Okta environment meets the requirements and enable the update user attributes setting before mapping an attribute.
- Ensure access to an Okta organization and a Security Assertion Markup Language (SAML) or System for Cross-domain Identity Management (SCIM) application integration.
- Activate provisioning for the application and enable the Update user attributes setting.
Create the custom attribute in the Okta user profile.
Create the custom attribute in the Okta user profile by navigating to the Profile Editor and defining the attribute properties.
- Navigate to Directory > Profile Editor in the Okta Admin Console.
- Select the User (default) profile.
- Select Add Attribute.
- Enter the required information, including the Display name, Variable name, and Description.
- Select Save, refresh the page, search for the newly created attribute in the list, and copy the variable name.
NOTE: Apply this to any application profile in the application list. For SCIM-enabled applications without schema discovery, obtain the External name and External namespace of the attribute from the application vendor.
How is an attribute mapped via a SAML assertion?
Map an attribute via a SAML assertion by editing the SAML settings for a custom application or the sign-on settings for an Okta Integration Network application.
Map an attribute on a custom SAML application by editing the attribute statements in the general settings.
- Navigate to the General tab and select Edit in the SAML Settings section.
- Select Next to skip editing the name and icon, and locate the Attribute Statements section.
- Enter the variable name of the attribute from the application side. Contact the application support team for the exact variable name and name format.
- Enter the Okta user profile attribute in the Value field by appending
user.to the attribute variable name. For example, if the variable name of the Okta attribute isemployee, enteruser.employee.
NOTE: Useappuser.<attribute_variable>(for example,appuser.employee) if the attribute is defined on the application profile and assigned a value during user assignment. - Select Next and then select Finish. Okta includes the attribute in the assertion.
Map an attribute on an Okta Integration Network (OIN) application by editing the attribute statements in the sign-on settings.
- Navigate to the Sign On tab.
- Select Edit in the Settings section.
- Expand the Attributes (Optional) dropdown menu.
- Enter the variable name of the attribute from the application side. Contact the application support team for the exact variable name and name format.
- Enter the Okta user profile attribute in the Value field by appending
user.to the attribute variable name. For example, if the variable name of the Okta attribute isemployee, enteruser.employee. - Select Save. Okta includes the attribute in the assertion.
Map an attribute via SCIM without schema discovery.
Map an attribute via SCIM without schema discovery by defining the attribute on the application profile using the external name and namespace provided by the vendor, and then configuring the mapping.
Define the attribute on the application profile by adding a new attribute with the external name and namespace.
- Navigate to Directory > Profile Editor and search for the application name.
- Select the name of the application to edit the attributes.
- Select Add Attribute and complete the required fields, including Display Name, Variable Name, External name, External namespace, and Description.
NOTE: Obtain the External name and External namespace of the attribute from the application vendor. These values are specific to each application and are required to connect to the application attribute. - Select Save.
Map the Okta attribute to the application attribute in the Profile Editor mappings.
- Navigate to Directory > Profile Editor and search for the application name.
- Select Mappings.
- Select the Okta User to Application.
- Enter
user.<Okta_attribute_variable_name>(for example,user.newOktaAttribute) or select it from the dropdown menu to map the Okta attribute. - Select the apply icon and choose Apply mapping on create and update from the dropdown menu to apply the attribute on both creation and updates. By default, the attribute applies only on creation.
- Select Save Mappings and then select Apply updates now. Okta triggers a provisioning job and sends the attribute to the application for all users.
How is an attribute mapped via SCIM with schema discovery?
Map an attribute via SCIM with schema discovery by refreshing the attribute list on the application profile to discover the attribute, and then configuring the mapping.
Define the attribute on the application profile by refreshing the attribute list and selecting the discovered attribute.
- Navigate to Directory > Profile Editor and search for the application name.
- Select the name of the application to edit the attributes.
- Select Add Attribute.
- Select Refresh Attribute List to display the attribute in the list.
- Select the checkbox next to the attribute and select Save.
Map the Okta attribute to the discovered application attribute in the Profile Editor mappings.
- Navigate to Directory > Profile Editor and search for the application name.
- Select Mappings.
- Select Okta User to Application.
- Enter
user.<Okta_attribute_variable_name>(for example,user.newOktaAttribute) or select it from the dropdown menu to map the Okta attribute. - Select the apply icon and choose Apply mapping on create and update from the dropdown menu to apply the attribute on both creation and updates.
- Select Save Mappings and then select Apply updates now. Okta triggers a provisioning job and sends the attribute to the application for all users.
