Configure an On-Premises SCIM Provisioning Application in Okta and Test the User Import Function
Last Updated:
Overview
Configuring an on-premises System for Cross-domain Identity Management (SCIM) provisioning application in Okta requires creating a custom integration and connecting it to the Okta Provisioning Agent. After completing the prerequisites with Okta Professional Services, administrators can configure the application in the Okta Admin Console and test the user import function.
NOTE: If this is a brand-new On-Premise SCIM Provisioning integration, please contact the Okta Professional Service team for assistance, as it is outside the scope of Okta Support. Any questions related to creating a custom OnPremise SCIM connector for the OnPremise SCIM integration or installing and configuring the Okta Provisioning Agent are outside the scope of support and must be assisted by the Okta Professional Service team.
For full details, please read the On-Premises provisioning Okta documentation.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- On-Premises System for Cross-domain Identity Management (SCIM) Provisioning
- Okta Integration Network (OIN)
Solution
How is the custom on-premises SCIM provisioning application created?
Prerequisites:
- Worked with the Okta Professional Service team to complete the required steps below, including:
Create a custom SAML or Secure Web Authentication (SWA) application in the Okta Admin Console to support on-premises SCIM provisioning.
- In the Okta Admin Console, navigate to Applications > Applications.
- Select Create App Integration.
- Select SAML 2.0 or SWA - Secure Web Authentication as the sign-in method.
NOTE: Do not select OIDC - OpenID Connect, as it does not support provisioning.
Review the following image for the SAML 2.0 option in the Create a new app integration window.
- Complete the application creation wizard.
- Navigate to the General tab of the newly created application.
- Select Edit in the App Settings section.
- Select On Premises SCIM Provisioning under Provisioning.
- Select Save.
Review the following image for the On Premises SCIM Provisioning option on the General tab.
Configure the SCIM connector to enable user imports.
Enter the SCIM connector base URL and select the Okta Provisioning Agent in the application provisioning settings to establish the connection.
- Select the Provisioning tab.
- Select Integration under Settings.
- Select Configure SCIM Connector.
Review the following image for the Configure SCIM Connector button on the Provisioning tab.
- Enter the required SCIM connector base URL.
- Select the Okta Provisioning Agent from the Connect to these agents dropdown menu.
NOTE: Obtain the required configuration information from the SCIM connector development team or the Okta Professional Services consultant.
- Select Save.
Review the following image for the SCIM connector configuration fields.
How is the user import function tested?
Initiate a manual import in the Okta Admin Console to test the user import function with the dedicated on-premises SCIM server source.
- Select the Import tab in the custom application.
- Select Import Now to start a new import job.
For any additional assistance for a brand-new On-Premise SCIM Provisioning integration setup, please contact the Okta Account Representative, who may help to arrange an Okta Professional Service engagement session, and our Okta Professional Service team can further address any outstanding questions for a custom On-Premise SCIM Provisioning app implementation inquiry.
