Okta Provisioning Error Occurs When Setting Up vSphere vCenter SCIM 2.0
Last Updated:
Overview
An error can occur when setting up System for Cross-domain Identity Management (SCIM) 2.0 with VMware vSphere because the vCenter SCIM server is behind a network firewall or is unavailable publicly on the internet. To resolve this, a network tunnel between the vCenter Server and Oktav must be created to resolve this issue.
This error is encountered in the Admin Console after navigating to Applications, selecting the VMWare vSphere Application, choosing Configure API Integration, and selecting Enable API Integration:
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- vSphere / vCenter
- System for Cross-domain Identity Management (SCIM) 2.0
- Network Architecture
Cause
Okta can only connect to SCIM servers that are publicly available. This error may occur if the vCenter SCIM server is behind a network firewall or is unavailable publicly on the internet for Okta to access.
Solution
What steps resolve the vSphere vCenter SCIM 2.0 provisioning error?
Review the vCenter integration documentation and implement a network tunnel to make the SCIM server accessible on the public internet so Okta can make API requests to it. Steps to resolve this include but are not limited to:
- Create a network tunnel between the vCenter Server system and the Okta server if the network is not publicly available.
- Use the appropriate publicly accessible URL as the Base Uniform Resource Identifier (URI) after creating the network tunnel.
- Implement a solution within the local network to make the SCIM server accessible on the public internet so Okta can make API requests to it.
- Contact the service provider or team that operates and supports the SCIM server, the network devices involved, or both, to make the necessary changes to ensure the network tunnel works accurately and securely with the Okta organization.
If Okta cannot reach the server because it is on the local network, a solution must be implemented within that network to make the SCIM server accessible on the public internet so Okta can make API requests to it. For any questions about how to set up a network tunnel, it is best to reach out to the service provider or team that operates and supports the SCIM server, the Network Devices involved, or both to make the necessary changes to ensure this works accurately and securely with the Okta org.
