<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Provisioning Error Occurs When Setting Up vSphere vCenter SCIM 2.0

API Access Management
Okta Classic Engine
Okta Identity Engine

Overview

An error can occur when setting up System for Cross-domain Identity Management (SCIM) 2.0 with VMware vSphere because the vCenter SCIM server is behind a network firewall or is unavailable publicly on the internet. To resolve this, a network tunnel between the vCenter Server and Oktav must be created to resolve this issue.

This error is encountered in the Admin Console after navigating to Applications, selecting the VMWare vSphere Application, choosing Configure API Integration, and selecting Enable API Integration:

 

Error 

 

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • vSphere / vCenter
  • System for Cross-domain Identity Management (SCIM) 2.0
  • Network Architecture

Cause

Okta can only connect to SCIM servers that are publicly available. This error may occur if the vCenter SCIM server is behind a network firewall or is unavailable publicly on the internet for Okta to access.

Solution

What steps resolve the vSphere vCenter SCIM 2.0 provisioning error?

 

Review the vCenter integration documentation and implement a network tunnel to make the SCIM server accessible on the public internet so Okta can make API requests to it. Steps to resolve this include but are not limited to:

  • Create a network tunnel between the vCenter Server system and the Okta server if the network is not publicly available.
  • Use the appropriate publicly accessible URL as the Base Uniform Resource Identifier (URI) after creating the network tunnel.
  • Implement a solution within the local network to make the SCIM server accessible on the public internet so Okta can make API requests to it.
  • Contact the service provider or team that operates and supports the SCIM server, the network devices involved, or both, to make the necessary changes to ensure the network tunnel works accurately and securely with the Okta organization.

If Okta cannot reach the server because it is on the local network, a solution must be implemented within that network to make the SCIM server accessible on the public internet so Okta can make API requests to it. For any questions about how to set up a network tunnel, it is best to reach out to the service provider or team that operates and supports the SCIM server, the Network Devices involved, or both to make the necessary changes to ensure this works accurately and securely with the Okta org.

Loading
Okta Support - Okta Provisioning Error Occurs When Setting Up vSphere vCenter SCIM 2.0