<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5WR000029wiFS0AYOkta Classic EngineIdentity GovernanceAnswered2026-09-23T17:57:26.000Z2026-09-21T02:19:58.000Z2026-09-23T17:57:26.000Z

Question About Unified On-prem SCIM Agent and OPA/OPS Architecture

Hello,

 

We would like to perform a test using the unified Okta On-prem SCIM Agent referenced in the previous Support response.

 

Currently, under Settings > Downloads in the Okta Admin Console, we can only see the Okta On-prem SCIM Server. There is no separate download option available for the unified Okta On-prem SCIM Agent.

 

Could you please clarify the following?

  1. Where can we download the unified Okta On-prem SCIM Agent?
  2. Does the feature require any Feature Flag, Early Access, or other enablement?
  3. If available, could you please provide the official installation and configuration documentation?

 

Additionally, we would like to confirm the supported architecture for the legacy Okta Provisioning Agent (OPA) + Okta On-prem SCIM Server (OPS) configuration.

 

Is it officially supported for a single OPA instance to communicate with multiple OPS instances?

 

For example:

1 OPA → Multiple OPS

 

Or is a strict 1:1 relationship between OPA and OPS required?

 

If a 1 architecture is supported, please also advise whether there are any limitations, prerequisites, or recommended deployment guidelines for this configuration.

 

Thank you.


  • Paul S. (Okta, Inc.)

    Hello @--.20920 (Customer)​  If that agent is not available I would recommend to Open a case with Support and they will be able to provide access to the agent and provide additional information on the specifics you are looking for.

    Selected as Best
  • Paul S. (Okta, Inc.)

    Hello @--.20920 (Customer)​ Thank you for posting on our Community page!

     

    You are asking where to download the unified Okta On-prem SCIM Agent, whether it requires feature enablement, where to find installation documentation, and whether a single Okta Provisioning Agent can communicate with multiple On-prem SCIM Server instances.

     

    1. For standard On-Premises Provisioning, the architecture relies on two distinct components:

    • Okta Provisioning Agent (OPA): The lightweight polling agent that securely communicates with Okta to retrieve provisioning events.
    • Okta On-Prem SCIM Server (OPS) / SCIM Connector: The middleware that receives the SCIM payload from the OPA and translates it into specific CRUD actions for your downstream target application.

    You only need to download the standard Okta Provisioning Agent, which is available in your Admin Console under Settings > Downloads.

     

    Enablement & Prerequisites

    Standard On-Premises Provisioning does not require a specific Feature Flag or Early Access enablement to download the agent. However, please note that Okta officially supports custom on-premises SCIM integrations only when the implementation is performed by Okta Professional Services, a Certified Partner, or when using the OIG Okta On-Prem Connector.

     

    2. Supported Architecture (OPA to OPS)

    Yes, it is officially supported for a single Okta Provisioning Agent (OPA) to communicate with multiple Okta On-Prem SCIM Servers (OPS). A strict 1:1 relationship is not required.

    Okta's official documentation states: "You can connect your Okta Provisioning Agent to multiple on-premises apps, but you must provide a unique SCIM server URL for each app."

    In a 1 OPA → Multiple OPS architecture, the OPA acts as a router. In the Okta Admin Console (under the Provisioning > Integration tab for each respective application), you simply select the same OPA from the "Connect to these agents" dropdown and specify the unique base URL for that specific app's downstream SCIM connector.

     

    3. Limitations and Deployment Guidelines

    While routing multiple SCIM servers through a single OPA is fully supported, you should keep the following guidelines in mind:

    • Single Point of Failure: If your single OPA goes offline, provisioning and imports will fail for all downstream applications relying on it.
    • High Availability (Recommended): Okta strongly recommends installing at least one additional Okta Provisioning Agent on a separate Windows or Linux server to ensure redundancy. You can assign multiple OPAs to handle traffic for your apps, and Okta will load-balance the requests.
    • Throughput & Resource Bottlenecks: All SCIM traffic (user creations, frequent profile updates, deactivations, and heavy bulk imports) across all connected apps will funnel through the single OPA. If you run massive concurrent imports across multiple apps, the OPA could become a bottleneck.
    • Network Reachability: The server hosting the single OPA must have network line-of-sight and appropriate internal firewall rules to reach the IPs and ports of every internal OPS instance it communicates with.
    • Timeouts: If the OPA does not receive a response from a downstream OPS within a specified timeframe, the API call will time out. With a single OPA handling multiple OPS servers under heavy load, you may need to carefully monitor and adjust the "Timeout for API calls" setting in the Okta UI to prevent task failures.

     

     

    Thank you for reaching out to our Community and have a great day!

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Expand Post
    • --.20920 (Customer)

      Thank you very much for your detailed response.

       

      I apologize if my previous question was not clear enough. I would like to clarify what I am specifically trying to confirm.

       

      In my previous inquiry regarding the Okta Provisioning Agent (OPA) and the Okta On-prem SCIM Server (OPS), I was informed that Okta had introduced a unified Okta On-prem SCIM Agent that replaces both the OPA and OPS, combining their functionality into a single agent.

       

      Based on that information, I wanted to test this unified On-prem SCIM Agent and checked Settings > Downloads in the Okta Admin Console.

       

      However, I can currently see only the Okta Provisioning Agent and On-prem SCIM Server as separate components, and I cannot find any download option specifically named On-prem SCIM Agent.

       

      Therefore, my question is not about how to download and use the existing OPA and OPS separately.

       

      I would specifically like to confirm the following:

      1. Is the unified On-prem SCIM Agent that replaces both OPA and OPS currently available?
      2. If it is available, where can I download it?
      3. Does access to this unified agent require any specific feature enablement, Early Access feature, or assistance from Okta Support?
      4. If it is not currently available for download, could you please clarify whether the previous information stating that the unified On-prem SCIM Agent replaces the legacy OPA + OPS architecture was incorrect or referred to a feature that has not yet been made generally available?

       

      I would greatly appreciate your clarification, as I would like to test the unified agent specifically rather than the existing separate OPA + OPS architecture.

       

      Thank you again for your assistance.

      Expand Post
      • Paul S. (Okta, Inc.)

        Hello @--.20920 (Customer)​  If that agent is not available I would recommend to Open a case with Support and they will be able to provide access to the agent and provide additional information on the specifics you are looking for.

        Selected as Best
      • --.20920 (Customer)

        Thank you for your response. I understand. I appreciate your guidance!

Loading
Question About Unified On-prem SCIM Agent and OPA/OPS Architecture