{"id":6420,"date":"2024-06-04T08:00:48","date_gmt":"2024-06-04T08:00:48","guid":{"rendered":"https:\/\/www.process.st\/help\/docs\/scim-okta\/"},"modified":"2024-06-10T10:28:06","modified_gmt":"2024-06-10T10:28:06","slug":"scim-okta","status":"publish","type":"ht_kb","link":"https:\/\/www.process.st\/help\/docs\/scim-okta\/","title":{"rendered":"SCIM User Provisioning With Okta"},"content":{"rendered":"<p><a href=\"http:\/\/www.simplecloud.info\/\">SCIM<\/a> (System for Cross-Domain Identity Management)\u00a0 allows you to add and remove users that you have set up in <a href=\"https:\/\/www.okta.com\/\">Okta<\/a>.<\/p>\n<p>You can securely set up and manage user roles and their access to <a href=\"https:\/\/www.process.st\/\">Process Street<\/a> with SCIM via Okta.<\/p>\n<p><em><strong>Users: To create an API key you must be an Administrator.<br \/>\n<\/strong><\/em><\/p>\n<p><em><strong>Note:<\/strong> This feature is only available in our <a href=\"https:\/\/www.process.st\/pricing\/\">Enterprise<\/a>\u00a0plan. Please reach out to your\u00a0Customer Success Manager or our <a href=\"mailto:support@mail.process-street.com\">support<\/a> team if you\u2019re interested in accessing it.<\/em><\/p>\n<p>In this article, you&#8217;ll learn to:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.process.st\/help\/docs\/scim-okta\/#1-createconnect-the-process-street-scim-application\">Create and connect the SCIM application<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/help\/docs\/scim-okta\/#enable-provisioning\">Enable provisioning<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/help\/docs\/scim-okta\/#set-up-provisioning\">Set up provisioning<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/help\/docs\/scim-okta\/#set-up-provisioning\">Assign users to Process Street<\/a><\/li>\n<\/ul>\n<h2>Preparations for this configuration<\/h2>\n<p>For this configuration, you must have SCIM enabled in your Process Street account and an SSO integration that supports SCIM provisioning.<\/p>\n<h2>SCIM Configuration for Okta<\/h2>\n<p>To set up SCIM user provisioning with Okta, you first need to configure SCIM for your Okta account and then assign users to Process Street through it.<\/p>\n<h3>Create\/Connect the Process Street SCIM Application<\/h3>\n<p>Log in to your Okta account and from the menu on the left, click <strong>Applications\u00a0<\/strong>and then select <strong>Browse App Integration Catalog.<\/strong><\/p>\n<p>Here, search for the pre-built SCIM app called &#8220;SCIM 2.0 Test App (OAuth Bearer Token)&#8221; to help you get set up faster and click <strong>Add Integration<\/strong>.<\/p>\n<p>In the <strong>General Settings<\/strong> tab, add the <strong>Application label<\/strong> as &#8220;Process Street&#8221;. Ensure to <strong>uncheck<\/strong> the option for <em>Browser plug-in auto-submit <\/em>and then click <strong>Next.<\/strong><\/p>\n<p>In the <strong>Sign-On Options<\/strong> tab, scroll down to Credential Details. Select the <strong>Application username format<\/strong> as &#8220;Okta username&#8221; and click <strong>Done<\/strong>.<\/p>\n<h3>Enable provisioning<\/h3>\n<p>Once you have created the SCIM connection, navigate to the <strong>Provisioning<\/strong> tab to configure the integration.<\/p>\n<p>Click <strong>Configure API Integration\u00a0<\/strong>and check the box to <strong>Enable API Integration<\/strong> then enter your SCIM app credentials as follows.<\/p>\n<p>In the <label id=\"userMgmtSettings.scim_base_url.label\"><strong>SCIM 2.0 Base Url<\/strong>\u00a0<\/label>field, add this URL: <em>https:\/\/public-api.process.st\/api\/scim<\/em><\/p>\n<p>For the <strong>OAuth Bearer Token<\/strong>, enter a <a href=\"https:\/\/www.process.st\/help\/docs\/process-street-api\/\">Process Street API<\/a> key. If you don&#8217;t have an API key, <a href=\"https:\/\/www.process.st\/help\/docs\/process-street-api\/#generating-an-api-key\">generate<\/a> one first.<\/p>\n<h3>Set up provisioning<\/h3>\n<p>In this step, you will map fields from Okta to your SCIM App.<\/p>\n<p>In the Provisioning tab, navigate to the menu on the left, and under <strong>Settings<\/strong>, select <strong>To App<\/strong>. Then, choose from <em>Okta<\/em> to <em>SCIM<\/em>.<\/p>\n<p>In the <strong>Provisioning to App<\/strong> section, click <strong>Edit<\/strong> and check the boxes to <em>enable<\/em> the following:<\/p>\n<ul>\n<li>Create Users<\/li>\n<li>Update User Attributes<\/li>\n<li>Deactivate Users<\/li>\n<\/ul>\n<p>In the <strong>Attribute Mapping<\/strong> section, ensure that these fields are mapped:<\/p>\n<ul>\n<li>Given name (map from Okta profile)<\/li>\n<li>Family name (map from Okta profile)<\/li>\n<li>Email<\/li>\n<li>Primary email type<\/li>\n<li>Display name<\/li>\n<li>User type (this controls the user&#8217;s role)<\/li>\n<\/ul>\n<p>Remove all other fields you don&#8217;t want to map and click <strong>Save<\/strong>.<\/p>\n<p><em><strong>Note<\/strong>: If you don&#8217;t remove the fields you don&#8217;t want to map, SCIM may not work as desired.<\/em><\/p>\n<h3>Assign users to Process Street<\/h3>\n<p>In the <strong>Assignments<\/strong> tab, click <strong>Assign<\/strong>, and select <strong>Assign to people<\/strong>.<\/p>\n<p>Search for the user you want to add and click <strong>Assign <\/strong>next to their name.<\/p>\n<p>You can add the following user types:<\/p>\n<p>Enter their details along with the user type and click Save.<\/p>\n<p>You can add users with the following user types.<\/p>\n<ul>\n<li>Admin<\/li>\n<li>Member<\/li>\n<li>Guest (Internal)<\/li>\n<li>Guest (External)<\/li>\n<\/ul>\n<p>If you don&#8217;t provide a user type, they will be added as a <strong>Guest (Internal)<\/strong> by default.<\/p>\n<p><em><strong>Note:<\/strong> When adding a\u00a0<strong>Guest (Internal)<\/strong> or\u00a0<strong>Guest (External)<\/strong> make sure to include the spaces and parenthesis exactly as you see them here.<\/em><\/p>\n<h2>FAQ<\/h2>\n<p><em><strong>Can I add existing users in Process Street to Okta to manage them?<br \/>\n<\/strong><\/em>Yes, ensure that you have the email address and the exact user name from Process Street and you can add them into Okta.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>SCIM (System for Cross-Domain Identity Management)\u00a0 allows you to add and remove users that you have set up in Okta. You can securely set up and manage user roles and their access to Process Street with SCIM via Okta. Users: To create an API key you must be an Administrator. Note: This feature is only [&hellip;]<\/p>\n","protected":false},"author":11,"template":"","meta":{"_acf_changed":false,"available_plan":"Enterprise","available_product":"Settings","footnotes":""},"ht_kb_category":[239],"ht_kb_tag":[460,461],"class_list":["post-6420","ht_kb","type-ht_kb","status-publish","hentry","ht_kb_category-security","ht_kb_tag-okta","ht_kb_tag-scim"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb\/6420","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb"}],"about":[{"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/types\/ht_kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/users\/11"}],"version-history":[{"count":6,"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb\/6420\/revisions"}],"predecessor-version":[{"id":8002,"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb\/6420\/revisions\/8002"}],"wp:attachment":[{"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/media?parent=6420"}],"wp:term":[{"taxonomy":"ht_kb_category","embeddable":true,"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb_category?post=6420"},{"taxonomy":"ht_kb_tag","embeddable":true,"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb_tag?post=6420"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}