- 15 Mar 2024
- 1 Minute to read
- Print
- DarkLight
- PDF
Okta
- Updated on 15 Mar 2024
- 1 Minute to read
- Print
- DarkLight
- PDF
Okta Provisioning
With Provisioning you can automate common administrative tasks. By enabling the System for Cross-domain Identity Management (SCIM) you can connect Visma with Okta, so you can:
Create users and groups
Grant and revoke access to groups
Edit attributes of users and groups
Suspend deprovisioned users
Prerequisites
Okta admin account
Before you configure provisioning for Visma, you need to have configured a SAML App integration. A step by step guide to configure Okta as a SAML identity provider within Visma can be found here
Make sure the ‘Application username format’ is defined as ‘Email’.
Configuration Steps
Once you have the SAML integration ready in Okta, follow the steps below:
Under your SAML application go to the “ General” tab and select SCIM for Provisioning under the App Settings.
Click Save. Provisioning tab will be displayed.
Click on the Provisioning tab, then click Edit.
While on SCIM Connection, go to the Provisioning page within Visma Authentication Settings and turn on SCIM 2.0 Provisioning.
Copy the SCIM Endpoint and paste it into the SCIM connector base URL field in Okta.
Fill in the Unique identifier field for users field with value userName.
For Supported provisioning actions select your desired configuration.
Visma supports Push New Users, Push Profile Updates and Push Groups.
While on SCIM Connection go to Visma Authentication Settings Provisioning tab and based on your Okta provisioning actions, choose the desired Visma actions and triggers.
In Okta for Authentication Mode select from the dropdown list HTTP Header.
In Visma Authentication Settings, Provisioning tab click on Generate SCIM token.
Copy the SCIM token.
Click Close.
While in Okta, paste the SCIM token from Visma into the Authorization field.
Click Save to enable the SCIM provisioning.
Select from the left menu: To app.
Click Edit.
Choose your desired configuration by clicking enable.
Visma supports ‘Create Users’, ‘Update User Attributes’ and ‘Deactivate Users’
Click Save.
Assign People to Provisioning
You need to assign the people that need to be provisioned to the Visma app. You have the choice to assign individual people records or to assign people based on their group membership.
Click Assign.
Click Assign to People.
Select the user you need and click Assign.
Click Done.
Only groups that are selected under Push Groups will be sent to Visma.
Provision Groups
Make sure the right Okta Groups are pushed now to Visma. Go to the Push Groups tab, search for the Groups you want to push to Visma and add the Groups to the list.
Click Push Groups.
Click Find groups by name.
Search and select the desired group.
Click Save.
Push Status should be Active.