17.3 Configuring Okta for the SCIM streaming service

Before you start your configurations, ensure that you have full administration access in Okta. For more information, see Okta developer website.

To configure Okta for the SCIM streaming service:

  1. Create a SCIM integration in Okta.

    1. Log in to the Okta administration console with your admin credentials.

    2. Create a new SCIM app in Okta.

      1. On the Okta dashboard, from the left panel, select Applications > Applications.

      2. Select Browse App Catalog.

      3. Search for SCIM 2.0, then select SCIM 2.0 (OAuth Bearer Token) from the list of available templates.

      4. Select Add Integration and ensure that the general settings have the required default selections.

      5. Click Next, then Done.

  2. Configure the SCIM API integration.

    1. On the new App page, select the Provisioning tab.

    2. Select Configure API Integration > Enable API Integration.

    3. Type the SCIM Endpoint URL of the OpenText Identity Governance server and the unique identifier that you specified in Step 6. Use the following format:

      https://igurl/api/scim/UNIQUE_IDENTITY_SOURCE_ID.

    4. Generate the bearer token using a script or a tool such as Insomnia, then enter the token in the OAuth Bearer Token field.

  3. Test the SCIM connection.

    1. Click Test API Credentials to verify the connection between Okta and your SCIM server.

    2. Save your provisioning settings.

  4. Enable SCIM provisioning.

    1. On the App page, from the Settings panel, select To App and then Edit.

    2. Enable the necessary provisioning actions from the available common operations to:

      • Create users

      • Update user attributes

      • Deactivate users

      NOTE:The current Okta integration does not support group provisioning.

    3. Save your settings.

  5. Provision users.

    1. From the left panel, select Directory > People.

    2. Add a new user by specifying all the necessary fields.

    3. Click Save.

    4. Select the new user that you added.

    5. Click Assign Applications.

    6. Assign the application that you created in Step 1.

    7. Click Save.

    8. Click Done.

To validate whether users are provisioned, log in to OpenText Identity Governance and navigate to Catalog > Identities.