Set up SCIM provisioning for Robin with Okta's connector app.
Requirements
- Advanced Authentication + User Management
- Administrator access in Robin
- Active Okta account
Supported provisioning features
Robin supports these provisioning features:
- Push New Users: When you create a user in Okta, Robin creates the user too.
- Push Groups: When you create a group in Okta, Robin creates the group too.
- Push Profile Updates: When you update a user's profile in Okta, Okta pushes the changes to Robin.
- Push User Deactivation: When you deactivate a user in Okta, or turn off the user's access to the application, Robin deactivates the user.
- Import New Users: Okta downloads new users created in Robin and turns them into new AppUser objects, to match them against existing Okta users.
- Import Profile Updates: Okta downloads changes to a user's profile in Robin and applies them to the profile fields stored in Okta.
- Reactivate Users: You can reactivate user accounts in the application.
Robin does not support password syncing.
Prerequisites
Robin requires only one attribute: a primary email. Okta maps these attributes by default. Robin recommends that you keep them:
userNamefamilyNamegivenNameemail
These attributes are Optional:
departmentcostCenterdivisionemployeeNumberlocaletitlemanagerpreferredLanguage
You set optional attributes with 2 different schemas, Core and Enterprise:
- To sync the title, locale, or preferredLanguage attributes, create a new attribute mapping and set the External namespace to urn:ietf:params:scim:schemas:core:2.0:User.
- To sync the department, costCenter, division, employeeNumber, or manager attributes, create a new attribute mapping and set the External namespace to urn:ietf:params:scim:schemas:extension:enterprise:2.0:User .
For example, to sync the department field, add a new attribute and set the mapping as the user profile mapping example shows.
Already have SAML turned on?
If you set up a new instance of Robin in Okta, for example to add SCIM, select ‘email’ when you map the email SAML attribute. This avoids duplicate accounts for users that SAML already added to Robin. In Okta, go to Applications > General > App settings > Email attribute value. This value should be selected by default.
Set up SCIM provisioning in Okta
To set up provisioning, you need administrator permissions and access to the Robin web dashboard. You also need admin access to your Okta org.
Generate a token in Robin and add it to Okta
-
In the web dashboard, go to Manage > Integrations > SCIM Provisioning, then select “Manage”.
-
On the SCIM Integration page, generate a SCIM token. Copy the token.
-
In a new browser tab, open the Okta management portal and add the Robin application.
-
Under Provisioning tab > Settings > API Integration, enter the access token you copied from Robin and select "Save".
-
Select the provisioning features you want to turn on, then select "Save".
You can then assign people to the app.
Sync the department attribute (optional)
To sync the department attribute, create a new attribute mapping for department and set the External namespace to urn:ietf:params:scim:schemas:extension:enterprise:2.0:User . Then set the mapping for the new attribute:
User profile mapping fields
This example shows the user profile mapping fields.
Sync managers
To sync managers into Robin, add the manager attribute to the mappings. Its value must match the manager's externalId in Okta.
For example, User A has the Okta ID 00ux4tqjtye2qJJGq697, and User B has the Okta ID 00ux4u0o95rupibGT851. To make User A the manager of User B, set the manager field of User B to 00ux4tqjtye2qJJGq697. This value is User A’s Okta ID.
Okta must send each user’s Okta ID as externalId. The manager must also be provisioned to Robin through SCIM, in the same Robin organization.
Robin links managers every 3 hours. It links only people whose record changed since the previous evening. If you add the manager later, change any attribute on the employee so your identity provider sends an update. Robin then links the manager.
You find the Okta ID in the URL of the user’s profile in Okta.
Troubleshooting
To turn on the Push Groups feature on existing application instances in Okta, turn on provisioning again:
- Open the Provisioning application tab.
- Select API integration > and select Edit.
- Select the Save button.