SCIM provisioning using OneLogin's connector app

Requires

  • Admin access in Robin
  • Robin's Advanced Authentication + User Management
  • OneLogin admin access

Set up SCIM provisioning for Robin with OneLogin's connector app.

Supported provisioning features

Robin supports these provisioning features:

  • Push New Users: When you create a user in OneLogin, Robin creates the user too.
  • Push Groups: When you create a group in OneLogin, Robin creates the group too.
  • Push profile updates: OneLogin pushes changes to a user's profile to Robin.
  • Push User Suspension: When you suspend a user in OneLogin, or turn off the user's access to the application, Robin deactivates the user.
  • Reactivate Users: You can reactivate user accounts in the application.

Prerequisites

Robin requires only one attribute: a primary email. The Robin connector in OneLogin maps these attributes:

Screen_Shot_2022-03-23_at_12.16.15_PM.png

  • Department
  • Email
  • FirstName
  • Groups: make sure the "Include in User provisioning" box is selected
  • LastName
  • NameID
  • SCIM Username
  • Title
  • DisplayName

To set up provisioning, you need administrator permissions and access to the Robin web dashboard. You also need OneLogin admin access to install apps in OneLogin.

Generate a token in Robin and add it to OneLogin

  1. In the web dashboard, go to Manage > Integrations > SCIM Provisioning > Manage.

    SCIM_connection.png

  2. On the SCIM integration page, generate a SCIM token. Copy the token.

    2022-03-24_09-17-41.png

  3. In a new browser tab, open the OneLogin management portal and add the Robin application.

    Screen_Shot_2022-03-23_at_10.10.44_AM.png

  4. On the Configuration tab, enter https://api.robinpowered.com/v1.0/scim-2 in SCIM Base URL. Paste the token you copied from Robin in SCIM Bearer Token, then select Enable.

    The SCIM Base URL and SCIM Bearer Token fields in the OneLogin Robin app

  5. Select the provisioning features you want to turn on. They look like this image.

    Screen_Shot_2022-03-23_at_12.16.33_PM.png

  6. Select Save.

You can then assign people to the app.

Add optional fields

To add optional fields, create a new custom field under Users → Custom User Fields.

5cc1b741-f514-4575-a189-59a37c60fe41.png

These custom fields are available in Robin:

  • department
  • costCenter
  • division
  • employeeNumber
  • locale
  • title
  • manager
  • preferredLanguage

Sync managers

To sync managers into Robin, the manager attribute should match the manager's OneLoginID in OneLogin.

For example, User A has the OneLoginID 255174535, and User B has the OneLoginID 255293122. To make User A the manager of User B, set the manager field of User B to 255174535. This value is User A’s OneLoginID. You find the OneLoginID in the user’s profile.

OneLogin must send each user’s OneLoginID as externalId. The manager must also be provisioned to Robin through SCIM, in the same Robin organization.

Robin links managers every 3 hours. It links only people whose record changed since the previous evening. If you add the manager later, change any attribute on the employee so your identity provider sends an update. Robin then links the manager.

Articles in this section

Was this article helpful?
0 out of 3 found this helpful
Share