SCIM Setup in Okta

Setting up SCIM in the Okta environment.

II. Configure provisioning in Okta

  1. Enable SCIM provisioning in the general tab of your LeanIX application.
  1. If previously created, delete and recreate “role” attribute to contain the following external namespace and then Save:
urn:ietf:params:scim:schemas:extension:workspacePermission:2.0:User
  1. Open the “Provisioning” tab and edit the SCIM Connection with the following information, then hit “Save”

FieldValue
SCIM connector base URLhttps://customer-domain.leanix.net/services/mtm/v1/scim/v2
Unique identifier field for usersuserName
Supported provisioning actionsImport New Users and Profile Updates, Push New Users, Push Profile Updates
Authentication ModeHTTP Header
BearerLong-lived bearer token previously retrieved
  1. Map your attributes

In the “To App” settings, enable the following and Save: Create users, Update user attributes, and Deactivate users

Scroll down to “LeanIX Attribute Mapping." Remove mapping for all attributes except for the following six:

Note: the role property is only relevant for customers with fully-external IDM

Note: the role property is only relevant for customers with fully-external IDM