Okta: SCIM provisioning

Let Okta create, update and deactivate people in MuchSkills. You turn on SCIM in the MuchSkills app integration you use for single sign-on, connect it with the client ID and secret we create for you, choose what Okta may do, and assign people.

Updated

Connected on requestITAdmins and HR

Who
A MuchSkills Owner or Admin, with an Okta admin who can manage app provisioning
How it connects
Support sends SCIM credentials, then you set up provisioning in Okta
Needs
The MuchSkills SAML app integration in Okta
Plans
Included in all plans

Before you start

  • In MuchSkills: the Owner or Admin role.
  • In Okta: an administrator who can manage provisioning for the MuchSkills app integration.
  • The single sign-on app. Okta adds SCIM to an existing SAML or SWA app integration. Set up Okta: single sign-on first and use that app.
  • Provisioning enabled in your Okta org. If the SCIM option is missing in step 2, contact Okta support.
  • SCIM credentials from MuchSkills. We create an OAuth 2.0 client ID and client secret for you. The secret does not expire. Step 1 covers this.
  • One way in. If you already sync people with the Okta connector in Settings › Integrations, decide which of the two you keep for the same people.

Steps

In MuchSkills

  1. Ask support for SCIM credentials. Email support@muchskills.com or use the chat, and say you use Okta. Until provisioning is set up, Team/Org › Settings › Security & SAML says SCIM provisioning is available for your organisation. See the setup guide for next steps.

In Okta

  1. Turn on SCIM. In the Okta Admin Console, open the MuchSkills app integration. On the General tab, click Edit in App Settings, set Provisioning to SCIM and click Save. Okta's guide to adding SCIM provisioning
  2. Enter the connection values. On the Provisioning tab, go to Settings › Integration and click Edit:
    • SCIM connector base URL: https://app.muchskills.com/scim/v2
    • Unique identifier field for users: userName
    • Supported provisioning actions: tick Push New Users and Push Profile Updates. Leave Import New Users and Profile Updates and Push Groups unticked.
  3. Add the credentials. Under Authentication Mode, choose OAuth2 and the Client Credentials grant type. Enter https://app.muchskills.com/oauth2/token as the access token endpoint, and the client ID and client secret from MuchSkills. If Okta asks for an authorization endpoint, enter https://app.muchskills.com/oauth2/authorize.
    Click Test Connector Configuration, then Save.
  4. Choose what Okta may do. Under Settings › To App, click Edit. Tick Create Users, Update User Attributes and Deactivate Users. Leave Sync Password off and click Save. Okta's guide to provisioning settings
  5. Check the attribute mappings. Scroll to Attribute Mappings on the same page. Make sure first name, last name, email, title and department are mapped. To change a mapping, click Go to Profile Editor, open Mappings, edit the attribute and click Save Mappings, then Apply updates now. The username comes from Application username, which you set to Email for single sign-on.
  6. Assign a few people. On the Assignments tab, click Assign, then Assign to People or Assign to Groups. Click Assign next to each, then Save and Go Back and Done. Okta creates them in MuchSkills.

Back in MuchSkills

  1. Check the people who arrived. Team/Org › Members lists them. When all is well, assign the rest of your people in Okta.

Check it worked

  • Test Connector Configuration succeeds in step 4.
  • The people you assigned show no provisioning errors on the app's Assignments tab in Okta.
  • Team/Org › Members lists them with the right names, titles and departments.
  • Team/Org › Settings › Security & SAML says SCIM provisioning is enabled for your organisation.

What you get

  • Joiners and leavers handled in Okta. Assign someone and they get a MuchSkills account. Unassign or deactivate them and they are deactivated in MuchSkills.
  • Profile changes follow. When a title or department changes in Okta, Okta pushes the update to MuchSkills.
  • One place to manage access. The single sign-on app and provisioning live in the same Okta app integration.

Important to know

What syncs. Only email and name are required. Map as many of the other attributes as you hold in Okta, because each one makes MuchSkills more useful.

Okta profileSCIM attributeNeededUsed in MuchSkills for
Username (the email)userNameRequiredEmail and login
Primary emailemailsRequiredEmail. Must match userName
First name, last namename.givenName, name.familyNameRequiredName
TitletitleRecommendedJob title
Departmententerprise extension: departmentRecommendedDepartment
Managerenterprise extension: managerRecommendedReporting lines and My Circle. The value must be the manager's email address or MuchSkills user id
Address fieldsaddressesRecommendedLocation. Keep country mapped
StatusactiveRecommendedDeactivating leavers

How Okta sends changes. Okta finds existing users by userName. It deactivates people by setting active to false, and never sends DELETE for users. Okta's SCIM reference

Leavers are deactivated, not deleted. When Okta sends active set to false, MuchSkills deactivates the person. Their project history and certificates stay on record.

Roles. Okta does not send a MuchSkills role in this set-up, so provisioned people join as Member. See SCIM provisioning: how it works for the roles attribute.

Email addresses are managed by Okta. Provisioned people cannot change their email address in MuchSkills. They see Managed by automated provisioning in Profile Settings › Account.

Keep the credentials safe. Treat the token or client secret like a password. If you think it has leaked, ask support for new credentials and update them in Okta.

Troubleshooting

What you seeWhyWhat to do
There is no SCIM option under ProvisioningThe provisioning feature is not enabled for your Okta org, or the app is not a SAML or SWA integrationContact Okta support, and use the MuchSkills SAML app integration
Test Connector Configuration failsThe base URL or credentials are wrongCheck the values in steps 3 and 4. Ask support for new credentials if you are unsure
Okta shows 401 Unauthorized for a pushThe token or client credentials are wrong or no longer validEnter the credentials again, or ask support for new ones
A push fails with 409 ConflictA MuchSkills account with that email address already existsCheck the email in MuchSkills and in Okta, and that the username is the person's email address
A push fails because userName is not a valid emailApplication username is not set to EmailSet it to Email on the Sign On tab, then push again
Changes in Okta do not reach MuchSkillsPush Profile Updates or Update User Attributes is offTurn both on, then make a change to test
A department or title is missingThe attribute is not mapped to the appMap it in Attribute Mappings, then Apply updates now
Do we need the single sign-on app first?

Yes. Okta adds SCIM provisioning to an existing SAML or SWA app integration, so set up Okta: single sign-on first and use that app.

We cannot see the SCIM option in Okta. Why?

Okta says the provisioning feature must be enabled for your org. If SCIM does not appear in the app's settings, contact Okta support.

Should we use HTTP Header or OAuth2?

OAuth2. MuchSkills gives you a client ID and client secret, not a static token, so HTTP Header does not apply. With the Client Credentials grant type, Okta fetches a new one-hour token on its own whenever it needs one.

What happens when someone leaves?

When you unassign or deactivate a person in Okta, Okta sends active set to false and MuchSkills deactivates them. Okta never deletes users in apps. Their project history and certificates stay on record.

Can we push Okta groups to MuchSkills?

No. MuchSkills accepts users, not groups, so leave Push Groups off. You can still assign groups in Okta to decide who is provisioned.

Which role do provisioned people get?

Member, unless a role is sent in the roles attribute. Okta does not send a MuchSkills role in this set-up, so people provisioned from Okta join as Member.

Can we start with a few people?

Yes, and we recommend it. Assign a handful of people, check them in MuchSkills, then assign the rest.

Should we use this or Okta: sync users?

Use one of them for the same people. SCIM is driven from Okta. The Okta connector in Settings › Integrations is driven from MuchSkills, syncs every 5 hours and syncs by group. See Okta: sync users.

Is SCIM included in our plan?

Yes. All MuchSkills plans include SCIM provisioning and single sign-on (SAML).

Checking Daniel’s calendar...

Ask us anything

A real person replies, usually the same working day.

Live webinar · 13 Oct, 17:00 CEST

How to analyse the Skill Gaps in your organisation

MuchSkills allows organisations to conduct an in-depth skills gap analysis in a matter of minutes and uncover the skill gaps that hurt organisational performance In this webinar, you will learn how t…