Okta: SCIM provisioning
Let Okta create, update and deactivate people in MuchSkills. You turn on SCIM in the MuchSkills app integration you use for single sign-on, connect it with the client ID and secret we create for you, choose what Okta may do, and assign people.
- Who
- A MuchSkills Owner or Admin, with an Okta admin who can manage app provisioning
- How it connects
- Support sends SCIM credentials, then you set up provisioning in Okta
- Needs
- The MuchSkills SAML app integration in Okta
- Plans
- Included in all plans
How to
Before you start
- In MuchSkills: the Owner or Admin role.
- In Okta: an administrator who can manage provisioning for the MuchSkills app integration.
- The single sign-on app. Okta adds SCIM to an existing SAML or SWA app integration. Set up Okta: single sign-on first and use that app.
- Provisioning enabled in your Okta org. If the SCIM option is missing in step 2, contact Okta support.
- SCIM credentials from MuchSkills. We create an OAuth 2.0 client ID and client secret for you. The secret does not expire. Step 1 covers this.
- One way in. If you already sync people with the Okta connector in Settings › Integrations, decide which of the two you keep for the same people.
Steps
In MuchSkills
- Ask support for SCIM credentials. Email support@muchskills.com or use the chat, and say you use Okta. Until provisioning is set up, Team/Org › Settings › Security & SAML says SCIM provisioning is available for your organisation. See the setup guide for next steps.
In Okta
- Turn on SCIM. In the Okta Admin Console, open the MuchSkills app integration. On the General tab, click Edit in App Settings, set Provisioning to SCIM and click Save. Okta's guide to adding SCIM provisioning
- Enter the connection values. On the Provisioning tab, go to Settings › Integration and click Edit:
- SCIM connector base URL: https://app.muchskills.com/scim/v2
- Unique identifier field for users: userName
- Supported provisioning actions: tick Push New Users and Push Profile Updates. Leave Import New Users and Profile Updates and Push Groups unticked.
- Add the credentials. Under Authentication Mode, choose OAuth2 and the Client Credentials grant type. Enter https://app.muchskills.com/oauth2/token as the access token endpoint, and the client ID and client secret from MuchSkills. If Okta asks for an authorization endpoint, enter https://app.muchskills.com/oauth2/authorize.
Click Test Connector Configuration, then Save. - Choose what Okta may do. Under Settings › To App, click Edit. Tick Create Users, Update User Attributes and Deactivate Users. Leave Sync Password off and click Save. Okta's guide to provisioning settings
- Check the attribute mappings. Scroll to Attribute Mappings on the same page. Make sure first name, last name, email, title and department are mapped. To change a mapping, click Go to Profile Editor, open Mappings, edit the attribute and click Save Mappings, then Apply updates now. The username comes from Application username, which you set to Email for single sign-on.
- Assign a few people. On the Assignments tab, click Assign, then Assign to People or Assign to Groups. Click Assign next to each, then Save and Go Back and Done. Okta creates them in MuchSkills.
Back in MuchSkills
- Check the people who arrived. Team/Org › Members lists them. When all is well, assign the rest of your people in Okta.
Check it worked
- Test Connector Configuration succeeds in step 4.
- The people you assigned show no provisioning errors on the app's Assignments tab in Okta.
- Team/Org › Members lists them with the right names, titles and departments.
- Team/Org › Settings › Security & SAML says SCIM provisioning is enabled for your organisation.
Benefits
What you get
- Joiners and leavers handled in Okta. Assign someone and they get a MuchSkills account. Unassign or deactivate them and they are deactivated in MuchSkills.
- Profile changes follow. When a title or department changes in Okta, Okta pushes the update to MuchSkills.
- One place to manage access. The single sign-on app and provisioning live in the same Okta app integration.
Important to know
Important to know
What syncs. Only email and name are required. Map as many of the other attributes as you hold in Okta, because each one makes MuchSkills more useful.
| Okta profile | SCIM attribute | Needed | Used in MuchSkills for |
|---|---|---|---|
| Username (the email) | userName | Required | Email and login |
| Primary email | emails | Required | Email. Must match userName |
| First name, last name | name.givenName, name.familyName | Required | Name |
| Title | title | Recommended | Job title |
| Department | enterprise extension: department | Recommended | Department |
| Manager | enterprise extension: manager | Recommended | Reporting lines and My Circle. The value must be the manager's email address or MuchSkills user id |
| Address fields | addresses | Recommended | Location. Keep country mapped |
| Status | active | Recommended | Deactivating leavers |
How Okta sends changes. Okta finds existing users by userName. It deactivates people by setting active to false, and never sends DELETE for users. Okta's SCIM reference
Leavers are deactivated, not deleted. When Okta sends active set to false, MuchSkills deactivates the person. Their project history and certificates stay on record.
Roles. Okta does not send a MuchSkills role in this set-up, so provisioned people join as Member. See SCIM provisioning: how it works for the roles attribute.
Email addresses are managed by Okta. Provisioned people cannot change their email address in MuchSkills. They see Managed by automated provisioning in Profile Settings › Account.
Keep the credentials safe. Treat the token or client secret like a password. If you think it has leaked, ask support for new credentials and update them in Okta.
Common errors
Troubleshooting
| What you see | Why | What to do |
|---|---|---|
| There is no SCIM option under Provisioning | The provisioning feature is not enabled for your Okta org, or the app is not a SAML or SWA integration | Contact Okta support, and use the MuchSkills SAML app integration |
| Test Connector Configuration fails | The base URL or credentials are wrong | Check the values in steps 3 and 4. Ask support for new credentials if you are unsure |
| Okta shows 401 Unauthorized for a push | The token or client credentials are wrong or no longer valid | Enter the credentials again, or ask support for new ones |
| A push fails with 409 Conflict | A MuchSkills account with that email address already exists | Check the email in MuchSkills and in Okta, and that the username is the person's email address |
| A push fails because userName is not a valid email | Application username is not set to Email | Set it to Email on the Sign On tab, then push again |
| Changes in Okta do not reach MuchSkills | Push Profile Updates or Update User Attributes is off | Turn both on, then make a change to test |
| A department or title is missing | The attribute is not mapped to the app | Map it in Attribute Mappings, then Apply updates now |
Frequently asked questions
Do we need the single sign-on app first?
Yes. Okta adds SCIM provisioning to an existing SAML or SWA app integration, so set up Okta: single sign-on first and use that app.
We cannot see the SCIM option in Okta. Why?
Okta says the provisioning feature must be enabled for your org. If SCIM does not appear in the app's settings, contact Okta support.
Should we use HTTP Header or OAuth2?
OAuth2. MuchSkills gives you a client ID and client secret, not a static token, so HTTP Header does not apply. With the Client Credentials grant type, Okta fetches a new one-hour token on its own whenever it needs one.
What happens when someone leaves?
When you unassign or deactivate a person in Okta, Okta sends active set to false and MuchSkills deactivates them. Okta never deletes users in apps. Their project history and certificates stay on record.
Can we push Okta groups to MuchSkills?
No. MuchSkills accepts users, not groups, so leave Push Groups off. You can still assign groups in Okta to decide who is provisioned.
Which role do provisioned people get?
Member, unless a role is sent in the roles attribute. Okta does not send a MuchSkills role in this set-up, so people provisioned from Okta join as Member.
Can we start with a few people?
Yes, and we recommend it. Assign a handful of people, check them in MuchSkills, then assign the rest.
Should we use this or Okta: sync users?
Use one of them for the same people. SCIM is driven from Okta. The Okta connector in Settings › Integrations is driven from MuchSkills, syncs every 5 hours and syncs by group. See Okta: sync users.
Is SCIM included in our plan?
Yes. All MuchSkills plans include SCIM provisioning and single sign-on (SAML).