Okta - SCIM Configuration - RSA Ready Implementation Guide
This article describes how to integrate Okta with RSA Cloud Access Service (CAS) using SCIM.
Configure CAS as a SCIM Server
Perform these steps to configure CAS as a SCIM server.
Procedure
- Sign in to the RSA Cloud Administration Console and click Users > Identity Sources > Add Identity Source.
- On the New Identity Source page, choose SCIM Managed.
- Specify the Identity Source Name.
- Enable SCIM connection user provisioning from a SCIM source.
- Copy the SCIM Service Provider Base URL.
- In the Authentication section, select API Key.
- Copy the SCIM Service API key. This is used in Okta configuration.
- Choose No Password Available to CAS for authentication.
- Save the configuration and click Publish Changes.
After publishing, your application is now enabled for SCIM.
Configure Okta as a SCIM Client
Perform these steps to configure Okta as a SCIM client.
Procedure
- Log in to the Okta admin web interface with the OKTA default admin user or any other admin https://IP-address.okta.com/oauth2/.
- Click Applications > Create App Integration Server Profiles > SAML Identity Provider.
- Under Applications, click Create App Integration.
- Choose SWA - Secure Web Authentication and click Next.
In the Okta configuration, there are two available options: SAML 2.0 and SWA (Secure Web Authentication).
- If you choose SAML 2.0, follow the configuration steps outlined in the Okta - RSA Ready Implementation Guide.
- If you choose SWA (Secure Web Authentication), perform the following steps.
- Specify the App name as mentioned in the following image.
- Navigate to General > App Settings > Provisioning, and choose SCIM.
- Navigate to the Provisioning tab > the Integration section, and specify the SCIM connection details.
- SCIM connector base URL copied from CAS.
- Unique identifier field for users: userName
- Supported provisioning actions: select the following checkboxes
- Import New Users and Profile Updates
- Push New Users
- Push Profile Updates
- Authentication Mode: Select HTTP Header
- HTTP Header Authorization: Copy the Bearer token from CAS. Test connector configuration should be successful.
- Verify the password configuration. Navigate to Security > Authenticators, select Actions > Edit for the Password authenticator, and ensure the password settings are configured according to the requirements listed in the following images.
The configuration is complete.
Related Articles
Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide 674Number of Views Microsoft Entra ID - SCIM Client for Cloud Authentication Service - RSA Ready Implementation Guide 581Number of Views Okta - RSA Ready Implementation Guide 115Number of Views Microsoft Entra ID External MFA - RSA Ready Implementation Guide 638Number of Views Palo Alto NGFW - RSA Ready Implementation Guide 404Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Step 3: Test with Your Identity Source and All Applications Microsoft Entra ID - SCIM Client for Cloud Authentication Service - RSA Ready Implementation Guide Disable multi-factor authentication (MFA) prompt for "Run as" on machine on which the RSA MFA Agent for Microsoft Windows … Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory
Don't see what you're looking for?