# Configure SCIM - Okta

This guide describes how to sync users and groups to **Row Zero** with **Okta** using SCIM (System for Cross-domain Identity Management). Once set up, any users or groups assigned to the application in Okta will automatically sync to Row Zero.

_**NOTE: Before configuring SCIM, determine the SSO solution you plan on using.**_

- _**If you are planning to configure SSO through SAML, please follow the instructions in**_ [_**Single Sign-On (SSO) - SAML (Okta)**_](single-sign-on-saml-okta) _**first.**_
- _**If you've already configued Okta to use SAML for SSO, skip to**_ [_**Step 2**_](scim-okta#step-2-configure-the-scim-connection)_**.**_

docs/scim-okta#step-2-configure-the-scim-connection

## Step 1: Create the SAML Application with Provisioning

1. In the Okta "Admin Console", navigate to "Applications --&gt; Applications"  

   ![scim okta applications](https://cdn.sanity.io/images/2w8agf2t/production/7aed2a477b9667071b5c1b3e0993c9872a85a724-287x512.png)

2. Click on the "Create App Integration" button:  

   ![scim okta app integration](https://cdn.sanity.io/images/2w8agf2t/production/541f5e2b7490f2857eb0c9e5503db783f513e73f-286x72.png)

3. Select "`SAML 2.0`" and click the "Next" button:  

   ![scim okta app integration saml](https://cdn.sanity.io/images/2w8agf2t/production/780aad7eb48e70dcf72986e480626a666c7a5fcd-1392x795.png)

4. In the "Create SAML Integration" page, provide the following:
    - For the "**App name**" type "`Row Zero`"
    - Find Upload new logo. You can click [this link](https://d3gu6cpxmtctuo.cloudfront.net/brand/v2/rz-logo-black.png) to download the Row Zero logo, and then upload for "**App logo**"
    - Leave the "**Do not display application icon to users**" _**unchecked**_
    - Click the "Next" button  

      ![scim okta saml settings](https://cdn.sanity.io/images/2w8agf2t/production/f0fc78bdce01de19f2d52cac22e4ee3c6ea045df-1547x853.png)

5. For the "SAML Settings" - "General" page, provide the following:
    - Leave the "**Use this for Recipient URL and Destination URL**" _**checked**_
    - For "**Single sign-on URL**" type "`https://rowzero.com`"
    - For "**Audience URI (SP Entity ID)**" type "`N/A`"
    - Click the "Next" button  

      ![scim okta create saml integration](https://cdn.sanity.io/images/2w8agf2t/production/078f1062b87f7c1dfc9bf9c2e2ed0747b660eab3-1584x1123.png)

6. Click the "Finish" button:  

![scim okta create saml integration](https://cdn.sanity.io/images/2w8agf2t/production/78169851f2b92fa4786f096e03a554c8b069c09d-1102x1073.png)

## Step 2: Configure the SCIM Connection

1. In the "**Row Zero**" application, on the "**General**" tab, click the "**Edit**" button:
    - For "**Provisioning**" select "`Enable SCIM provisioning`"
    - Click the "**Save**" button  

      ![scim okta saml settings](https://cdn.sanity.io/images/2w8agf2t/production/17235918dfa295847469323a6b58fe0ef3e22369-1117x1222.png)

2. In the "**Row Zero**" application, on the "**Provisioning**" tab, click the "**Edit**" button:
    - For "**SCIM connector base URL**" type "`https://scim.rowzero.com/scim/v2`"
    - For "**Unique identifier field for users**" type "`userName`"
    - For "**Supported provisioning actions**" select "`Push New Users`", "`Push Profile Updates`", and "`Push Groups`"
    - For "**Authentication Mode**" select "`HTTP Header`"
    - For "**Authorization**" enter the token provided to you by Row Zero
    - Click the "**Test Connector Configuration**" button and verify success
    - Click the "**Save**" button  

![scim okta saml settings](https://cdn.sanity.io/images/2w8agf2t/production/19c51604be74c7915c8e5717de501acd7baa1a67-1555x1603.png)

## Step 3: Enable User Provisioning Features

1. In the “**Row Zero**” application, under the “_**Provisioning**_” tab, select “_**Settings —&gt; To App**_”:  

   ![scim okta provisioning app](https://cdn.sanity.io/images/2w8agf2t/production/fdb1f20061422ba520bee0ab094e7bed0ec61e66-1269x562.png)

2. Click the “_**Edit**_” link, and select “_**Create Users**_”, “_**Update User Attributes**_”, and “_**Deactivate Users**_” checkboxes:  

   ![scim okta sync profile](https://cdn.sanity.io/images/2w8agf2t/production/396317fcdfe20bf0878891e3df7e413c29e24676-1281x1120.png)

3. Click the “_**Save**_” button:  

   ![scim okta save button](https://cdn.sanity.io/images/2w8agf2t/production/30740d376806cd9d0b32a01eb6e3be8c456c5199-100x61.png)

4. On the same page, under “**Row Zero**”, click on the “_**Go to Profile Editor**_” button:  

   ![scim okta go to profile editor](https://cdn.sanity.io/images/2w8agf2t/production/7401d5fd460b3aed210eb4b12047c0cd4a0cb0a3-937x226.png)

5. Under the “_**Attributes**_” section click on the “_**Mappings**_” button:  

   ![scim okta plus mappings](https://cdn.sanity.io/images/2w8agf2t/production/c85bb65c35333d5ca5bc4b4aad5173b9242b2904-1267x574.png)

6. Select the “_**Okta User to Row Zero**_” tab:  

   ![scim okta to row zero](https://cdn.sanity.io/images/2w8agf2t/production/3b2a677c77aafba1ca6f800b68ba445ea993131c-949x157.png)

7. Select “_**Do not map**_” for every mapping other than “_**userName**_” and “_**displayName**_”:  

   ![scim okta mappings](https://cdn.sanity.io/images/2w8agf2t/production/232f4dec376cf234f6db2783cae89bd84c9fa227-1461x1155.png)

8. Click the “_**Save Mappings**_” button:  

   ![scim okta mappings](https://cdn.sanity.io/images/2w8agf2t/production/630ebcaaeb1361d871058fcc4b469b1265e1dcec-223x81.png)

9. Click the "_**Apply Updates**_" button

## Step 4: Assign Groups and Users

1. Navigate back to “_**Applications**_” → “_**Applications**_” and click on the “**Row Zero 2.0 App (OAuth Bearer Token)**” application:  

   ![scim okta row zero application](https://cdn.sanity.io/images/2w8agf2t/production/af73f78fa5d240d53fc841c90268f280448c07af-1600x858.png)

2. Under the “_**Push Groups**_” tab press the “_**Push Groups**_” button and select “_**Find groups by name**_”:  

   ![scim okta push groups](https://cdn.sanity.io/images/2w8agf2t/production/f33b1f993f1edb5d187edf50a00356ecf2a120ae-1282x1057.png)

3. Select the “_**Push group memberships immediately**_” checkbox, enter the group name(s) you’d like to sync to Row Zero, and when done click the “_**Save**_” button:  

   ![scim okta push groups selection](https://cdn.sanity.io/images/2w8agf2t/production/813201ef67a54f45630ac70c71f5dc3a37bf539b-1527x1365.png)

4. Under the “_**Assignments**_” tab press the “_**Assign**_” button and select “_**Assign to People**_” for any user in your application that could possibly use Row Zero in order to activate type ahead completion in the secure sharing feature:
    - Note: If Okta makes you populate the “_**Given name**_” and “_**Family name**_” attributes when assigning the user, populate them with relevant values; ultimately these will be ignored by Row Zero in favor of the display name.  

      ![scim okta assign users](https://cdn.sanity.io/images/2w8agf2t/production/ce5b7c3e6a5d31f8a2556270965a1310ac3de09e-943x973.png)

5. Under “_**Assignments**_” tab press the “_**Assign**_” button and select “_**Assign to Groups**_” and assign any of the groups defined under the “_**Push Groups**_” tab:
    - Note: The “_**Push Groups**_” tab tells Okta to sync the group records but not the group membership, the “_**Assignments**_” tab in relation to groups tells Okta to sync the members of the group.  

![scim okta assign groups](https://cdn.sanity.io/images/2w8agf2t/production/ce5b7c3e6a5d31f8a2556270965a1310ac3de09e-943x973.png)
