Skip to main content

Set up SCIM provisioning from Okta

How-to guide · Okta

Written by Agent Bob

In this guide, you connect a managed app to Okta over SCIM through StackBob.ai, and then reconcile the app's existing accounts and entitlements with Okta. You map and approve the SCIM groups that represent the app's entitlements, import them into Okta, link them to Okta groups, and resolve rogue users.

When you finish, Okta is the source of truth for the mapped entitlements in the app. StackBob.ai handles user provisioning, updates, deactivation, and ongoing rogue user detection.


Prerequisites

  • A StackBob.ai organization where you hold the Org Admin role, with Okta set as the primary IGA. See Create your StackBob Org.

  • A managed app with a completed StackBob NCAP™ sync. See Quickstart: Connect your first managed app.

  • An Okta account with the Super Administrator role, or alternatively both the Application Administrator and Group Administrator roles.

  • For Automated SCIM setup: the Okta Management API connected. See Connect the Okta Management API

  • For Manual SCIM setup: existing SAML or SWA Okta app, or the SCIM 2.0 Test App (OAuth Bearer Token) app added from the Okta Integration Network catalog.


1. Choose the setup method

  1. In StackBob.ai, open the managed app that was successfully synced with StackBob via NCAP (app status in StackBob is Synced with App).

  2. On the Set Up Provisioning from Okta banner, select Set Up SCIM.

    ℹ️ This step also sets all the users into Unreconciled status to signal that reconciliation between the Target App (GitHub) and your primary IGA (Okta) needs to happen.

  3. Under Choose Okta setup method banner, select one option:

    • Automated SCIM setup: StackBob.ai connects to Okta via the Okta Management API. Then creates (or matches existing) app in Okta → exposes SCIM groups for import → creates Okta groups with user memberships → links them to SCIM-imported groups → detects and presents rogue users for review and resolution.

    • Manual SCIM setup: StackBob.ai exposes SCIM groups for import and provides a CSV file with groups and memberships. You create and reconcile them in Okta.

ℹ️ Both setup methods use the same SCIM connection. They differ only in who creates and links the Push Groups in Okta (in step 7) and who detects rogue users (in step 8).

✅ If you want to start testing SCIM without establishing Okta API integration, you can select Manual setup for now and connect Okta later on Okta Group creation step (step 7).


2. Create or select the app in Okta

The setup banner below applies to Automated SCIM setup only. If you chose Manual SCIM setup, go to step 3 and create Okta app manually.

  1. Under Create or select the app in Okta, select one of the options:

    • Create New App: StackBob.ai creates a SCIM 2.0 Test App (OAuth Bearer Token) app integration in Okta, with provisioning already enabled.

    • Select Existing App: select an existing SAML or SWA app integration from the list, so in the next setup steps it can be reconciled.

  2. Select Continue.

ℹ️ For custom apps, Okta supports SCIM 2.0 provisioning only on SAML and SWA app integrations, or on the SCIM 2.0 Test App from the Okta Integration Network (OIN) catalog.
If you have existing app that is using OpenID Connect (OIDC) as sign in method, set up provisioning in a separate app, and assign the same users and/or groups to both apps.

✅ If you're using Manual setup and need a new app integration, add the SCIM 2.0 Test App (OAuth Bearer Token) from the Okta Integration Network catalog and use it only for provisioning. Your existing SSO app stays as it is, and users keep signing in through it. The new app's sign-on settings aren't used, so you can leave them at their defaults. To keep the app off your users' Okta dashboard, open its General tab and select Do not display application icon to users.


3. Configure provisioning in Okta

The Configure provisioning in Okta banner shows the SCIM URL and SCIM token that StackBob.ai generated for this managed app. Keep the banner open while you add them to Okta. The banner tracks the test requests Okta sends to StackBob.ai and shows when the connection is working.

How you add the SCIM URL and token depends on the type of app integration you have in Okta:

Configuration flow 1: SCIM 2.0 Test App (OAuth Bearer Token)

Follow this flow if in the previous step (step 2) StackBob.ai has created the app in Okta via API, or if you added SCIM 2.0 Test App (OAuth Bearer Token) app integration from the catalog yourself.

The GitHub example (on the screenshots) goes through this flow:

  1. On the banner, select the open-in-new-tab icon next to the app name. The GitHub app opens in Okta.

  2. Go to ProvisioningIntegration and select Configure API Integration → Tick Enable API Integration.

  3. Fill in the fields:

    • SCIM 2.0 Base Url: paste the SCIM URL from StackBob.ai.

    • OAuth Bearer Token: paste the SCIM token from StackBob.ai.

  4. Leave Import Groups ticked.

  5. Select Test API Credentials. Okta confirms that the connection works.

  6. Select Save.

  7. Go to Provisioning → "To App" and select Edit. Turn on Create Users and Update User Attributes, then select Save.

Configuration flow 2: Existing SAML or SWA app

Follow this flow if you're adding provisioning to an app integration you already have and it's using SAML or SWA sign-in.

  1. Open the app in Okta.

  2. If the app has no Provisioning tab, go to GeneralApp SettingsEdit and set Provisioning to SCIM.

  3. Go to ProvisioningIntegration and select Edit.

  4. Fill in the connector settings:

    • SCIM connector base URL: paste the SCIM URL from StackBob.ai.

    • Unique identifier field for users: userName

    • Supported provisioning actions: select Import New Users and Profile Updates, Push New Users, Push Profile Updates, Push Groups, and Import Groups.

      ℹ️ Push Groups must be selected as supported action here. Without it, the Push Groups will not available in the later steps of this guide.

    • Authentication Mode: select HTTP Header, then paste the SCIM token from StackBob.ai as the bearer token under Authorization.

  5. Select Test Connector Configuration. Okta lists the provisioning actions that the StackBob.ai connector supports. Every action you selected in sub-step 4 should show a green check mark. Close the dialog.

  6. Select Save.

  7. Go to Provisioning → "To App" and select Edit. Turn on Create Users and Update User Attributes, then select Save.

Finish provisioning configuration

When StackBob.ai receives Okta's test SCIM request, the button Finish Testing becomes enabled and you can move to the next step.

⚠️ Until you Finish Testing, StackBob.ai treats requests from Okta as tests. When you do Finish Testing, the setup flow progresses to the next step, and all SCIM requests from then on are treated as live and influence reconciliation and provisioning into the managed app.

✅ To protect managed app accounts from accidental deactivation during reconciliation, leave Deactivate Users off in the Okta app (under ProvisioningTo App) until you finish reconciliation. If you turn it on earlier, Okta might deactivate every managed app account that isn't yet assigned in Okta.


4. Select entitlement types for SCIM group mapping

StackBob NCAP™ automatically discovers the types of entitlements the app uses. For GitHub, these are Role, Team, and Repository. You can choose which types StackBob.ai should reconcile with IGA via SCIM groups. StackBob.ai then suggests a SCIM group for each entitlement value of selected types, and you review the suggestions.

  1. On the Select entitlements for SCIM groups mapping banner, turn on each entitlement type you want Okta to govern. In this example, Role, Team, and Repository are all turned on.

  2. Select Save & Continue.

✅ Types with many values, such as Repository, can produce a large number of SCIM groups. Turn on only the types you actually want Okta to govern.

ℹ️ You can also change the selected entitlement types later in StackBob under AppSettings Provisioning Entitlements for SCIM Groups Mapping. But only entitlement types which were not yet synced with IGA can be turned off.


5. Review and approve the SCIM group mapping

StackBob.ai suggests a SCIM group for each entitlement value of the types you selected in step 4. In this GitHub example, that means a group for each role (such as Owner and Member), each team, and each repository's access.

When you approve a group, StackBob.ai exposes it over SCIM so Okta can import it. Groups you don't approve aren't exposed, and they stay unmanaged until you approve and import them.

  1. On the Review and approve SCIM group mapping banner, select Show Unreviewed Groups. The SCIM Groups tab opens, filtered to show only unapproved groups.

  2. For each group, review the entitlement it represents and the accounts that currently hold it.

  3. For each entitlement you want to govern in Okta, do one of the following:

    • Map it to an existing group: select the Map action and enter the name of the existing group to match.

    • Approve it as a new SCIM group: approve the group with the name StackBob.ai suggests.

  4. When you're ready to import, select Continue on the setup banner. The button becomes available once at least one group is approved or mapped.

✅ Start with a few groups to get familiar with the flow. You can map or approve the rest later, then run the import in Okta again to pick them up. Each entitlement mapping has its own status, so you can filter which groups are reviewed, imported, or not yet imported.


6. Import accounts and groups into Okta

  1. Open the managed app profile in Okta.

  2. Go to the Import tab and select Import Now. Okta retrieves all app's accounts and only mapped/approved groups from StackBob.ai.

  3. When the import finishes, review the results:

    • Matched accounts: check that each proposed match pairs the GitHub account with the correct Okta user.

    • Unmatched accounts: leave them unconfirmed. StackBob.ai will present them as Rogue users later steps.

  4. Select the matched accounts you want to keep, and then select Confirm Assignments.

    ⚠️ Confirming an unmatched account in Okta creates a new Okta user for an account that might not belong to anyone in your organization, and gives that account a managed identity. Review unmatched accounts carefully before you confirm or deactivate them.

  5. Return to StackBob.ai and select Continue on the setup banner.

    ℹ️ Only approved or mapped SCIM groups are imported into Okta in this step. They stay read-only until they are linked to Okta Push Groups in the next step.

    ✅ All user accounts are imported into Okta over SCIM in this step, but they stay unreconciled until they're assigned to Push Groups in the next step.


7. Create and link Push Groups

Each SCIM-imported group needs an Okta group linked to it. Once a group is linked, Okta owns its membership.

Automated setup

StackBob.ai uses the Okta Management API to create one Okta group for each approved SCIM group. It adds the members who currently hold that entitlement in the app, then links the Okta group to its SCIM-imported group. The links are created inactive, so nothing changes in the app during this step.

  1. On the Create and link Push Groups in Okta via API banner, select Link Groups.

  2. When the operation completes and you are ready to proceed to the final reconciliation step, select Continue.

If the banner reports that some Push Groups couldn't be created because their SCIM groups weren't imported into Okta, repeat step 6 and run Import Now in Okta again.

Manual Setup

  1. On the Create and link Push Groups in Okta banner, select Download Groups CSV. The file lists each group's exact name and its members.

  2. In Okta, go to DirectoryGroups and create each group, using the exact name from the CSV.

  3. Add every member listed in the CSV to their group. As you do, note any listed member who has no Okta user, or whose Okta user is deactivated. These are Rogue users, and you resolve them in the next step.

  4. Open the app in Okta, go to the Push Groups tab, and select Push Groups.

  5. Select Find groups by name and search for one of the groups you created in step 2 of this procedure.

  6. Under Match results and push action, select Link Group, then select the matching SCIM-imported group.

  7. Repeat steps 5 and 6 for every group in the CSV, then select Save.

  8. Return to StackBob.ai and select Next Step on the setup banner.

⚠️ Add all members to a group before you link it. Linking starts the SCIM clean-up immediately. If a group is empty or incomplete when you link it, Okta tries to remove the missing users from the app over SCIM.

⚠️ Don't rename Okta groups or SCIM-imported groups afterwards. StackBob.ai matches them by name. Renaming a group stops synchronization, and Okta doesn't show an error.

✅ You can still switch to Automated SCIM setup flow at this point, just select Set Up Okta API on the banner. Learn more in Connect the Okta Management API.


8. Resolve Rogue users and finish reconciliation

A Rogue user is an account in the app that has no matching Okta user, or whose Okta user is deactivated. Okta can't govern a Rogue user's access. In GitHub, a common example is a personal GitHub account that someone added to the organization directly or ex employee who was deactivated in Okta but his account in the app remained active due to lack of automated deprovisioning.

You can resolve each Rogue user in one of two ways:

  • Revoke: Remove the account's access with the Revoke action in StackBob.ai (and StackBob will deactivate user account automatically via NCAP), or you can deactivate user directly in the app.

  • Bring under management: In Okta, create or reactivate the user, assign them to the app, and add them to the corresponding Push Group.

Finish reconciliation with Automated setup

  1. On the Review Rogue users and finish reconciliation banner, select Show Rogue Users. The list shows each account and why it was flagged.

  2. Resolve each Rogue user in one of two ways:

    • Revoke access: Use the Revoke action in StackBob.ai. This revokes the user's access in the app and marks the account as revoked in StackBob.ai.

    • Bring under management: In Okta, go to the app's Import tab and confirm the account. Then, in StackBob.ai, open the app's More actions menu and select Push Groups to Okta to add the user to the matching Push Groups.

  3. When all users and groups are reconciled, open the App in Okta and go to the Push Groups tab. Select Bulk Edit, select all groups, and choose Activate. Okta pushes group memberships to the app immediately.

  4. In Okta app, set Deactivate Users to ON (under ProvisioningTo App).

  5. When ready return to StackBob.ai and select Finish Reconciliation on the setup banner.

✅ With Automated setup, StackBob.ai automatically detects all Rogue user accounts during the initial reconciliation and presents them for your review, with the option to revoke their access via NCAP.

✅ After the initial reconciliation, StackBob.ai keeps monitoring accounts in the app and detects any new Rogue users added directly to the app.

Finish reconciliation with Manual setup

Without Okta Management API access, StackBob.ai can't compare app accounts with Okta users. You need to manually detect the Rogue users you noted while importing users into Okta from StackBob-generated CSV.

  1. Resolve each Rogue user. If you need more time for one, open the account's More actions menu in StackBob and select Mark as Rogue. To revert select this status select Mark Unreconciled.

  2. In Okta, open the app and go to the Push Groups tab. Confirm that every linked group shows Active

  3. In Okta app, set Deactivate Users to ON (under ProvisioningTo App).

  4. Return to StackBob.ai and select Finish Reconciliation on the setup banner.


Result

GitHub is now provisioned from Okta through StackBob.ai, and Okta is the source of truth for the mapped entitlements.

  • Provisioning: When a user is assigned to the app in Okta, StackBob.ai creates their account in GitHub. When the user's profile changes in Okta, StackBob.ai updates the account. When the assignment is removed, StackBob.ai deactivates the account.

  • Entitlements: When you add or remove a user in a Push Group in Okta, StackBob.ai grants or revokes the matching role, team, or repository access in GitHub.

  • Rogue users: StackBob.ai keeps monitoring GitHub and flags any new account added directly to the app.

Entitlements you didn't approve in step 5 stay unmanaged. You can approve them later from the SCIM Groups tab, then run Import Now in Okta to pick them up and then Push Groups to Okta to add the user to the matching Push Groups.


Next steps

  • How SCIM group mapping works: how entitlements become SCIM groups, and what changes when Okta takes over a group.

  • Managed app statuses: what each account and group status means after reconciliation.

  • Connect the Okta Management API: switch from Manual to Automated setup so StackBob.ai creates and links future groups for you.


Need help?

If something doesn't work as described, contact your StackBob.ai onboarding representative, or send us a message from the chat in the bottom-right corner of this page.

Did this answer your question?