If your organization uses Okta to manage your employees’ access to tools and services, you can take advantage of Okta’s “Provisioning” feature to automatically grant access to OpsLevel to your users.
The integration between Okta and OpsLevel that enables this provisioning to occur is built around an industry-standard protocol known as SCIM (System for Cross-domain Identity Management). To learn more about how Okta works with SCIM, please see this article.
The remainder of this guide is focused on enabling you to configure both OpsLevel and Okta to get provisioning up and running for your organization.
If you are interested in how to set up Single Sign-On in OpsLevel via Okta, please check out our guide here.
The following provisioning features are supported by OpsLevel today:
- Push Users: Users in Okta that are assigned to the OpsLevel application within Okta are automatically added as users in OpsLevel
- Update User Attributes: When user attributes are updated in Okta, they will be updated in OpsLevel.
- Deactivate Users: When users are deactivated in Okta, they will be set to ‘Deactivated’ within OpsLevel – which prevents the user from logging into OpsLevel.
SCIM-based user provisioning is available to all customers of OpsLevel at this time.
Step-by-step configuration instructions
The OpsLevel - Okta Provisioning integration uses the same Application in Okta as our Single Sign-On integration. We recommend you configure Single Sign-On first by following the steps here.
Create a SCIM Integration in OpsLevel
In order to complete Step 5, you'll need to be logged in as a user with the Admin role. For more information on roles in OpsLevel, check out the guide.
- In the OpsLevel app, Click Integrations in the left sidebar.
- Click the + New Integration tile.
- On the New Integrations page, click the SCIM tile.
- Click Create to create a new SCIM Integration.
- On the SCIM Integration page, press the + Create API Token button and follow the prompts to create your API Token. When created, copy the token for use in Step 6 of Configuring the OpsLevel Okta Application below.
NOTE: Ensure that you keep the token in a safe place as you will need it when configuring the integration within Okta and you will not be able to retrieve the value again later. If you do need to retrieve the value you will have to replace the token by clicking Delete API Token and repeat the API Token creation flow.
- While on this page, copy the SCIM API URL for use in Step 5 of configuring the OpsLevel application in Okta.
Configure Provisioning in the OpsLevel Okta Application
The below steps assume you've installed the OpsLevel application in Okta already. If you haven't, follow the steps in our Single Sign-On guide for Okta.
- In Okta, navigate to the Applications tab, then find and navigate to the OpsLevel application.
- Click on the Provisioning tab, then click Integration in the Settings panel on the left side.
- Click the Configure API Integration button.
- Check the Enable API Integration checkbox to view additional settings.
- Paste the values that were saved during configuration of the SCIM Integration in OpsLevel:
- Use the SCIM API URL (from Step 6 above) for the Base Url field.
- Use the API Token (from Step 5 above) for the API Token field.
- Now that the Integration Settings are complete, click the To App Settings option in the left panel of the Provisioning tab and click Edit.
- Check each box for OpsLevel's supported provisioning features:
- Create Users
- Update User Attributes
- Deactivate Users
- Click Save.
- Navigate to the Sign-On tab and click Edit.
- Under Credential Details, select Email as the Application username format and click Save.
Now that provisioning is configured, you can assign your Okta users to the OpsLevel application as needed. New OpsLevel users provisioned this way will be automatically invited to your OpsLevel organization and receive a welcome email with a link to the OpsLevel application. For more information about how to assign Okta users, see Okta's documentation.
If you have questions or difficulties with the SCIM integration, hit us up at firstname.lastname@example.org.