Okta SCIM Integration Guide for Scalefusion
  • 12 Nov 2025
  • 3 Minutes to read
  • PDF

Okta SCIM Integration Guide for Scalefusion

  • PDF

Article summary

The SCIM (System for Cross-domain Identity Management) integration with Okta allows organizations to automate the provisioning and management of users and groups in Scalefusion. With this integration, IT admins can easily synchronize user accounts, update user information, and manage group memberships directly from Okta ensuring that user access in Scalefusion stays up-to-date and aligned with your organization’s identity policies.

This guide walks you through the step-by-step process of configuring the SCIM connection between Okta and Scalefusion, along with details on supported features, setup requirements, and troubleshooting tips.

Features

The following provisioning features are supported with this integration:

  • Push Users: Automatically create and manage users from Okta in Scalefusion.

  • Update User Attributes: Changes to user attributes in Okta will flow through to Scalefusion.

  • Deactivate Users: When users are deactivated in Okta, they will be deactivated in Scalefusion.

  • Push Groups: Groups and their members from Okta can be synchronized to Scalefusion.

Requirements

  1. SCIM Connector should be configured on Scalefusion Dashboard.

  2. You need an Okta admin account with permissions to add and configure applications.

  3. Ensure your Scalefusion account has the necessary access to generate the SCIM API endpoint and token.

How to Configure

Set Up the SCIM Application in Okta

  1. In the Okta Admin Console go to Applications → Applications.

  2. Click Browse App Catalog.

  3. Search for “SCIM” and select SCIM 2.0 Test App (Header Auth).

  4. Click Add Integration.

  5. Under General Settings, enter an application label and click Next.

  6. On the Sign-On tab, accept the default settings and click Done.

Configure API Integration

  1. Navigate to the Provisioning tab of the SCIM application.

  2. Click Integration, then enable API Integration.

  3. From your Scalefusion Dashboard's SCIM configuration panel, copy the Base URL (the SCIM API endpoint) and API Token (prefixed with “Bearer ”). Paste them into Okta.

  4. Click Test API Credentials to verify the connection, then click Save.

     

Configure Provisioning Actions

  1. Go to To App → Edit in the Provisioning tab.

  2. Enable the checkboxes:

    • Create Users

    • Update User Attributes

    • Deactivate Users

  3. Click Save.

Assign Users or Groups to the SCIM Application

A. Assign Individual Users

  1. Under the Assignments tab click Assign → Assign to People.

  2. If needed, add a new person and fill the required details: User Type, First Name, Last Name, Username, Primary Email, optionally Secondary Email and Groups, Activation status.

  3. Click Assign next to the desired user.

B. Assign Groups

Step 1: Create a Group
  1. Go to Directory → Groups → Add Group.

  2. Provide a Name and optional Description. Click Save.

Step 2: Add Users to the Group
  1. In the group’s details, click Assign People.

  2. If users aren’t yet present, click More Actions → Add People and complete the user details. Use the “+” icon to add each user to the group.


Step 3: Assign the SCIM App to the Group
  1. In the SCIM application, go to Assignments → Assign → Assign to Groups.

  2. Select the group you created and click Assign.

Push Groups to Scalefusion

  1. In the SCIM application in Okta, go to Push Groups → Push Groups → Find groups by name.

  2. Search for the group you created, select it and click Save.

Note: If you push groups without assigning them to the SCIM app, only the group names sync — users will not sync. To include both groups and their users, you must both assign the SCIM app to the group and push the group.

  1. Once synced, in Scalefusion you will see:

    • Under User Enrollment: individually provisioned users

    • Under User Groups: groups and their associated users

Troubleshooting

If you encounter issues with provisioning (for example API test fails, or users/groups not syncing), ensure:

  • The API Token and Base URL from Scalefusion were copied correctly into Okta.

  • The SCIM Connector on the Scalefusion side is configured and active.

  • Users or groups have been both assigned to the SCIM application and pushed from Okta.

  • Okta provisioning logs do not show errors such as authorization failure or missing permissions.

If you have any questions or are having issues with SCIM Integration, please leave us a message at support@scalefusion.com


Was this article helpful?