SCIM provisioning
Use System for Cross-domain Identity Management to automate user and group provisioning from your IdP to Colabra.
Who can use this feature?
👤 By default, all Admins (but not Editors and Viewers).
🏢 Available on the Enterprise plan.
If you have SAML SSO enabled with a supported identity provider, you can contact us to get SCIM enabled for your workspace.
Once SCIM is enabled, you will not be able to manage users from within Colabra, and they will be kept up to date through your identity provider.
What you can do with SCIM
User provisioning and management:
Create and remove members in your organization.
Update a member's profile information.
Retrieve the members in your workspace.
Find members by name or email.
Group provisioning and management:
Create and remove groups in your organization.
Add and remove members in a group.
Retrieve the groups in your workspace.
Find groups by name.
Not supported:
Managing external collaborators (guests).
Configuration
Once SAML is configured, you will see the option to enable SCIM in Settings > Security.
Toggle the option to enable SCIM, and click "View configuration" to get your SCIM base connector URL and Bearer Auth token. Keep these values safe as you will need them to configure SCIM in your Identity provider.
In the Okta admin pages, open the Colabra application you have for SAML 2.0
In the General tab, click Edit and choose SCIM in the Provisioning section and Save
In the Provisioning tab, enter the SCIM Base connector URL you generated from Colabra
For the Unique identifier field for users section enter email
For Supported provisioning actions you can enable "Import New Users and Profile Updates", "Push New Users" and "Push Profile Updates." Push and Import for Groups are not supported at this time
For Authentication mode field, choose HTTP Header and enter your Bearer token generated from Colabra. You can now test the configuration and save
In OneLogin's Admin panel > Applications, click Add App
Search for the "SCIM Provisioner with SAML (SCIM v2 Enterprise, full SAML)" app and add
Click on the Configuration tab and add your SCIM base URL and Bearer token
Click on the Provisioning tab and Enable Provisioning
Save your App
In OneLogin's Admin panel > Applications, click Add App
Search for the "SCIM Provisioner with SAML (SCIM v2 Enterprise, full SAML)" app and add
Click on the Configuration tab and add your SCIM base URL and Bearer token
Click on the Provisioning tab and Enable Provisioning
Save your App
In OneLogin's Admin panel > Applications, click Add App
Search for the "SCIM Provisioner with SAML (SCIM v2 Enterprise, full SAML)" app and add
Click on the Configuration tab and add your SCIM base URL and Bearer token
Click on the Provisioning tab and Enable Provisioning
Save your App
FAQ
Last updated