Configure iGrafx for automatic user provisioning using Okta
Enable automatic user provisioning and de-provisioning from Okta via the System for Cross-domain Identity Management (SCIM). SCIM provisioning is available in the iGrafx Cloud offering with the Process DesignProcess Design The discipline of explicitly modeling business processes to document, analyze, and optimize them. In Process360 Live, process design is the authoring side that complements mining's data-driven view. module only.
Prerequisites
- An Okta tenant.
- Admin access to the iGrafx Process DesignProcess Design The discipline of explicitly modeling business processes to document, analyze, and optimize them. In Process360 Live, process design is the authoring side that complements mining's data-driven view. module, with the Manage user directories server permission.
Steps
Create the SCIM directory in iGrafx Process Design
- Sign in to iGrafx Process360 LiveProcess360 Live iGrafx's cloud platform for end-to-end process management — combining process design, mining, simulation, and automation in a single environment. Process DesignProcess Design The discipline of explicitly modeling business processes to document, analyze, and optimize them. In Process360 Live, process design is the authoring side that complements mining's data-driven view..
- Go to Administration → User Management → Directories.
- Click Add new directory, enter a name, and select directory type SCIM.
- Click Create directory.
- Record your SCIM secret token and SCIM Tenant URL for later. (To view the URL or generate a new token, click Edit on the SCIM directory, then Generate new token.)
Create the app integration
Okta requires provisioning to be paired with a SAMLSAML An XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider. Process360 Live supports SAML 2.0 for SSO. 2.0 or Secure Web Authentication (SWA) app integration. If you already have a SAMLSAML An XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider. Process360 Live supports SAML 2.0 for SSO. integration, skip to Enable provisioning.
- In the Okta Admin Portal, go to Applications → Applications → Create App Integration.
- Select SAMLSAML An XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider. Process360 Live supports SAML 2.0 for SSO. 2.0 and click Next.
- Fill in the General settings and click Next.
- Configure your iGrafx Process360 LiveProcess360 Live iGrafx's cloud platform for end-to-end process management — combining process design, mining, simulation, and automation in a single environment. SAMLSAML An XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider. Process360 Live supports SAML 2.0 for SSO. integration and click Next.
- Optionally complete the Feedback section.
Enable provisioning
- On the General tab, enable Provisioning.
- On the new Provisioning tab, click Edit and set:
- SCIM connector base URL — your SCIM Tenant URL.
- Unique identifier field for users —
userName. - Supported provisioning actions — select all except Import Groups.
- Authentication Mode — HTTP Header.
- Authorization — your SCIM secret token.
- On the To App tab, click Edit and enable Create Users, Update User Attributes, and Deactivate Users.
- Optional — to import users created in iGrafx before provisioning was enabled: on the Import tab, click Import Now, then select the users to manage through Okta.
Provision users and groups
- Users — on the Assignments tab, click Assign. Assign to People provisions the selected users; Assign to Groups provisions all users in a group. (Removing a user from the group or app disables their iGrafx user; disabled users don't consume a license.)
- Groups — make sure the group is on the Assignments tab, then on the Push Groups tab click Push Groups and find groups by name or by rule. The selected groups are created in iGrafx with their members.