Connect Okta to Trustmi using SCIM 2.0 to create and update user accounts, and deactivate or reactivate users when their access changes. This guide covers user provisioning only. Group Push, group import, password synchronization, and user schema import are not covered.
Before you start
- An Okta administrator account with permission to manage applications and provisioning.
- A Trustmi administrator account for the intended organization, with access to Settings → Authentication → SCIM Provisioning and permission to create SCIM tokens. If the page is missing or token controls are disabled, contact your Trustmi administrator or Support.
- A dedicated test user. Do not test deactivation with an existing employee or business-critical account.
SCIM is not SSO. SCIM manages user accounts. SSO controls how users sign in and must be configured separately. Enabling SCIM does not configure SSO or automatically grant Trustmi roles.
1. Prepare SCIM access in Trustmi
- Sign in to the correct Trustmi organization. Open Settings → Authentication → SCIM Provisioning.
- Enable SCIM provisioning if it is not already enabled and this change has been approved for your organization.
- Copy the Endpoint URL shown on the page. Use the endpoint for the intended environment. The SCIM base URL ends in
/scim/v2; do not append/Usersor/Groups. - If no active token exists, select Create Token. Copy the full token immediately and store it in an approved secrets manager. The secret is shown only once.
If a token already exists: check which integrations use it before changing anything. The Token ID shown in Trustmi is metadata, not the bearer-token secret. If the secret is unavailable, coordinate a replacement with the integration owner. Revoking a token stops every connection that uses it.
2. Add the Okta application
Use the Trustmi application made available to your organization. If a catalog application is not yet available, an administrator can use SCIM 2.0 Test App (OAuth Bearer Token) for a controlled setup agreed with Trustmi. Using this test application does not mean that Trustmi is published or certified in the Okta Integration Network.
- In the Okta Admin Console, open Applications → Applications → Browse App Catalog.
- Find the approved application and select Add Integration. Use a label that clearly distinguishes production from staging.
- Complete setup without assigning existing users or groups.
- Open Provisioning → Integration and select Configure API Integration.
3. Configure and test API credentials
| Okta setting | Value |
|---|---|
| Enable API integration | Enabled |
| SCIM 2.0 Base URL | The Endpoint URL copied from Trustmi |
| OAuth Bearer Token | The full SCIM-token secret, not its Token ID |
- Enter the base URL and token. Paste only the token into the token field; do not add the word
Bearer. - Select Test API Credentials. Resolve any error before continuing.
- Review provisioning and import options before selecting Save. Saving can enable synchronization.
A successful credential test verifies connectivity and authentication. It does not prove that user creation, updates, or deactivation work end to end.
Group options: do not enable Group Push or group import as part of this Users-only setup. Some test applications show group options by default. Review these with your integration owner. Do not change an existing integration merely to match this guide: if Okta warns that a change will delete application groups, stop and review the impact before saving.
4. Enable user provisioning and review mappings
Under Provisioning → To App → Edit, enable the capabilities approved for your rollout: Create Users, Update User Attributes, and Deactivate Users. Leave password synchronization disabled; Trustmi SCIM does not support password changes.
| SCIM attribute | Trustmi value | Configuration note |
|---|---|---|
| userName | User email | Use the email address as the application username. |
| emails (primary) | User email | Must match userName. |
| name.givenName / name.familyName | First / last name | Use the corresponding Okta profile fields. |
| active | Active / inactive state | Managed by provisioning and deactivation. |
| title | Job title | Optional, where offered by the application profile. |
| Enterprise department / division | Department / division | Optional; use the SCIM Enterprise User extension mapping. |
Do not assume email renames are supported. Coordinate identity changes with Trustmi Support. Manage Trustmi roles, permissions, and organizational-unit access in Portal User Management; these are not granted by the profile mappings above.
5. Validate with one dedicated test user
- Assign only the dedicated test user to the Okta application. Confirm that the user appears in Trustmi User Management with the intended email and profile.
- Update the test user's first or last name in Okta and verify the corresponding Trustmi profile change.
- Verify the intended Trustmi role and organizational-unit access separately. A provisioned account alone does not prove that access is correct.
- Only after approval for this test, unassign or deactivate the test user in Okta. Confirm that Trustmi marks the user inactive. This is an access-revocation test, not a physical-data deletion procedure.
- Review Okta provisioning tasks and the System Log for failures. Validate reactivation with the same test identity before expanding the rollout.
Do not assign all employees until these checks pass. Keep existing user and group assignments unchanged during initial validation.
Troubleshooting
| Symptom | What to check |
|---|---|
| SCIM page is missing / access denied | Correct organization, feature availability, SCIM-settings permission, and token-management permission. |
| 401 Unauthorized | Full token secret, correct environment, expiry/revocation, and no extra Bearer prefix in Okta's token field. |
| 403 Forbidden | SCIM enablement and whether the organization is active. Contact your administrator or Support. |
| 409 Conflict | An existing identity. Review the existing record; do not delete it to resolve the error. |
| 400 Bad Request | Username/email consistency and supported profile mappings or PATCH attributes. |
| 404 Not Found | Base URL, resource ID, environment, and organization scope. |
| Credentials pass but provisioning fails | Assignments, To App settings, profile mappings, and the failed Okta provisioning task. |
When contacting Support, provide the environment, timestamp, operation, HTTP status, and a sanitized Okta System Log event or task reference. Never include tokens, passwords, reset links, or an unredacted request. Contact support@trustmi.ai if you need assistance.
Security and maintenance
- Treat the SCIM token as an administrative credential for its Trustmi organization. Never place it in screenshots, tickets, email, or this article.
- Coordinate token rotation with all integration owners. Update Okta, retest credentials, save, and validate provisioning after replacement.
- Disabling SCIM or revoking its token stops synchronization; it is not a substitute for deactivating an individual user.
- Use a separate guide and an explicitly approved rollout for group provisioning. This guide does not cover Group Push, group import, physical OU deletion, password synchronization, or user schema import.
Comments
0 comments
Please sign in to leave a comment.