Customers using Single Sign-on also have access to user provisioning & de-provisioning via dscout’s implementation of industry standard SCIM API. This feature allows customers to use their identity provider (IdP) to securely create dscout accounts for their users, keep their information (name, email, etc.) in sync, and revoke access to dscout (de-provision) .

Your dscout account owner and/or IdP administrator will manage access to dscout. When your dscout account is ready, they will provide login instructions.


Supported features

  • Create users in dscout
  • Update users in dscout
    • Supported attributes are limited to:
      • userName maps to dscout user’s email address
      • name.givenName
      • name.familyName
      • title
      • timezone
  • Deactiviate users in dscout

Requirements

  • A dscout account in the Select or Select+ subscription tier
  • Must be the account owner of your dscout account
  • Administrator rights in your organization’s Okta account
  • An existing Okta SSO configuration

Configuration Steps

In dscout

  1. As the account owner, visit your account’s settings page and select SSO and user provisioning.
  2. Under the User provisioning (SCIM), click the Generate API key button to name and generate your key.
  3. Leave this tab open while you continue the configuration in Okta.

Screenshot 2024-05-31 at 10.52.54 AM (1).png

In Okta

Log in to your Okta admin portal and complete the following steps:

  1. Under the Applications tab, navigate to the dscout application.
  2. On the Sign On tab, select Email for the Application username format.

image003.png

3. Select the Provisioning tab and then select Integration in the sub navigation. Toggle Enable API Integration, you will need to type Bearer and then paste your copied API Token into the input    field (ex. Bearer MY-COPIED-TOKEN-VALUE), test your credentials and then click Save.

Screenshot 2024-07-08 at 3.26.55 PM.png

 

4. While still on the Provisioning tab, click on the To App tab and click Edit. Then enable the SCIM functionality you’d like to support. It’s recommended that you toggle all three options. Then            click Save.

 

Screenshot 2024-07-08 at 3.30.44 PM.png

5. SCIM provisioning has now been enabled. Assigning new users to dscout in Okta will automatically create their account and revoking access will automatically deactivate their account.

6. Recommended - In dscout, we strongly recommend that after you’ve tested the integration, you switch your dscout account to SCIM-only. Once this setting is on, you will no longer be able to add or remove users from the platform without first provisioning or de-provisioning them in your IdP.

 

Screenshot 2024-07-08 at 3.33.43 PM.png

Known Issues/Troubleshooting

If you have questions or difficulties with your dscout + Okta SCIM integration, please contact our support team at help@dscout.com.

FAQs

After enabled SCIM, will all of my current users assigned to the application be migrated to dscout?

No. Only users updated or added after SCIM is enabled are added.

I’m an existing customer and have already added many users in dscout. How do I sync them with my identity provider?

In your identity provider, simply assign all relevant users to dscout. If the user does not already exist in dscout, their account will be provisioned. If the user was previously added manually in dscout, this process with sync those records (please confirm that user’s email in your identity provider matches the user’s email on their existing dscout account).

Will newly provisioned users receive a notification or invite from dscout?

No. dscout will not notify new users upon provisioning. We leave their notification in your hands after you’ve made any necessary adjustments to their role and/or added them to any workspaces or projects.

I deprovisioned a user from dscout in my identity provider, but they are still showing up in dscout.

Our SCIM API accepts “deactivation” requests from your identity provider, but we do not delete the user from your account. Instead, we mark them as “deprovisioned” and disallow the user from accessing dscout. You (or your account owner) can login to dscout once the user is deactivated and remove them.

How can I learn more about SCIM?

There are many good references on the internet. Here are a few:

Was this article helpful?

0 out of 0 found this helpful
Have more questions? Submit a request