Search Results :

×

Setup User Provisioning (SCIM) into Drupal with Okta


User Provisioning provides you with the ability to manage all the users at a central user management identity. Okta Provisioning service supports SCIM 2.0 protocol for automatic provisioning/de-provisioning. miniOrange User Provisioning and Sync module implement the SCIM endpoints to allow provisioning/de-provisioning of users into the Drupal site as and when any CRUD operation is performed in the central identity i.e. Okta.

Installation Steps


  • Download the module:
    composer require 'drupal/user_provisioning'
  • Navigate to Extend menu on your Drupal admin console and search for miniOrange User Provisioning using the search box.
  • Enable the module by checking the checkbox and click on Install button.
  • Configure the module at
    {BaseURL}/admin/config/people/user_provisioning/overview
  • Install the module:
    drush en user_provisioning
  • Clear the cache:
     drush cr
  • Configure the module at
    {BaseURL}/admin/config/people/user_provisioning/overview
  • Navigate to Extend menu on your Drupal admin console and click on Install new module button.
  • Install the Drupal User Provisioning and Sync module either by downloading the zip or from the URL of the package (tar/zip).
  • Click on Enable newly added modules.
  • Enable this module by checking the checkbox and click on Install button.
  • Configure the module at
    {BaseURL}/admin/config/people/user_provisioning/overview

Configure Drupal as SCIM Server:

  • Once the module is installed, navigate to the Configuration tab of the Drupal site and select miniOrange User Provisioning.
  • miniOrang User Provisioning and Sync module installation steps
  • Navigate to the User Provisioning tab of the module and click on the Configure button under the Changes from Provider to Drupal (SCIM Server) section.
  • Azure-AD-click-on-configure-button

Create Application in Okta:

  • Log into the Okta portal.
  • From the left panel, select Applications under the Applications dropdown.
  • Okta-SCIM-Client-navigate-to-application
  • Click on the Browse App Catalog button.
  • Okta-SCIM-Client-click-browse-api-cataloge
  • Search for the SCIM Bearer Token and select SCIM 2.0 Test App (OAuth Bearer Token).
  • Okta-SCIM-Client-search-SCIM-Bearer-Token
  • Click on the Add Integration button.
  • Okta-SCIM-Client-click-add-integration
  • In General settings, enter the application name under the Application label text field and click on the Next button.
  • Okta-SCIM-Client-enter-application-name
  • Under the Sign-On Options, scroll down and click on the Done button.
  • Okta-SCIM-Client-click-done-saml-application

Configure Okta as SCIM Client:

  • Navigate to the Provisioning tab and click on the Configure API Integration button.
  • Okta-SCIM-Client-click-configre-api-integration
  • Check the Enable API integration checkbox.
  • Okta-SCIM-Client-enable-api-integration-checkbox
  • Navigate to the Drupal site.
  • Under Configure Drupal as a SCIM Server section, copy the SCIM Base URL.
  • Okta-SCIM-Client-copy-scim-base-url
  • Navigate back to the Okta dashboard and paste the copied SCIM Base URL under the SCIM 2.0 Base Url text field.
  • /Okta-SCIM-Client-Paste-SCIM-base-url
  • Navigate to the Drupal site and copy the SCIM Bearer Token.
  • Okta-copy-SCIM-bearer-token
  • Navigate back to the Okta dashboard and paste the copied SCIM Bearer Token under the OAuth Bearer Token text field.
  • Okta-SCIM-Client-Paste-SCIM-bearer-token
  • Click on the Test API Credentials button.
  • Okta-SCIM-Client-click-test-api-integration
  • Once the Test is successful, click on the Save button.
  • Okta-SCIM-Client-click-save-after-test-connection

Select the Operations allowed:

  • Navigate to the To App section from the left panel of the Provisioning tab.
  • Okta-SCIM-Client-navigate-to-app
  • Click on the Edit button next to the Provisioning to App.
  • Okta-SCIM-Client-click-edit-button
  • Enable the operations (Create/Update/Deactivate/Delete) that will be allowed for provisioning.
  • Okta-SCIM-Client-select-operations
  • Click on the Save button.
  • Okta-SCIM-Client-click-save-after-operations-select

Assign users to the application:

  • Navigate to the Assignments tab and click on Assign. From the dropdown, select Assign to People.
  • Okta-SCIM-Client-click-assign-to-people
  • Search for the user(s) to be assigned and click on the Assign button.
  • Okta-SCIM-Client-search-user-click-assign
  • Fill in or Confirm the user details and click on Save and Go Back button.
  • Okta-SCIM-Client-verify-user-information
  • Once the user(s) is assigned, click on the Done button.
  • Okta-SCIM-Client-click-done-button-assigned
  • The user has been successfully assigned to the Okta Application.
  • Okta-SCIM-Client-user-succesfully-assigned
  • Let’s check if the user is provisioned to the Drupal site. Navigate to the Drupal site and click on the People tab from the top navigation panel. As per the following screenshot, the user has been successfully created on the Drupal site.
  • Okta-SCIM-Client-user-successfully-provisioned

Congratulations, you have successfully set up Drupal as the SCIM server and Okta as the SCIM client.

If the Provision was not successful, please contact us at drupalsupport@xecurify.com. Please send the screenshot of the error window, and we will assist you in resolving the issue and guiding you through the setup.

Additional Features:

 Case Studies
miniOrange has successfully catered to the use cases of 400+ trusted customers with its highly flexible/customizable Drupal solutions. Feel free to check out some of our unique case studies using this link.
 Other Solutions
Feel free to explore other Drupal solutions that we offer here. The popular solutions used by our trusted customers include 2FA, SSO, Website Security. 
  24*7 Active Support
The Drupal developers at miniOrange offer quick and active support for your queries. We can assist you from choosing the best solution for your use case to deploying and maintaining the solution.
Hello there!

Need Help? We are right here!

support
Contact miniOrange Support
success

Thanks for your inquiry.

If you dont hear from us within 24 hours, please feel free to send a follow up email to info@xecurify.com