diff --git a/docs/sources/setup-grafana/configure-security/configure-scim-provisioning/configure-scim-with-okta/_index.md b/docs/sources/setup-grafana/configure-security/configure-scim-provisioning/configure-scim-with-okta/_index.md index 4d044a93f05..f7d575e8ecb 100644 --- a/docs/sources/setup-grafana/configure-security/configure-scim-provisioning/configure-scim-with-okta/_index.md +++ b/docs/sources/setup-grafana/configure-security/configure-scim-provisioning/configure-scim-with-okta/_index.md @@ -37,15 +37,15 @@ Before configuring SCIM with Okta, ensure you have: - Grafana Enterprise or Grafana Cloud Advanced - Admin access to both Grafana and Okta -- [SAML authentication configured with Okta](../../configure-authentication/saml/#set-up-saml-with-okta) +- [SAML authentication configured with Okta](../../configure-authentication/saml/configure-saml-with-okta/) - SCIM feature enabled in Grafana {{< admonition type="note" >}} **Important SAML and SCIM Configuration:** When using SAML for authentication alongside SCIM provisioning with Okta, it is crucial to correctly align user identifiers. -For detailed information on why this is critical for security and how to configure it, refer to the main [SCIM provisioning documentation (../\_index.md#critical-aligning-saml-user-id-with-scim-externalid)](../_index.md#critical-aligning-saml-user-id-with-scim-externalid). +For detailed information on why this is critical for security and how to configure it, refer to the main [SCIM provisioning documentation](../). -Ensure your Okta SAML application is configured to send a stable, unique identifier (that will map to the Grafana SCIM `externalId`) as a SAML claim. Then, configure the Grafana SAML settings to use this claim. For general Okta SAML setup, refer to [Set up SAML with Okta](../../configure-authentication/saml/#set-up-saml-with-okta). +Ensure your Okta SAML application is configured to send a stable, unique identifier (that will map to the Grafana SCIM `externalId`) as a SAML claim. Then, configure the Grafana SAML settings to use this claim. For general Okta SAML setup, refer to [Set up SAML with Okta](../../configure-authentication/saml/configure-saml-with-okta/). {{< /admonition >}} ## Configure SCIM in Grafana @@ -54,9 +54,10 @@ To enable SCIM provisioning in Grafana, create a service account and generate an ### Create a service account -1. Navigate to **Administration > User Access > Service accounts** -2. Click **Add new service account** -3. Create a new access token and save it securely +1. Navigate to **Administration > Users and access > Service accounts** +2. Click **Add service account** +3. Create a new service account with Admin role +4. Create a new token for the newly created service account and save it securely - This token will be used in the Okta configuration ## Configure SCIM in Okta @@ -71,35 +72,40 @@ Configure both SAML authentication and SCIM provisioning in Okta to enable autom ### Configure provisioning settings -In the **To App** tab, enable: - -- Create Users -- Update User Attributes -- Deactivate Users +To enable user provisioning through SCIM, configure the SCIM integration settings in Grafana by specifying the connector URL, authentication mode, and supported provisioning actions. Follow these steps to complete the integration. ### Configure SCIM integration In the **Integration** tab, configure: - **SCIM Connector base URL:** - ``` - https://{your-grafana-domain}/apis/scim.grafana.app/v0alpha1/namespaces/stacks-{stack-id} - ``` - Replace `{your-grafana-domain}` with your Grafana instance's domain (e.g., `your-stack.grafana.net` for Grafana Cloud or `grafana.yourcompany.com` for self-hosted instances). Replace `{stack-id}` with your Grafana Cloud stack ID. + - For Grafana Cloud instances: + ``` + https://{stack-name}.grafana.net/apis/scim.grafana.app/v0alpha1/namespaces/stacks-{stack-id} + ``` + Replace `{stack-name}` and `{stack-id}` with your Grafana Cloud stack name and ID. + - For self-hosted instances: + ``` + https://{your-grafana-domain}/apis/scim.grafana.app/v0alpha1/namespaces/default + ``` + Replace `{your-grafana-domain}` with your Grafana instance's domain (e.g., `grafana.yourcompany.com`). - **Unique identifier field:** userName - **Supported provisioning actions:** - Import New Users and Profile Updates - Push New Users - Push Profile Updates +- **Authentication Mode:** HTTP Header +- **Authorization:** Bearer {your-grafana-service-account-token} +- Click **Test Connector Configuration** and then save the configuration -## Test the integration +In the **To App** tab, enable: + +- Create Users +- Update User Attributes +- Deactivate Users After completing the configuration: 1. Test the SCIM connector in Okta 2. Assign a test user to the application 3. Verify the user is provisioned in Grafana - -## Troubleshooting - -For common issues and solutions when working with SCIM provisioning, refer to the [SCIM troubleshooting guide](../troubleshooting/).