> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.getunleash.io/provisioning/how-to-setup-provisioning-with-okta/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.getunleash.io/_mcp/server. # Set up Okta provisioning > Learn how to configure SCIM provisioning for Unleash using Okta to automatically manage user accounts and access. v6.1 Enterprise ## Unleash Configuration > **Info** > > Before you begin, ensure that you have a strategy in place to prevent [being locked out of all admin accounts](/support/troubleshooting#got-locked-out-of-an-admin-account-after-configuring-scim). ### Step 1: Navigate to Provisioning configuration First you'll need to log in to Unleash as an admin user. Navigate to the Single Sign-On section and select the "SCIM" tab. The SCIM API URL will be shown in this section, you'll need this to configure Okta later. ![Navigate to the SCIM Config](/_fern-img/350dbf92c4e4a1649a6202d22fd34f57d7978a8caa55268cdaf134b1074fad66.webp) ### Step 2: Enable Provisioning Enable SCIM by turning on the toggle and keep the token Unleash provides you for the Okta setup below. ![Enable the SCIM toggle](/_fern-img/822b2545b78eba3ebb85ae994508b427e0523a8f1f0576e8770d2aa2f45c912b.webp) ## Okta Configuration ### Step 1: Create an Application in Okta > **Info** > > If you already have SAML SSO configured for Unleash in Okta you can skip to the [next step](how-to-setup-provisioning-with-okta#step-2-enable-provisioning-in-your-okta-application). If you're planning on using [SAML for Unleash](/single-sign-on/how-to-add-sso-saml), do that first and skip to the next step. Note that if you're using OIDC SSO in Okta you still need to do this step. > > This step will create an empty Sign-On Application that will only be used for SCIM. **1) Navigate to "Admin -> Applications" and click the "Create App Integration" button.** ![Navigate to Create Application](/_fern-img/9d29b3c3c2178648656f79d3e93191d3d169736a12a8a965c50e4bb1788aa99c.webp) **2) Select SWA - Secure Web Authentication** ![Select Secure Web Application](/_fern-img/d5fa2fe15f6741e2bea468ca98eef8bd0f70834d9c7dd771c8da6b05202ee5bc.webp) **3) Fill in your App Name and App's login page URL** ![Setup Application Properties](/_fern-img/f5692c2b84465ec1f697551666c9e3b5c55a2589f3bf6096abfa0b7792d8a01b.webp) ### Step 2: Enable Provisioning in your Okta Application > **Info** > > If you already have a SAML application setup for Unleash you'll be modifying that application in this step. **Enable SCIM provisioning and save.** ![Enable SCIM](/_fern-img/c9d9d0d7e4a845a323b364046b47962aaa12eeca4347c1c0d1f732619c3d81f3.webp) ### Step 3: Connect Unleash **1) Navigate to the Provisioning tab** **2) Set the Unleash SCIM URL** This is provided by the Unleash UI in the [configuring Unleash](how-to-setup-provisioning-with-okta#step-1-navigate-to-provisioning-configuration) section. **2) Set email as the unique identifier** **3) Configure actions** Turn on "Push New Users", "Push Groups" and "Push Profile Updates". **4) Set authentication mode to "HTTP Header"** **5) Add your SCIM token** This was provided by the Unleash UI in the [configuring Unleash](how-to-setup-provisioning-with-okta#step-2-enable-provisioning) section. ![Connect Unleash](/_fern-img/c9d9d0d7e4a845a323b364046b47962aaa12eeca4347c1c0d1f732619c3d81f3.webp) ### Step 4: Configure Okta Provisioning Navigate to the "To App" tab. Turn on "Create Users", "Update User Attributes" and "Deactivate Users". Save your configuration. ![Configure Okta Provisioning](/_fern-img/b79d37490d62296f63a0e4f3f1b5f47239cfe0138498569a801bb0aedbea42e3.webp) ### Step 5: Configure Provisioning Properties **1) Set email** Set the email field to map to your login property. This is important and ensures that your SSO integration continues to work. **2) Remove unneeded properties** You should remove all unnecessary properties. This ensures that Okta will reach a steady state when synchronizing. The properties that you must retain are: * Username * Given name * Family name * Email * Primary email type * Display name ![Configure Provisioning Attributes](/_fern-img/f8d70ac43f1dbed8ddde0e7f1d390bac85bc1fcab1130843dfeed235a1462abc.webp) > Learn how to configure SCIM provisioning for Unleash using Okta to automatically manage user accounts and access.