Before you begin
You’ll need:- A Windmill SAML app in Okta with SSO active in Windmill. See Set up SAML SSO.
- The Tenant URL and Secret token from Windmill. In Settings > Security, select Set up SCIM, then Generate token. See Set up SCIM provisioning.
- Super Admin or Application Admin access in Okta.
Turn on provisioning
Open the Windmill app in Okta
Enable SCIM on the app
Connect Okta to Windmill
Turn on the provisioning actions
Map the standard attributes
The To App section of the Provisioning tab lists the attribute mappings Okta sends to Windmill. Okta’s SCIM template includes most of the fields Windmill supports. Confirm these mappings and remove any you don’t want to send.Add the Windmill extension attributes
Job level, start date, pronouns, and gender live in the Windmill extension schema. Okta doesn’t include them by default. Add each one to the app’s user profile in the Profile Editor, then map an Okta attribute to it.Open the app's profile in the Profile Editor
Add an attribute
Map an Okta attribute to each new attribute
user.jobLevel or user.startDate. Set the mapping to apply on Create and update.Select Save Mappings, then Apply updates now to push the values to existing assigned users.jobLevel. Then populate it from your HR system or by hand. For start date, use the YYYY-MM-DD format.Map the manager
Windmill reads the manager from the enterprise extension attributemanager.value. In most Okta SCIM apps this is the Manager value attribute (variable name managerValue). If your app doesn’t have it, add it in the Profile Editor with external name manager.value and external namespace urn:ietf:params:scim:schemas:extension:enterprise:2.0:User.
Map it to an Okta attribute that identifies the manager by work email or Okta login, for example user.managerId when your directory stores the manager’s login there. Windmill resolves the manager by SCIM ID, external ID, username, or work email. See Manager references.
Both the manager and the report must be assigned to the Windmill app. If the manager hasn’t been provisioned yet, Windmill keeps the reference and applies it once the manager exists.
Assign people
Okta provisions a person when you assign the Windmill app to them.Open the Assignments tab
Assign people or groups
Check Windmill
Push groups
To bring Okta groups into Windmill Groups, use the Push Groups tab in the Windmill app. Windmill creates a group with the same name and keeps its membership in sync. See Sync groups from your identity provider for the steps and how synced groups behave in Windmill.Set the field sources in Windmill
Windmill stores every value Okta sends. It writes a value to an employee’s profile only when SCIM is the source for that field. Fields with no source are claimed by SCIM automatically. Fields owned by another system, like job level from your HRIS (Human Resources Information System), keep the other system’s value until you switch the source. To have Okta manage a field, open Settings > Org Chart, open Company defaults, and set the field’s source to SCIM. Windmill applies the latest values Okta sent within a few minutes. See How SCIM works with field sources.Verify the setup
- In Windmill, the SCIM card in Settings > Security shows Active and a recent Last sync time.
- Open an assigned employee in Settings > Org Chart. The Sources tab shows SCIM for the fields Okta manages, and the Info tab shows the values.
- In Okta, Reports > System Log shows the push events. Filter by your Windmill app to see any errors.
FAQs
Test Connector Configuration fails.
Test Connector Configuration fails.
Okta reports an error that says SCIM provisioning is paused.
Okta reports an error that says SCIM provisioning is paused.
Job level, start date, pronouns, or gender aren't reaching Windmill.
Job level, start date, pronouns, or gender aren't reaching Windmill.
urn:ietf:params:scim:schemas:extension:gowindmill:2.0:User. The attribute must be mapped in Okta User to [app] mappings and applied on Create and update. And Update User Attributes must be on under Provisioning > To App. Then check the field’s source in Windmill under Settings > Org Chart.The manager isn't set in Windmill.
The manager isn't set in Windmill.
Okta shows a 409 conflict for a user.
Okta shows a 409 conflict for a user.
Do assigned people get an invite email or Slack message?
Do assigned people get an invite email or Slack message?