Enable Okta SAML and SCIM in airfocus

Written by:  Morgan T
Last updated:  

Learn how to use SAML single sign-on (SSO) and SCIM for your organization's user identity management by granting airfocus access to our identity provider (IdP). In this article, we will go through set up recommendations for Okta.

This functionality is available to all customers with an airfocus Enterprise plan subscription.

Introduction to SAML SSO and SCIM

Integrating airfocus with Okta enables your users to authenticate using SAML single sign-on through Okta. Single sign-on allows the admin of your airfocus team to determine who has access to airfocus via your existing identity provider solution (IdP). Your team members will be able to seamlessly access airfocus as long as they’re logged in to your organization’s IdP.

Furthermore, our SCIM integration allows admins to create users and provision and deprovision users within Okta itself, without having to sign in to airfocus.

Note: When accessing airfocus for the first time, a member with the contributor role will be offered (pre-filled with their full name and email address), confirmed and added to your team.

Okta SAML setup

  1. Log in to Okta.
  2. Navigate to the Applications page.
  3. Click Create App Integration to create a new SAML application in Okta.
  4. Select SAML 2.0 as the sign-in method.
  5. Click Next.
  6. Type in a name for the airfocus app you're creating.
  7. Click Next.
    set-up-okta-scim-saml-and-sso-4.png
  8. Configure the following values: 
    • Single sign on URL: https://auth.airfocus.com/login/sso/callback/saml  
    • Audience URI (SP Entity ID): https://airfocus.com 
      • Please note, if you are located in the US or APAC region and your account was created after September 2025 replace "airfocus.com" in the above URLs with "airfocus.app".
        set-up-okta-scim-saml-and-sso-5.png
  9. Scroll to the Attribute Statements section and configure the following values:
    • email = user.email
    • givenName = user.firstName
    • surname = user.lastName
      set-up-okta-scim-saml-and-sso-6.png
  10. Scroll to the bottom of the page and click Next.
  11. Check the box on the Feedback page that says "This is an internal app that we have created."
  12. Click Finish.
    set-up-okta-scim-saml-and-sso-8.png
  13. On your newly created airfocus app in Okta, select the Assignments tab.
  14. Ensure that you have added at least yourself as an allowed user to the application.
    • If you haven't yet, use the "Assign" feature to do so.
  15. Then, select the Sign On tab.
  16.  On the far-right hand side, scroll if needed and select the View SAML setup instructions button. 
  17. Take note of the three values there.
    set-up-okta-scim-saml-and-sso-12.png
  18. Log in to airfocus.
  19. Navigate to the airfocus SAML configuration page. 
  20. Under "Provider", select Set up SAML SSO.
    set-up-okta-scim-saml-and-sso-13.png
  21. Navigate to “Team settings". 
  22. Select the Security/SSO tab.
  23. Configure the following values by copy and pasting from the step 17 above:
    • IDP Single sign-on URL: {first value from the step above}
    • IDP Issuer: {second value from the step above}
    • IDP X.509 Certificate: {third value from the step above}
      set-up-okta-scim-saml-and-sso-14.png
  24. Click Test.
  25. You should be redirected to the Okta Login and from there back to airfocus and see a confirmation that everything has worked.
    set-up-okta-scim-saml-and-sso-15.png
  26. Optionally, you can enforce the SSO login across the team by checking the checkbox for "Enforce Single sign-on".
    • Once enabled, members can only log in using SAML SSO. Email and password log in will be disabled.
      set-up-okta-scim-saml-and-sso-17.png
  27. Select Apply.
     

Okta SCIM setup

Note: airfocus doesn’t currently support syncing passwords from identity providers. Any SCIM provisioned users will need to sign into airfocus via SAML SSO to access their account.

To set up Okta SCIM for your account:

  1. Log in to Okta. 
  2. Navigate to the airfocus app that you created in the Okta SAML setup instructions above.
  3. Select the General tab of your custom Okta app.
  4. Enter edit mode of your app settings.
  5. Under provisioning, select "SCIM".
  6. Click Save. Leave this tab open, as we will come back to it in a few steps.
  7. In a new tab, log in to airfocus.
  8. Navigate to “Team settings". 
  9. Select the Security/SSO tab.
  10. Click Enable SCIM.
  11. Note the base URL, team ID, and generated token.
    set-up-okta-scim-saml-and-sso-19.png
  12. Navigate back to your Okta tab.
  13. Select the Provisioning tab of your application in Okta.
  14. Click Edit to the far-right of "SCIM Connection".
  15. Configure the following values:
    • SCIM connector base URL: the base URL listed in the SCIM user management page
    • Unique identifier field for users: the field userName
    • Provisioning actions: check all boxes
    • Authentication mode: HTTP Header Header
    • Authorization Bearer: the SCIM token that was just generated
      configure-values-for-scim-app-in-okta.png
  16. Click Test connector configuration to confirm that it works.
  17. Select Save.
  18. On the Provisioning tab still, click Edit to the right of "Provisioning to app".
  19. Check the boxes to enable "Create Users", "Update User Attributes", and "Deactivate Users".
  20. Click Save.
    set-up-okta-scim-saml-and-sso-23.png

Note: If you need to edit the email of a user in Okta and have the update apply properly to airfocus, make sure to edit the "email" field rather than the "username" field. Editing the username field will create a new user in airfocus (this is a known Okta limitation). 

SCIM groups

To create a group:

  1. Ensure you’ve enabled SCIM groups in your Okta application (done in Step 5 of the SCIM Setup section above).
  2. Go to the Directory Groups tab in Okta.
  3. Click Add group.
  4. Fill out a name and optionally a description.
  5. Select Save.
  6. Select the group in the Directory Groups tab in Okta.
  7. Within the group, navigate to the Applications tab.
  8. Click Assign applications.
  9. Select Assign to the right of "airfocus".
  10. Click Save and Go Back.
  11. Click Done.

Assign people from the SCIM group in Okta, using one of the following methods:

  • From the "People" tab, click Assign people and do so individually.
  • From the "Groups" tab, type in the name of Okta groups you'd like to assign all together.

Once you've assigned people to your SCIM group, follow these steps to sync it with airfocus:

  1. Navigate to your airfocus application in Okta.
  2. Select the Push Groups tab.
  3. Select the Push Groups dropdown.
  4. From the dropdown, select Find groups by name.
  5. Type in the name of your group and select it. 
  6. Click Save.

It should now show up as “Active” in both Okta and airfocus.

set-up-okta-scim-saml-and-sso-34.png
set-up-okta-scim-saml-and-sso-35.png

User roles

Airfocus has three user roles: Contributor, Editor, and Administrator. These roles can be provisioned through Okta, but it takes a little bit of setup as Okta doesn't provide roles by default. In order to work, the roles must be created for Okta user profiles, then for user profiles of the airfocus app in Okta, then mapped to each other.

Note: If roles are not set up, each user will automatically be assigned the “Contributor” role in airfocus. This section is only necessary if you wish to provision user roles using Okta.

To set up user roles:

  1. Log in to Okta.
  2. Navigate to Directory. 
  3. From the dropdown menu, select Profile Editor.
  4. Click on the User (default) profile for Okta.
  5. Select Add Attribute.
  6. Create the contributor role with the following details. These values are case sensitive.
    • Data type: boolean
    • Display name: Contributor
    • Variable name: contributor
    • Keep the User permission as “Read Only”
  7. Click Save and Add Another.
  8. Create the Editor role with the following details. These values are case sensitive.
    • Data type: boolean
    • Display name: Editor
    • Variable name: editor
  9. Click Save and Add Another.
  10. Create the Administrator role with the following details. These values are case sensitive.
    • Data type: boolean
    • Display name: Administrator
    • Variable name: administrator
  11. Click Save.
  12. Navigate back to the Profile Editor page.
  13. Select the airfocus User profile.
  14. Select Add Attribute.
  15. Create the contributor role with the following details. These values are case sensitive.
    • Data type: string
    • Display name: Contributor
    • Variable name: contributor
    • External name: roles.^[type=='contributor'].value
    • External namespace: urn:ietf:params:scim:schemas:core:2.0:User
  16. Click Save and Add Another.
  17. Create the Editor role with the following details. These values are case sensitive.
    • Data type: string
    • Display name: Editor
    • Variable name: editor
    • External name: roles.^[type=='editor'].value
    • External namespace: urn:ietf:params:scim:schemas:core:2.0:User
  18. Click Save and Add Another.
  19. Create the Administrator role with the following details. These values are case sensitive.
    • Data type: string
    • Display name: Administrator
    • Variable name: administrator
    • External name: roles.^[type=='admin'].value
    • External namespace: urn:ietf:params:scim:schemas:core:2.0:User
  20. Click Save.
  21. Under "Attributes", select Mappings.
  22. Select Okta User to airfocus at the top of the page.
  23. Scroll to the bottom and find the rows with the new role attributes in the right hand column.
    • To the left of “contributor”, enter: (user.contributor == true) ? 'contributor' : ''
    • To the left of “editor”, enter: (user.editor == true) ? 'editor' : ''
    • To the left of “administrator”, enter: (user.administrator == true) ? 'admin' : ''
      • Note: The '' at the end of each statement are two single quotes, not one double quote.
        okta-user-to-airfocus-role-attributes.png
  24. Click Save Mappings.
  25. Select Apply updates.

To assign user roles to a user, follow these steps:

  1. Log in to Okta.
  2. Navigate to the Directory.
  3. From the dropdown menu, select People.
  4. Select the user you'd like to assign a user role to.
  5. Click the Profile tab.
  6. Click Edit in the top-right corner.
  7. Assign the applicable user role(s).
    • If a user has multiple roles assigned to them in Okta, airfocus will use the highest role provided (Administrator being the highest, followed by Editor, followed by Contributor).
    • "Undefined" and "false" are effectively the same. It does not matter which one you choose if you don't want the person to have that role. If every role is set to undefined, the user will have the “Contributor” role by default.
  8. Select Save.

You should now see the user’s role reflected in airfocus.
okta-user-role-reflected-in-airfocus.png

Give feedback on this article

Have feedback about this article? Tell us about your experience here.

Did you find what you were looking for?

Still have a question or want to share what you have learned? Visit our Community   to get help and collaborate with others.