Provisioning users with Okta

If you use Okta as an IdP, you can provision users into Clumio directly using Okta Groups. 

Prerequisites

  • The individual setting up must have Super Admin access to Clumio and Admin access to the Okta portal.

  • The individual must be a part of a group that gets Super Admin access within Clumio.

Setup

To enable Super Admin and Admin access, do the following:  

  1. Log on to Okta.

  2. Go to Applications > Clumio.

  3. Under the Sign On settings tab, click Edit and expand Attributes.

  4. Add the following to the "Attribute statements" and the "Group Attribute statements" respectively:

    Name Format Filter Value
    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name Unspecified N/A user.firstName
    http://schemas.xmlsoap.org/claims/Group Unspecified Matches regex .*
  5. Under the Assignments tab, click Assign > Assign to Group and assign the app to the groups you want.

    Note

    At least one group must have the current user as a member, and this group will get Super Admin permissions within Clumio.

  6. Log on to the Clumio portal.

  7. Go to Settings > Access Management > Auto user provisioning.

  8. Click Get Started and type a rule name, select the conditions to apply the rule, give the group a name, select the Super Admin Role, and assign that role to an OU.

  9. Verify that the logged in user is a part of the group that is assigned the Super Admin role.

  10. After the first rule is created, click Enable Auto User Provisioning.

  11. To create more rules, click Create Auto User Provisioning Rule.

Once Auto User Provisioning is enabled, all users are evaluated according to the rules you created.

×

Loading...