Netskope and Okta SCIM Provisioning

Netskope and Okta SCIM Provisioning

This guide explains how to set up and install the Netskope User Enrollment within Okta. This configuration allows users to enroll their endpoints into their tenant via SAML, and enables provisioning and deprovisioning via SCIM.

The Netskope User Enrollment app allows you to easily provision users and user groups using Okta. Netskope supports the following provisioning features:

  • Push New Users and User Groups

When a user or user group is created in Okta, or a new user or user group is created in AD and uploaded to Okta, the user is automatically provisioned in the Netskope tenant.

  • Push User Deactivation
  • Reactivate user

When a user existing in Okta and provisioned in the Netskope tenant is deactivated by Okta, the user is deactivated in the Netskope tenant as well.

A user in the Netskope tenant and identified by the same user-id in Okta, or a user that was created and provisioned in the Netskope tenant by Okta is activated, the user is reactivated in the Netskope tenant.


  • An Okta admin account with console access.
  • The SCIM Server URL and OAuth Token: This is required to establish connection between your Okta account and Netskope cloud.

Configuring Okta for the Netskope User Enrollment

This document explains how you can quickly integrate with Okta to provision users in the Netskope cloud. To integrate Okta to the Netskope cloud, you will need:

  1. An admin account with access to the Okta admin console.
  2. Create a SCIM 2.0 app in the Okta admin console.
  3. Configure Netskope SCIM app with sign-on and user-attribute options.
  4. Assign users to the Netskope SCIM app.
  5. Log in to your Netskope Tenant and go to Settings > Tools > Directory Tools.
  6. In the Directory Tools page, select SCIM Integration tab to create OAUTH tokens for all your vendors.
  7. Provide the Name for the New OAuth Token and Click on Generate.
  8. The Generate Token will be shown on the SCIM Integration Dashboard and you can copy the same for further use. Additionally, it will show further information like Last Used Time.

Creating Netskope User Enrollment App in Okta

The first step towards integrating Okta with Netskope is to create and configure the Netskope User Enrollment app as a SCIM application in the Okta account.

  1. Log in to your Okta account admin console.
  1. In the admin console, Click on Applications -> Click on Browse App Catalog -> Search for the Netskope User Enrollment App
  1. Click on Add Integration
  1. Provide the Application Label and Click on Done

Configuring Netskope SCIM App

  1. In the App Provisioning page, Configure the API Integration.
  1. Copy the Base URL and API Token from the SCIM Integration as discussed the prerequisite and paste the same in the API Integration tab.
  1. Click on Save and Test API Credentials before Saving.
  1. In the Provisioning tab, select To App from the left-hand-side options, and click Edit button for Provisioning to App. Enable the following:
    • Create Users
    • Update User Attributes
    • Deactivate Users
    1. Click Save.

    Add / Assign User and User Group to the Netskope User Enrollment App

    1. In the Assignments tab, click Assign and select Assign to People.
    1. Select the user to be assigned and click the Assign button.
    1. Select the groups to be assigned and click the Assign button.
    1. To push groups, click the Push Groups tab.
      1. Click Find Groups by Name button.
    1. Search for the group to be added to the app and click the SAVE button
    1. Once added successfully, the user group will display Active status.

    Netskope Tenant Verification

    To verify if the users are provisioned in Netskope Tenant from Okta, do the following:

    1. Log in to your Netskope Tenant account.
    2. Go to Settings > Security Cloud Platform > Groups to check if the group has been pushed with those number users
    1. Checking the same in OKTA Dashboard for the same Group

Share this Doc
In this topic ...