Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Next challenges

Recent achievements

  • Global
  • Personal

Recognition

  • Give kudos
  • Received
  • Given

Leaderboard

  • Global

Trophy case

Kudos (beta program)

Kudos logo

You've been invited into the Kudos (beta program) private group. Chat with others in the program, or give feedback to Atlassian.

View group

It's not the same without you

Join the community to find out what other Atlassian users are discussing, debating and creating.

Atlassian Community Hero Image Collage

Can I sync manually added users with the IdP on an ongoing basis?

Hi,

 

We have a case where existing users keep inviting new users from the company to the application. Now even though we have SCIM enabled the users register via the manual method and are out of sync with the IdP SCIM and cannot be managed by SCIM.

Now I know, Okta has an import function to resolve this but thats not something I am given access to. So wondering if there is another way to enable on-going sync with IdP so that any new manually added user becomes managed by SCIM at a later point?

I understand the requirements: Yes, the user must exist in our IdP group for authentication/SSO but might not have been assigned the app for SCIM group provisioning. Does that make sense? Or am I doing something wrong?

1 answer

1 accepted

1 vote
Answer accepted
Ivan Lima Community Leader Jan 23, 2021

Hey @Nakul Jamadagni, I've seen a similar situation, and how I got around that was reassigning the users/groups from the assignments tab on the Idp side and syncing again. Have you tried that?

Dave Meyer Atlassian Team Jan 23, 2021

Agreed. If the user has already been invited manually and you assign a user with the same email address in Okta, then we will match it to the existing account. The profile details from Okta will become the source of truth and the user will be fully managed in Okta like any other IdP-managed user.

On the end user's side, they won't notice a thing unless they had manually set profile details (like job title) already. In that case they would get overwritten by the values from Okta.

Like # people like this

Thank you @Ivan Lima / @Dave Meyer for the quick response. This has resolved quite a few but some corner cases remain not in sync. Any recommended way to resolve these inconsistencies?

Suggest an answer

Log in or Sign up to answer
TAGS
Community showcase
Published in Atlassian Access

We're launching improved navigation for admins

Hi Atlassian Community, My name is Avni Barman and I am a Product Manager on the Atlassian Access team! One of my top priorities is to help make the administrator's life easier through improved pro...

915 views 1 10
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you