The Okta SCIM integration lets Account Admins automate user provisioning, profile updates, deactivation, and group sync between Okta and 15Five. This article describes what the integration does and links to task-specific setup articles.
Note: If your organization uses Okta for SSO, set up SSO before configuring SCIM. See Set up SAML Single Sign-On (SSO) in 15Five for instructions.
Required role: Account Admin with Manage Integrations access.
Feature Structure
What the Integration Does
The 15Five SCIM integration with Okta supports the following actions:
- Create users — Assigning a user to the 15Five app in Okta creates them in 15Five.
- Sync profile updates — Changes to user data in Okta are pushed to 15Five.
- Deactivate users — Deactivating a user or removing their 15Five app access in Okta deactivates them in 15Five.
- Import users to Okta — Users created in 15Five can be pulled into Okta and matched against existing Okta users.
- Sync groups — Groups created in Okta can be pushed to 15Five.
- Pull groups into Okta — Groups created in 15Five can be pulled into Okta for reference.
- Delete groups — Groups removed from the 15Five app in Okta are deleted in 15Five.
Supported Attributes
The following attributes can be synced from Okta to 15Five:
- First name
- Last name
- Title
- Employee number
- Location
- Manager ID
- Start date
- Hire date
- Termination date
- Custom attributes
- Group ID
- Group name
- Group members
Key Rules
- SCIM syncs are on-demand. Changes pushed from Okta reach 15Five immediately.
- When SCIM is enabled, manual user creation via Manage People is disabled. CSV import can be enabled by contacting Contact the 15Five Support Team.
- Timezone sync is not supported via SCIM.
- Groups imported from 15Five into Okta cannot be edited in Okta — manage them in 15Five.
- Only Group ID, name, and members sync from Okta to 15Five. Group type changes made in 15Five are not overridden by future SCIM syncs.
- If your organization uses SSO, do not enable Sync Password in Okta.
- Existing 15Five user data is not deleted when SCIM is enabled, provided email addresses match.
What You Can Do
Set Up
- Enable SCIM in 15Five and generate an access token
- Configure the 15Five SCIM application in Okta
- Set up SAML Single Sign-On (SSO) in 15Five
Manage
- Provision and sync users from Okta to 15Five
- Sync groups from Okta to 15Five
- Sync start, hire, and termination dates via SCIM
- Sync custom attributes from Okta to 15Five via SCIM
Common Issues
- Manager field not syncing from Okta to 15Five
- Start date or location field not syncing from Okta to 15Five
- Email address already in use error when creating a user via SCIM
- Updates or de-provisioning not working for some users in Okta
- Automatic provisioning error — Resource None not found