Configuring Neowit with Okta User Provisioning

You can automatically provision your company’s users with Neowit from Okta. The guide requires that you’ve already set up an Application / Single Sign-On (SSO) using SAML in both the Neowit app and in Okta

Prerequisites

  • A Neowit administrator account.
  • An Okta subscription
  • Okta admin privileges.
  • Previously configured Application for SSO in Okta and paired it with an Authentication configuration in the Neowit app.

Features

  1. Update user attributes: User attributes that are updated in Okta will be automatically updated on the Neowit platform.
  2. Deactivate users: When users are deactivated in Okta, they will also be automatically deactivated on the Neowit platform.
  3. Create users: Users that are assigned to the Neowit platform in Okta are automatically provisioned and added to your organization on the Neowit platform.
  4. Create groups: Groups that are assigned to the Neowit platform in Okta are automatically provisioned and added to your organization on the Neowit platform.
  5. Import Users: Users created in the Neowit platform are automatically imported to Okta.

How to add

  1. From Okta Admin Console you can find the Neowit app by clicking "Applications" -> "Applications" -> "Browse App Catalog" and searching for Neowit.
  2. When adding Neowit you will be prompted for a Neowit IdP ID this will be available from Settings/Authentication on our platform, you can refer to the SAML setup guide for this step, https://kb.neowit.io/okta
  3. When the Neowit app has been added to your Okta, open the app in Okta and click on "Provisioning" -> "Integration" -> "Configure API Integration". Here you need to click "Enable API Integration".
  4. Next you will be asked for a token. Head over to the Neowit app and click "Settings" -> "Authentication", and open the authenticator that was configured with your SSO.
  5. On the bottom of this page select Okta as SCIM User provisioning type and click "Replace Bearer". You will then be presented with a token, copy this to your clipboard and head back to the Okta Admin Console.
  6. Fill in the API token.
  7. Next go to "Provisioning" -> "To app", and click "Edit". Enable "Create user", "Update user attributes" and "Deactivate users". Then click "Save"
  8. Next go to "Sign on" and click "Edit".
  9. Select "Email" as the "Application username format" and save.
  10. You can start assigning people to the app.