SCIM Provisioning

SCIM with OneLogin

Automatically sync employee entries with users from OneLogin. Setup your integration in only a few steps. To sync a person's department, location and/or manager from OneLogin to AssetNode, you need to enable the corresponding option in your AssetNode account settings in the SCIM 2.0 section before you enable provisioning.

Syncs every ~40 minutes

Setup guide (18 steps)

1
Log in to your OneLogin account
Navigate to your OneLogin admin portal and sign in.
OneLogin: Log in to your OneLogin account
2
Add a new application
Click on "Applications", then on "Add App".
OneLogin: Add a new application
3
Search for the SCIM app
Search for "SCIM Provisioner with SAML (SCIM v2 Core)" and select it.
OneLogin: Search for the SCIM app
4
Name and save the application
Give it a name (like "AssetNode SCIM") and click "Save". You might get an error notification after this, but you can safely ignore it.
OneLogin: Name and save the application
5
Open the Parameters tab
Click on "Parameters" in the left menu bar.
OneLogin: Open the Parameters tab
6
Add the "name" parameter
Click on the "+" to add a new parameter. Enter "name" in the Field Name and click "Save". Then search for "Name" in the Value dropdown, select it and click "Save".
OneLogin: Add the "name" parameter (1/2)
OneLogin: Add the "name" parameter (2/2)
7
Add the "title" parameter
Add another parameter with the Field Name "title". Search for "Title" in the Value dropdown, select it and click "Save".
OneLogin: Add the "title" parameter (1/2)
OneLogin: Add the "title" parameter (2/2)
8
Add the "department" parameter
Add another parameter with the Field Name "department". Search for "Department" in the Value dropdown, select it and click "Save".
OneLogin: Add the "department" parameter (1/2)
OneLogin: Add the "department" parameter (2/2)
9
Add the "location" parameter (optional)
Add another parameter with the Field Name "location". Select which field in OneLogin you'd like to map to the employee's location field in AssetNode (e.g. "company"). You can skip this step if you don't want to sync the location.
OneLogin: Add the "location" parameter (optional) (1/2)
OneLogin: Add the "location" parameter (optional) (2/2)
10
Save the parameters
Click on "Save" in the top right corner to save all the parameter mappings.
OneLogin: Save the parameters
11
Configure SCIM connection
Click on "Configuration" in the left menu bar. Copy the "Endpoint URL" and the "Secret Token" from your AssetNode account settings (SCIM 2.0 section), and paste them into the "SCIM Base URL" and "SCIM Bearer Token" fields.
OneLogin: Configure SCIM connection (1/2)
OneLogin: Configure SCIM connection (2/2)
12
Paste the SCIM JSON Template
Scroll down and paste the SCIM JSON Template into the "SCIM JSON Template" field.
OneLogin: Paste the SCIM JSON Template
13
Enable the API connection
Scroll back up and click on "Enable" to activate the SCIM connection.
OneLogin: Enable the API connection
14
Save the configuration
Click on "Save" in the top right corner.
OneLogin: Save the configuration
15
Configure Provisioning
Click on "Provisioning" in the left menu bar. Check the "Enable Provisioning" checkbox. Un-check the "Create user", "Delete user" and "Update user" fields. Change the deletion dropdown value to "Suspend". Click "Save".
OneLogin: Configure Provisioning
16
Select a user to assign
Click on "Users" in the top menu bar and then select a user that you would like to add to the app.
OneLogin: Select a user to assign (1/2)
OneLogin: Select a user to assign (2/2)
17
Add user to the application
Click on "Applications", then click the "+" button. Select the app you just created (AssetNode SCIM) and click "Continue". Then click "Save".
OneLogin: Add user to the application (1/3)
OneLogin: Add user to the application (2/3)
OneLogin: Add user to the application (3/3)
18
Verify provisioning
You can now see that the user has been provisioned and added to the app. Repeat the user assignment process for all the users you'd like to add as employees.
OneLogin: Verify provisioning (1/2)
OneLogin: Verify provisioning (2/2)

After completing setup

  • The synchronization takes place approximately every 40 minutes. Any changes you make to users in OneLogin will be automatically reflected in AssetNode.
  • To sync the employee's location, enable "Set employee location info from Identity Provider" in your AssetNode SCIM settings.
  • To sync the employee's department, enable "Set employee department info from Identity Provider" in your AssetNode SCIM settings.
  • If you remove a user from OneLogin, they are marked as "Archived" in AssetNode (not deleted) — they may still have assets checked out.