Integrations

/

Okta SAML2 + SCIM with Flexopus: Centrally manage users and groups

With the Okta integration in Flexopus, you connect your existing identity management directly to your workplace management solution – for centralized, secure, and automated user administration.

No items found.
No items found.

What is Okta SAML2 + SCIM synchronization?

The Okta integration with Flexopus combines two complementary standards: SAML2 for Single Sign-On (SSO) and SCIM for automated user provisioning.

SAML2 (Security Assertion Markup Language 2.0) allows your employees to log in to Flexopus using their Okta credentials – without a separate password. SCIM (System for Cross-domain Identity Management) ensures that user accounts and groups are automatically created, updated, and deactivated in Flexopus from Okta.

The connection runs via a secure API interface. Flexopus receives user data from Okta and synchronizes it automatically. Only the necessary attributes are transferred, such as name, email address, department, and group membership.

What is the purpose of the integration?

The Okta integration creates a seamless workflow between your identity provider and Flexopus. Instead of manually creating or maintaining users in Flexopus, Okta handles this task fully automatically.

Typical use cases:

  • New team member: If the person is added to the corresponding group in Okta, they automatically receive access to Flexopus – without manual intervention.
  • Departing employees: If an account is deactivated or deleted in Okta, the profile in Flexopus is automatically blocked.
  • Department changes: Changes to groups or attributes in Okta are passed directly to Flexopus.
  • Single Sign-On: Employees log in with their familiar Okta credentials – no additional password, no separate login.

How easy is the integration?

Setting up the Okta integration in Flexopus is done in just a few steps. Essentially, you create a SAML2 app integration in the Okta admin console, configure the attribute mappings, and upload the metadata file to Flexopus. For SCIM provisioning, you generate an API token in Flexopus and enter it in Okta.

A complete step-by-step guide for setup can be found in our Help Center.

What are the benefits of the integration?

  • Automatic user provisioning: New employees are created directly in Flexopus from Okta – without manual effort.
  • Automatic deactivation: If employees leave the company, their Flexopus access is automatically blocked.
  • Single Sign-On (SSO): One-time login with Okta credentials – no additional password required.
  • Centralized group management: Groups from Okta are imported directly into Flexopus and can be used for access management.
  • Minimal data transfer: Only the necessary user attributes are transferred – compliant with data protection and secure.
  • Fewer errors: Manual data maintenance is eliminated, preventing typos and inconsistencies.
  • Included for free: The integration is included in Flexopus at no extra cost (depending on the selected plan).
Categories
Developed By
Flexopus GmbH
Frequently Asked Questions

Questions and answers

What happens to a Flexopus account when a user is deleted or deactivated in Okta?

If a user is deactivated or deleted in Okta, Flexopus automatically deactivates the corresponding profile. The user can no longer log in afterward. The profile remains stored in Flexopus but is marked as inactive. Existing bookings or data are preserved.

Are groups from Okta also synchronized in Flexopus?

Yes, groups from Okta can be transferred to Flexopus via SCIM. These groups are created in Flexopus as external, read-only groups. This means: names, members, and structure are managed exclusively via Okta. Flexopus supports flat group structures; nested groups are synchronized at the first level.

How does Flexopus handle duplicate user entries?

During synchronization, Flexopus checks several identifiers in a defined order: first the SCIM ID, then the external provider ID (e.g., from Okta), then the UPN, and finally the email address. A new profile is only created if none of these values match. This reliably prevents duplicate entries.

Can I use SCIM without SAML2 SSO?

Technically this is possible, but it is not recommended. SCIM writes important fields such as email address, UPN, and external ID. Without SAML2, inconsistencies can occur. If you would like to use SCIM without SSO, please contact our support team at support@flexopus.com in advance to coordinate your concept.

Which user data is transferred?

Only the attributes necessary for Flexopus are transferred: first name, last name, email address, display name, and optionally department and job title. Unnecessary fields are not synchronized to keep data transfer to a minimum.