> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.optery.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# How to configure SSO & SCIM for your organization?

Optery provides a self-service workflow to configure SSO & SCIM for your organization. Please follow the below steps to complete integration.
* NOTE: If your organization has not purchased SSO and/or SCIM via an Optery Sales Representative, please proceed to the Help Desk article [here](https://help.optery.com/en/article/how-to-purchase-sso-scim-for-your-organization-d9njdo/) to complete the steps for purchase.


**Step 1 -** Login to your Optery for Business organization [here](https://business.optery.com/login). 
* NOTE: If you have not created an Optery for Business organization, please complete the steps [here](https://help.optery.com/en/article/getting-started-with-optery-for-business-for-administrators-1r0e5wi/) first. If you need to be invited as an Administrator, please reach out to your organization's Optery for Business Administrator for access. 
![Login to Optery for Business](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-06-16-at-81735_tcb5ci.png)

**Step 2 -** Upon logging into your Optery for Business organization, select Organization. 

**Step 3 -** In the Organization page, select the Single Sign-On / Provision tab. 

![Single Sign-on / Provision tab](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-06-16-at-73250_mcqrrr.png)


**Step 4 -** Email domain/s will automatically populate with the domain added by your Optery Implementation Manager when enabling SSO/SCIM on the backend or during purchase for self-serve customers. 
* NOTE: Email domains can be added and updated if needed. Comma separated values are supported.

![Domains](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-06-16-at-82347_glwnzn.png)

**Step 5 -** Update Provision Default Plan. The selected plan in this field will be assigned to new members provisioned with SSO & SCIM. 

![Provision Default Plan](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-06-16-at-83634_17yb043.png)

![Select Default Plan](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-06-10-at-12005_1t1ymt9.png)

**Step 6 - Review Organization Settings**

**IF NEEDED,** toggle on Disable Organization Direct Sign-Up. If toggled on, members will not be able to sign up directly, members will only be able to sign up via an invite or SCIM.

**IF NEEDED,** toggle on Disable Passwords on Organization.
* If toggled on and only SSO is configured, invites sent to members of your organization will not require a password to be added when creating an account.
* If toggled on and SSO & SCIM are configured, invites sent to members of your organization will not require a password regardless of this setting being enabled.
* NOTE: This setting is not retroactive.


![](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2026-04-27-at-13626_6qn30z.png)


**Step 7 -** Select Generate SSO setup link and/or Generate SCIM setup link.
* NOTE: SSO & SCIM setup links are valid for 24 hours.

![Generate Setup Link](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-06-16-at-84206_1hptxrl.png)

Below are examples of the links that will be generated when completing the above step.

![Setup Links Generated](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-06-16-at-84448_1iatud0.png)


Next, proceed to the below steps to begin configuration of your SSO and/or SCIM integration.



**Configuring SSO/SCIM integration**

**Step 1 -** Upon generating your organization's personalized SSO/SCIM setup links in your Optery for Business dashboard (steps above) open the link to select your Identify Provider. 

![Select IDP](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-06-10-at-12718_1mvr45w.png)
**Step 2 -** After selecting your Identity Provider, please complete the promoted steps in the Optery Identity Provider Wizard to complete integration. 



**Optional Configurations for SCIM Integration**

Optery can provision/de-provision users as they're imported into the application.

**Provisioning** 
* Required: firstName, lastName, email, country
* Recommended: currentCity, currentState, birthYear

If your organization is utilizing **Okta**, please complete the below steps to configure your new custom plan attribute.
* NOTE: If your organization has purchased only one type of plan (Core, Extended or Ultimate) a new custom plan attribute does not need to be configured as all members will default to the Provision Default Plan setting in your Admin Dashboard.

After completing Step 3 - Set up Attribute Mapping in the Optery Identity Provider Wizard, begin adding your new custom plan attribute.

**Step 1 -** Within your Okta Admin Console, go to the Applications page, select Applications and then select the Provisioning tab.


![Okta Admin Console](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-07-16-at-90814_3jre6l.png)

**Step 2 -** Scroll to the middle of the page and select Go to Profile Editor


![Go to Profile Editor](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-07-16-at-91349_24219p.png)

**Step 3 -** Select the Edit icon on any existing attribute.


![Edit existing attribute](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-07-16-at-91634_z8w6go.png)


**Step 4 -** Copy the existing External namespace and then select Cancel.

![Copy existing External namespace](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-07-16-at-93954_1malvon.png)

**Step 5 -** You will then be redirected back to the Profile Editor page. Next, select Add Attribute.


![Add Attribute](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-07-16-at-94312_1oh6vta.png)

**Step 6 -** Create a new attribute with the below details included and select Save.
* Ensure plan is all lowercase
* Paste the copied External namespace in the previous steps to the External namespace field for the new attribute
* Set Attribute to Group
* Select Save

![Create a new attribute](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-07-16-at-94633_sg4zzv.png)


**Step 7 -** Within your Okta Admin Console, go to the Directory page and select Groups.



![Groups](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-07-16-at-10114_wvepqk.png)

**Step 8 -** Select Add Group and create a new group for each type of plan your organization has purchased. (Ultimate, Extended and/or Core).


![Add group](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-07-16-at-10140_7mutj5.png)


![Ultimate](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-07-16-at-10200_5m90gr.png)
![Extended](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-07-16-at-10201_1eq61s1.png)
![Core](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-07-16-at-10204_n4blui.png)




**Step 9 -** Once your Groups are created, select one of your applicable Groups.
* NOTE: The next steps must be completed for all applicable groups for your organization. 

![Select one of your applicable Groups](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-07-16-at-10270_bcc1ao.png)


**Step 10 -** After selecting your newly created Group, you will then be directed to the below page. Next, select Applications.


![Applications](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-07-16-at-10312_gh593y.png)

**Step 11 -** Select Assign applications.


![Assign Applications](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-07-16-at-10341_2hmt5.png)

**Step 12 -** Select Assign to the Optery Application.
* NOTE: Your application may be named differently based on what naming convention you used when creating your new application.

![Assign](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-07-16-at-10372_1o10egb.png)



**Step 13 -** Scroll to the bottom of the Assign Applications page to \*(depending on which plan you selected) and input the applicable plan name. Then select Save and Go Back.
* For example, if you've selected the Ultimate Group, plan will require Ultimate. 


![](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-07-16-at-10422_1y5c6fx.png)
![Input applicable plan name](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-07-16-at-10465_1crq1xd.png)


**Step 14 -** Optery will then be Assigned to the group as seen in the screenshot below. Next, select Done.

![Select Done](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-07-16-at-10504_1yoiznd.png)
Optery is now assigned to the applicable Group as seen below.


![Optery is now assigned to the applicable Group](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-07-16-at-10531_dz5uj8.png)



**De-provisioning**
* Downgrade and Remove from Organization - will downgrade a member to a Free Optery plan and remove the member from your organization


NOTE: The Integration Status of SSO & SCIM is made available in the Optery for Business dashboard. *Awaiting status* will update to *Active* when configuration is completed successfully. 

![Integration Status](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-06-16-at-75737_a0rupj.png)

SSO & SCIM integration can be revoked at any time by using the above toggle option found in your Optery for Business dashboard under Organization - Single Sign-On / Provision. The below prompt will appear to provide confirmation before proceeding. 
* NOTE: Deactivating Single Sign-On will also disable Directory Sync 

![Disable Single Sign-on](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-06-10-at-12485_kgvdns.png)

![Disable Directory Sync](https://storage.crisp.chat/users/helpdesk/website/-/a/2/6/9/a2694c90838a2000/screenshot-2025-06-10-at-12490_1ljd3vi.png)







