Setting up automatic user provisioning for Okta

2026-07-07Last updated

To synchronize user management in Security Center SaaS with Okta, you can set up automatic user provisioning with help from the Genetec™ Technical Assistance Center (GTAC).

Before you begin

What you should know

Invitation emails aren’t sent to automatically provisioned users.

Procedure

  1. Your integrator creates a new case with GTAC and includes the necessary information:
    • Email contact for the Okta administrator with sufficient privileges and expertise to set up an application integration for their identity provider.
    • Domains used by the users during login. For example, for users who log in with myuser@company.com, the domain is company.com.
    • Security Center SaaS system name.

      The system name can be found in user preferences under the user name, or from the Select a system page in Security Center SaaS.

    • Security Center SaaS system ID. For example, SCC-200012-345678.

      This ID can be found in the License section of the About page in Genetec™ Configuration desktop.

    • Okta tenant URL. For example, https://<yourtenantname>.okta.com.

      The tenant URL can be found in Okta Security > API > Issuer Metadata URI .

    • Customer name.
    • Groups to be included in the synchronization scope.
      Note:
      Only direct-group membership is supported. Group nesting, indirect user membership, or automatic provisioning for guests or external Okta users is not supported.
  2. Genetec verifies the information in the case and schedules a call with the IT administrator to configure the setup together.
  3. Attend the setup call.
    Genetec helps you configure the following provisioning settings in a new Okta application:
    • SCIM connection information.
    • Users and Groups attributes mapping required by Security Center SaaS.
  4. Define the scope of the automatic user provisioning by adding the required user groups to your Okta application.
    Best Practice:
    Only place user groups in the scope. Group nesting isn’t supported.
  5. After Okta has completed initial provisioning of your groups, go to https://securitycentersaas.genetec.cloud and use the Configuration task to assign roles to your groups.
    Tip:
    Okta pushes users and groups data to Security Center SaaS as soon as possible. To trigger an immediate data update, see Forcing a synchronization in Okta.

After you finish

Assign roles to users and groups imported from Okta.