Provision Users and Groups from Okta

Updated

Okta is a cloud-based identity and access management (IAM) platform that centralizes user and customer profiles to enhance security and streamline access. It offers features like multifactor authentication, single sign-on, and lifecycle management to help organizations manage user identities effectively.

NetBird's Okta integration enhances user management by allowing you to utilize Okta as your identity provider. This integration automates user authentication in your network, adds SSO and MFA support, and simplifies network access management to your applications and resources.

The integration process consists of two stages: first, you’ll set up OpenID Connect (OIDC) to enable Single Sign-On (SSO) from NetBird's login page using Okta credentials. Next, you’ll configure SCIM (System for Cross-domain Identity Management) to synchronize users and groups smoothly.

Get Started with NetBird-Okta Integration

To set up SSO, go to Integrations in the NetBird admin console's left menu to access the Identity Provider integration page. Click the Connect Okta button to get started with the Okta-NetBird integration. This will open a pop-up window with detailed instructions on synchronizing NetBird and Okta.

The Okta card on the Identity Provider Sync tab with its Connect Okta button

Prerequisites

Before you begin the integration process, ensure you have the necessary permissions in Okta. You need an Okta user account with one of the following roles:

  • Super Admin
  • Org Admin
  • Group Admin

To check your user permissions in Okta:

  • Log in to your Okta admin dashboard.
  • Expand People in the left menu.
  • Select your user.
  • Navigate to the Admin roles tab.

Confirm that you have one of the required roles before proceeding with the integration.

Installing the NetBird Integration

Once you have the necessary permissions, you can set up the NetBird application. First, on NetBird, click Continue → to show a summary of the necessary steps.

Let's go through them one by one:

  • In Okta’s admin dashboard, click Applications in the left menu.
  • Select Applications from the submenu.
  • Click the Browse App Catalog button.

In the app catalog, enter "NetBird" in the search bar. Then, click the Add Integration button.

Accept the default application name and click the Done button. On the next screen, click the Assign dropdown and select Assign to People.

You will see a list of users. Find your user account, click Assign, and save the changes. Verify your user is assigned to the NetBird app and click Done. Your user now appears on the NetBird application's Assignments tab.

Configuring SSO in Okta

The next step is to configure Okta-NetBird SSO integration.

In NetBird, click the Continue → button. A new wizard screen will appear, offering the instructions for retrieving Okta’s OpenID Connect credentials. You can click Close and navigate to Okta.

  • Click on the Sign On tab on Okta. Look for OpenID Connect under Sign on methods in the Settings section.
  • Copy the Client ID value.
  • Copy the Client Secret value.

Store these credentials securely, as you will need them soon.

The Sign On tab of the NetBird app in Okta, showing the OpenID Connect Client ID and Client Secret

  • Click Edit in the Settings section.
  • In Credential Details, change the Application username format from Okta username to Email.
  • Click the Save button

The Credential Details section with Application username format set to Email

  • On the top right, click on your username
  • Copy your Okta account domain, shown under your email address in that menu, for example trial-1234567.okta.com.

The final step is to send an email to the NetBird team with the authentication information you just retrieved:

  • Okta Client ID
  • Okta Client secret
  • Okta account domain
  • Okta primary email domain (usually your username)

You will receive an email once the NetBird team enables authentication for your account.

This completes the first stage, enabling Single Sign-On (SSO) from NetBird's login page using Okta credentials. Now, you can navigate to app.netbird.io and log in using Okta Verify.

Enabling Okta SCIM in NetBird

In NetBird, go to Integrations > Identity Provider Sync and click the Connect Okta button again. The first screen reminds you of the permissions your user needs in Okta. Click Get Started →. The next screen covers the SSO setup from the previous section, so click Continue → to skip it.

The next screen will show you how to enable NetBird API credentials in Okta. Copy the value of the Authorization (Bearer) token.

The NetBird wizard step showing the Authorization (Bearer) token to copy into Okta

Navigate to the NetBird app in your Okta admin dashboard. Click the Provisioning tab, then select Configure API Integration.

Follow these steps:

  • Check the box to enable API Integration.
  • Enter your NetBird API Token.
  • Click Test API Credentials to verify the SCIM connection.

The Okta API Integration form with Enable API integration checked and the token entered

If everything works as expected, Okta shows the message "NetBird was verified successfully!". Click Save to continue.

Configuring SCIM Provisioning to NetBird

On NetBird, click Continue →. You'll see instructions for configuring SCIM provisioning to NetBird.

Back in Okta, stay on the Provisioning tab, select To App in the left-hand Settings list, and click Edit next to Provisioning to App.

Enable Okta to create, update, and deactivate NetBird users by checking the corresponding boxes:

  • Create Users
  • Update User Attributes
  • Deactivate Users

When done, click Save.

The Provisioning to App settings with Create Users, Update User Attributes, and Deactivate Users enabled

Assigning NetBird Application to Okta Groups

In NetBird, click Continue →, you'll see the steps for assigning the NetBird integration to Okta groups.

  • Navigate to the Assignments tab.
  • Similar than before when you assigned your user to NetBird app, click the Assign button
  • This time, select Assign to Groups.
  • Select Okta groups that you want to assign to the NetBird app.

Once you assign the desired groups, click Done. The selected groups appear on the Assignments tab.

Push Okta Groups to NetBird

One more time, go to NetBird and click Continue →. You'll see the final instructions to push Okta groups to NetBird.

  • In Okta, navigate to Push Groups tab
  • Click the Push Groups button
  • Select Find groups by name
  • Search for specific groups to push to NetBird.

The Push Groups tab with the Push Groups dropdown open on Find groups by name

Once you finish, go back to NetBird and click Finish Setup. You can verify the synchronization by navigating to Team > Users. The users listed in NetBird should match those assigned to the app in Okta.

The NetBird Users table listing the users pushed from Okta