Requirements
- Admin access to an Okta org.
- Admin access to Remote with API credentials generation capability.
- Remote company should already have employee and department data populated for sync.
Supported Features
- Import users: Okta imports employee profiles from Remote.
- Import groups: Okta imports Remote departments as groups.
- Profile sourcing: Remote acts as the authoritative source for supported employee profile attributes in Okta.
- Employee status sync: Okta can read employee status from Remote, including whether an employee is active or inactive.
- Department sync: Okta can read department assignments from Remote.
- Manager sync: Okta can read manager relationships from Remote where available.
Limitations:
- Create users in Remote: Okta cannot create employee accounts in Remote.
- Update users in Remote: Okta cannot update employee attributes in Remote.
- Deactivate users in Remote: Okta cannot deactivate or offboard employees in Remote.
Employee onboarding, profile changes, department changes, manager changes, and offboarding must be completed in Remote. Okta imports those updates from Remote during its next sync.
What data does Okta get from Remote?
Important: Okta can only read data from Remote. It cannot create, modify, or deactivate employees. Remote remains the single source of truth for all employment data.
Employee information (SCIM "Users"):
- Full name (user name, given name, family name)
- Email address
- Email address type (personal or work)
- Employee number
- Department
- Manager
Department information (SCIM "Groups"):
- Department name
- List of active employees in each department
Configuration Steps
Step 1: Generate API Credentials in Remote
- Log in to your Remote admin dashboard.
- Navigate to Company Settings > Integrations > Remote API
- Generate a new API Token for SCIM provisioning. Grant it Full access under Endpoint collections. Check the By generating, you agree to the Remote API Terms of Use checkbox.
- Copy and save the token securely.
Step 2: Add Remote SCIM Integration in Okta
- In your Okta Admin Console, navigate to Applications > Applications.
- Click Browse App Catalog.
- Search for "Remote" and select the Remote SCIM 2.0 integration.
- Click Add and enter a name for the integration (e.g., "Remote SCIM Provisioning").
- Click Next and then Done.
Step 3: Configure SCIM Connection
- In the Remote app instance, click the Provisioning tab.
- Click Configure API Integration → check Enable API integration.
- Enter the following:
- Bearer Token: Paste the token from Step 1
- Click Test Connection to verify.
- Click Save.
Step 4: Enable Provisioning Features
- In the Provisioning tab, scroll to Provisioning to App.
- Enable:
- Import Groups. This allows Okta to import Remote departments as groups.
- Click Save.
Remote’s SCIM integration is read-only. Okta can import and sync employee and department data from Remote, but it cannot create, update, or deactivate employees in Remote. Employee onboarding, profile updates, and offboarding must be completed in Remote.
Step 5: Configure Attribute Mappings
- Click the Attribute Mappings tab
-
Verify the following critical mappings:
Okta field Remote field userNameuserNamefirstNamename.givenNamelastNamename.familyName -
For additional attributes, ensure corresponding fields exist in Remote.
Okta field Remote field emailuserNameemployeeNumberuser.employeeNumberdepartmentuser.departmentmanagerValueuser.managerIdmanagerDisplayNameuser.manager - Click Save.
Step 6: Test the Integration
- In Okta, go to the Import tab.
- Click on Import Now to verify that employee profiles are returned from Remote.
- Confirm that employee names, email addresses, departments, and manager fields appear as expected.
Configuration Notes
- First Sync: When you first enable provisioning, Okta syncs all assigned users. This may take several minutes depending on user count. Do not deactivate users or make bulk changes during this time.
- Email as Primary Identifier: Remote uses email as the primary identifier. Ensure the email field in Okta is accurately mapped and kept up-to-date.
- Department Mapping: If your Okta users have a "Department" attribute, map it to Remote's department field for automatic grouping.
- Manager Information: If you want manager relationships synced, ensure the manager field in Okta contains the manager's email address in Remote.
Troubleshooting
Connection Test Failed
Possible causes:
- Invalid or expired Bearer Token: Regenerate a new token in Remote's API settings
- Network/firewall restrictions: Check with your IT team to confirm Okta's IP addresses are whitelisted.
Users Created but Attributes Not Syncing
Possible causes:
- Incorrect attribute mappings: Review mappings in the Attribute Mappings table and verify Okta fields are mapped to correct Remote fields
- Missing data in Okta: Verify Okta user profiles contain data in the mapped fields (first name, last name, email)
- Field validation errors: Check Remote's validation rules; some attributes may be required in Remote but optional in Okta
Deactivation Not Syncing
Possible causes:
- User dependencies: Some Remote configurations prevent deactivation if the user has active dependencies; contact Remote Support
Sync Failures or Rate Limiting
Solutions:
- Review sync logs in Remote.com SCIM > View Logs for detailed error messages
- Okta respects Remote's rate limits and will automatically retry
- For persistent issues, contact Remote Support with the Okta operation ID and affected user email addresses
Support
For assistance with this integration:
- Remote Support: support@remote.com
- Remote Documentation: https://support.remote.com/hc/en-us
- Okta Community: devforum.okta.com
Comments
0 comments
Please sign in to leave a comment.