Trim Okta, Keycloak, JumpCloud, and IIJ ID sync screenshots (#982)

This commit is contained in:
Brandon Hopkins
2026-09-24 15:24:55 -07:00
committed by GitHub
parent 75080c9e32
commit 0d44d0b7ba
48 changed files with 54 additions and 210 deletions
Binary file not shown.

Before

Width:  |  Height:  |  Size: 210 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 461 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 930 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 847 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 54 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 152 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 253 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 234 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 205 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 158 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 180 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 246 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 232 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 229 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 311 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 156 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 157 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 113 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 189 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 236 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 154 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 308 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 228 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 296 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 76 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 166 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 188 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 104 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 198 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 228 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 288 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 112 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 332 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 80 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 114 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 122 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 48 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 333 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 47 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 212 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 242 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 171 KiB

@@ -31,20 +31,18 @@ To enable SCIM synchronization in NetBird, navigate to `Integrations > Identity
Select your **JumpCloud** identity provider connector for this integration and click **Continue** to proceed.
<p>
<img src="/docs-static/img/manage/team/idp-sync/jumpcloud-sync/select-idp.png" alt="select-identity-provider" className="imagewrapper-big"/>
<img src="/docs-static/img/manage/team/idp-sync/jumpcloud-sync/select-idp.png" alt="The connector picker with the JumpCloud identity provider selected" className="imagewrapper-big"/>
</p>
This will open a pop-up window featuring a user-friendly wizard to guide you through the configuration process.
![NetBird Jumpcloud Getting Started](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-scim-getting-started.png)
Click `Get Started` to launch the configuration wizard. You will be guided through several configuration options:
**Groups to be synchronized**
By default, all groups assigned to the NetBird application in JumpCloud will be synchronized. If you want to synchronize only assigned groups that start with a specific prefix, you can specify them in the filter. Keep in mind that the prefix matching is case-sensitive.
![NetBird Jumpcloud Group Filter](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-scim-group-filter.png)
![The NetBird wizard step for filtering which groups to synchronize by prefix](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-scim-group-filter.png)
Click `Continue` to proceed to the next step.
@@ -52,19 +50,17 @@ Click `Continue` to proceed to the next step.
By default, all users from the groups assigned to the NetBird application will be synchronized. If you want to further filter and synchronize only users from specific assigned groups, you can specify those group names in the filter. The group name matching is case-sensitive.
![NetBird Jumpcloud User Group Filter](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-scim-user-group-filter.png)
Click `Continue` to generate your SCIM credentials.
**SCIM Credentials**
NetBird will generate the SCIM credentials required to configure JumpCloud. Make note of both the **Base URL** and **Token Key** as you will need them in the next section to complete the JumpCloud configuration.
![NetBird Jumpcloud SCIM Credentials](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-scim-credentials.png)
![The NetBird wizard showing the generated SCIM Base URL and Token Key](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-scim-credentials.png)
Click `Finish Setup` to complete the NetBird SCIM configuration.
![NetBird Jumpcloud SCIM Enabled](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-scim-enabled.png)
![The Identity Provider Sync tab showing the JumpCloud integration enabled](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-scim-enabled.png)
You can now proceed to configure the SCIM application in JumpCloud using the credentials generated above.
@@ -81,14 +77,12 @@ In the **Configuration Settings** section, enter the following SCIM Service Prov
* **Token Key**: Paste the Bearer token you copied from NetBird
* **Test User Email**: Provide a new, unused email address for testing (e.g., `test@yourdomain.com`)
![JumpCloud SCIM Configuration](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-scim-config.png)
![The JumpCloud Identity Management tab with the SCIM Base URL, Token Key, and Test User Email filled in](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-scim-config.png)
* Click `Test Connection` to verify the SCIM connection
If the connection is successful, you'll see a success message. Click `Activate` to enable SCIM provisioning.
![JumpCloud SCIM Test Success](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-scim-activated.png)
## Assigning Groups for SCIM Synchronization
To enable SCIM synchronization of groups and their memberships to NetBird, you need to assign user groups to the NetBird SCIM application.
@@ -100,8 +94,6 @@ In your [JumpCloud admin console](https://console.jumpcloud.com/):
* Select the groups whose members you want to synchronize to NetBird
* Click `Save` to apply the changes
![JumpCloud Assign Groups](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-assign-groups.png)
Once saved, JumpCloud will automatically synchronize the selected groups and their user memberships to NetBird.
## Verify Synchronization
@@ -109,8 +101,6 @@ Once saved, JumpCloud will automatically synchronize the selected groups and the
After assigning groups in JumpCloud, the synchronization will begin automatically. You can verify that users and groups
have been successfully synchronized by navigating to `Team > Users` in your NetBird dashboard.
![NetBird Verify Users](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/netbird-verify-users.png)
<Note>
SCIM provisioning will manage only resources that are created through Jumpcloud. Any resources created directly in NetBird will not be managed by SCIM.
</Note>
@@ -24,7 +24,7 @@ Before you begin the integration process, ensure you have the necessary permissi
Once the SCIM plugin is installed, you should see the SCIM section available in your Keycloak admin console.
![Keycloak SCIM Installed](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-installed.png)
![The Keycloak admin console sidebar showing the SCIM section added by the plugin](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-installed.png)
## Enabling Keycloak SCIM in NetBird
@@ -33,20 +33,18 @@ To enable SCIM synchronization in NetBird, navigate to `Integrations > Identity
Select your **Keycloak** identity provider connector for this integration and click **Continue** to proceed.
<p>
<img src="/docs-static/img/manage/team/idp-sync/keycloak-sync/select-idp.png" alt="select-identity-provider" className="imagewrapper-big"/>
<img src="/docs-static/img/manage/team/idp-sync/keycloak-sync/select-idp.png" alt="The connector picker with the Keycloak identity provider selected" className="imagewrapper-big"/>
</p>
This will open a pop-up window featuring a user-friendly wizard to guide you through the configuration process.
![NetBird Keycloak Getting Started](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-getting-started.png)
Click `Get Started` to launch the configuration wizard. You will be guided through several configuration options:
**Groups to be synchronized**
By default, all groups mapped in the Keycloak SCIM client will be synchronized. If you want to synchronize only groups that start with a specific prefix, you can specify them in the filter. Keep in mind that the prefix matching is case-sensitive.
![NetBird Keycloak Group Filter](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-group-filter.png)
![The NetBird wizard step for filtering which groups to synchronize by prefix](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-group-filter.png)
Click `Continue` to proceed to the next step.
@@ -54,19 +52,17 @@ Click `Continue` to proceed to the next step.
By default, all users from the mapped groups will be synchronized. If you want to further filter and synchronize only users from specific groups, you can specify those group names in the filter. The group name matching is case-sensitive.
![NetBird Keycloak User Group Filter](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-user-group-filter.png)
Click `Continue` to generate your SCIM credentials.
**SCIM Credentials**
NetBird will generate the SCIM credentials required to configure Keycloak. Make note of both the **Base URL** and **Token Key** as you will need them in the next section to complete the Keycloak configuration.
![NetBird Keycloak SCIM Credentials](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-credentials.png)
![The NetBird wizard showing the generated SCIM Base URL and Token Key](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-credentials.png)
Click `Finish Setup` to complete the NetBird SCIM configuration.
![NetBird Keycloak SCIM Enabled](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-enabled.png)
![The Identity Provider Sync tab showing the Generic SCIM integration enabled](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-enabled.png)
You can now proceed to configure the SCIM client in Keycloak using the credentials generated above.
@@ -76,12 +72,8 @@ To configure SCIM in Keycloak, you need to access the SCIM Administration Consol
Navigate to the SCIM Administration Console. On the first login screen, enter your realm name (e.g., `netbird`) and click `Start Login`.
![Keycloak SCIM Login](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-login.png)
Once logged in, navigate to the `SCIM Client` menu and click on `Remote SCIM Provider`. Then click the `+` button to add a new service provider configuration.
![Keycloak SCIM Remote Provider](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-remote-provider.png)
In the SCIM Remote Provider Configuration form, fill out the following sections:
**SCIM Provider Details:**
@@ -94,7 +86,7 @@ In the SCIM Remote Provider Configuration form, fill out the following sections:
* **Base URL**: Paste the Base URL you copied from NetBird (e.g., `https://api.netbird.io/api/scim/v2`)
* **Hostname-Verifier Enabled**: Enable this checkbox
![Keycloak SCIM Configuration](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-config.png)
![The Keycloak SCIM Remote Provider Configuration form with provider and connection details filled in](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-config.png)
**Authentication:**
* **Authentication Type**: Select `Long Life Bearer Token Authentication`
@@ -102,20 +94,10 @@ In the SCIM Remote Provider Configuration form, fill out the following sections:
Click `Add` to save the configuration.
![Keycloak SCIM Authentication](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-authentication.png)
After adding the configuration, click `Save Configuration` and then click `Use default Configuration` to apply the settings.
The default schema for the SCIM provider will be created automatically.
![Keycloak SCIM Default Schema](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-default-schema.png)
Next, assign the SCIM provider to your realm. Click the `Realm Assignment` tab to view all available realms.
![Keycloak SCIM Realm Assignment](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-realm-assignment.png)
Find your realm (e.g., `netbird`) and click `Assign to Realm` to enable SCIM synchronization for that realm.
![Keycloak SCIM Realm Assigned](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-realm-assigned.png)
Next, assign the SCIM provider to your realm. Click the `Realm Assignment` tab to view all available realms, find your realm (e.g., `netbird`), and click `Assign to Realm` to enable SCIM synchronization for that realm.
## Configure Resource Filtering
@@ -125,8 +107,6 @@ To control which specific groups and users should be synchronized, you need to c
Under the `SCIM Client` menu section, click on `Remote SCIM Provider`, then click `Edit` in the NetBird provider row.
Select the `Resource Filtering Rules` tab.
![Keycloak SCIM Resource Filtering](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-resource-filtering.png)
**User Filtering**
To synchronize only users from specific groups, configure the user filtering rule and click `Save Configuration`:
@@ -145,7 +125,7 @@ To synchronize only groups that match specific criteria, configure the group fil
* **Comparator**: Select `Contains`
* **Comparison Value**: Enter the text that should be contained in the group name
![Keycloak SCIM Filtering Configuration](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-filtering-config.png)
![The Keycloak Resource Filtering Rules tab with a user filter and a group filter configured](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-filtering-config.png)
## Initial Sync
@@ -159,7 +139,7 @@ Confirm the following settings:
* **Identifier**: Set to `Username`
* **Synchronization Strategy**: Set to `Get and (update or create) Strategy`
![Keycloak SCIM User Sync Settings](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-user-sync-settings.png)
![The Keycloak User Synchronization settings with Identifier and Synchronization Strategy selected](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-user-sync-settings.png)
Click `Count local and remote resources` to validate that the **Local User Count** and **Remote User Count** values are as expected.
@@ -173,8 +153,6 @@ Confirm the following settings:
* **Operation Type**: Set to `Create Group`
* **Synchronization Strategy**: Set to `Get and (update or create) Strategy`
![Keycloak SCIM Group Sync Settings](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-group-sync-settings.png)
Click `Count local and remote resources` to validate that the **Local Group Count** and **Remote Group Count** values are as expected.
Once validated, click `Synchronize all resources from startIndex` to sync all groups.
@@ -187,8 +165,6 @@ Confirm the following settings:
* **Operation Type**: Set to `Update Group Members`
* **Synchronization Strategy**: Set to `Get and (update or create) Strategy`
![Keycloak SCIM Group Membership Sync Settings](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-group-membership-sync-settings.png)
Click `Count local and remote resources` to validate that the **Local Group Count** and **Remote Group Count** values are as expected.
Once validated, click `Synchronize all resources from startIndex` to sync all group memberships.
@@ -197,8 +173,6 @@ Once validated, click `Synchronize all resources from startIndex` to sync all gr
After completing the initial sync, you can verify that users and groups have been successfully synchronized by navigating to `Team > Users` in your NetBird dashboard.
![NetBird Verify Users](/docs-static/img/manage/team/idp-sync/keycloak-sync/netbird-verify-users.png)
<Note>
SCIM provisioning will manage only resources that are created through Keycloak. Any resources created directly in
NetBird will not be managed by SCIM.
+8 -28
View File
@@ -26,23 +26,17 @@ Once SSO is configured, and you can successfully log in to NetBird using your II
To enable SCIM synchronization in NetBird, navigate to `Integrations > Identity Provider Sync` in your NetBird dashboard.
<p>
<img src="/docs-static/img/manage/team/idp-sync/iij-id-sync/iij-id-connect.png" alt="NetBird IIJ ID Integration" className="imagewrapper-big"/>
<img src="/docs-static/img/manage/team/idp-sync/iij-id-sync/iij-id-connect.png" alt="The Identity Provider Sync tab on the Integrations page with the Connect Generic SCIM button" className="imagewrapper-big"/>
</p>
Click the `Connect Generic SCIM` button to begin the configuration process.
<p>
<img src="/docs-static/img/manage/team/idp-sync/iij-id-sync/iij-id-scim-getting-started.png" alt="NetBird IIJ ID Getting Started" className="imagewrapper-big"/>
</p>
Click `Get Started` to launch the configuration wizard. You will be guided through several configuration options:
Click the `Connect Generic SCIM` button, then `Get Started` on the first screen to launch the configuration wizard. You will be guided through several configuration options:
**Groups to be synchronized**
By default, all groups exported to the NetBird application in IIJ ID will be synchronized. If you want to synchronize only exported groups that start with a specific prefix, you can specify them in the filter. Keep in mind that the prefix matching is case-sensitive.
<p>
<img src="/docs-static/img/manage/team/idp-sync/iij-id-sync/iij-id-scim-group-filter.png" alt="NetBird IIJ ID Group Filter" className="imagewrapper-big"/>
<img src="/docs-static/img/manage/team/idp-sync/iij-id-sync/iij-id-scim-group-filter.png" alt="The wizard step for filtering synchronized groups by name prefix" className="imagewrapper-big"/>
</p>
Click `Continue` to proceed to the next step.
@@ -51,10 +45,6 @@ Click `Continue` to proceed to the next step.
By default, all users from the groups exported to the NetBird application will be synchronized. If you want to further filter and synchronize only users from specific groups, you can specify those group names in the filter. The group name matching is case-sensitive.
<p>
<img src="/docs-static/img/manage/team/idp-sync/iij-id-sync/iij-id-scim-user-group-filter.png" alt="NetBird IIJ ID User Group Filter" className="imagewrapper-big"/>
</p>
Click `Continue` to generate your SCIM credentials.
**SCIM Credentials**
@@ -62,16 +52,10 @@ Click `Continue` to generate your SCIM credentials.
NetBird will generate the SCIM credentials required to configure IIJ ID. Make note of both the **Base URL** and **Token Key** as you will need them in the next section to complete the IIJ ID configuration.
<p>
<img src="/docs-static/img/manage/team/idp-sync/iij-id-sync/iij-id-scim-credentials.png" alt="NetBird IIJ ID SCIM Credentials" className="imagewrapper-big"/>
<img src="/docs-static/img/manage/team/idp-sync/iij-id-sync/iij-id-scim-credentials.png" alt="The wizard step showing the generated SCIM Base URL and Token Key" className="imagewrapper-big"/>
</p>
Click `Finish Setup` to complete the NetBird SCIM configuration.
<p>
<img src="/docs-static/img/manage/team/idp-sync/iij-id-sync/iij-id-scim-enabled.png" alt="NetBird IIJ ID SCIM Enabled" className="imagewrapper-big"/>
</p>
You can now proceed to configure provisioning in IIJ ID using the credentials generated above.
Click `Finish Setup` to complete the NetBird SCIM configuration. The Generic SCIM card now shows the integration as enabled, and you can proceed to configure provisioning in IIJ ID using the credentials generated above.
## Configure Provisioning in IIJ ID
@@ -83,7 +67,7 @@ Select `Export accounts` and enter the following details:
* **Access token**: Paste the Token Key you copied from NetBird
<p>
<img src="/docs-static/img/manage/team/idp-sync/iij-id-sync/iij-id-provisioning-settings.png" alt="IIJ ID Provisioning Settings" className="imagewrapper-big"/>
<img src="/docs-static/img/manage/team/idp-sync/iij-id-sync/iij-id-provisioning-settings.png" alt="The IIJ ID Provisioning tab with Export accounts selected and the SCIM base URL and access token filled in" className="imagewrapper-big"/>
</p>
Click `Update Provisioning Information` to save the configuration.
@@ -100,7 +84,7 @@ want to synchronize, then set:
Click `Update Applications User Settings` to apply the change.
<p>
<img src="/docs-static/img/manage/team/idp-sync/iij-id-sync/iij-id-enable-export.png" alt="IIJ ID Enable Export" className="imagewrapper-big"/>
<img src="/docs-static/img/manage/team/idp-sync/iij-id-sync/iij-id-enable-export.png" alt="The IIJ ID Application User edit form with Export set to Export" className="imagewrapper-big"/>
</p>
The `Export` column now shows `Export` for that entry. When you select a group as an Application User, its members become
@@ -111,10 +95,6 @@ Application Users as well, so IIJ ID exports those users to NetBird.
Exporting the users does not export the groups themselves. Still in your `NetBird` application, select the `Group` tab,
enter the groups you want to export to NetBird, and click `Add`.
<p>
<img src="/docs-static/img/manage/team/idp-sync/iij-id-sync/iij-id-add-group.png" alt="IIJ ID Add Group" className="imagewrapper-big"/>
</p>
Once saved, IIJ ID will automatically export the selected users, groups, and their memberships to NetBird.
<Note>
@@ -127,7 +107,7 @@ After configuring provisioning in IIJ ID, the synchronization will begin automat
have been successfully synchronized by navigating to `Team > Users` in your NetBird dashboard.
<p>
<img src="/docs-static/img/manage/team/idp-sync/iij-id-sync/netbird-verify-users.png" alt="NetBird Verify Users" className="imagewrapper-big"/>
<img src="/docs-static/img/manage/team/idp-sync/iij-id-sync/netbird-verify-users.png" alt="The NetBird Users table listing the users exported from IIJ ID" className="imagewrapper-big"/>
</p>
<Note>
@@ -33,19 +33,15 @@ Once SSO is configured, and you can successfully log in to NetBird using your Ju
To enable SCIM synchronization in NetBird, navigate to `Integrations > Identity Provider Sync` in your NetBird dashboard.
![NetBird Jumpcloud Integration](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-connect.png)
![The Identity Provider Sync tab with the Connect Jumpcloud button](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-connect.png)
Click the `Connect Jumpcloud` button to begin the configuration process.
![NetBird Jumpcloud Getting Started](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-scim-getting-started.png)
Click `Get Started` to launch the configuration wizard. You will be guided through several configuration options:
Click the `Connect Jumpcloud` button, then `Get Started` to launch the configuration wizard. You will be guided through several configuration options:
**Groups to be synchronized**
By default, all groups assigned to the NetBird application in JumpCloud will be synchronized. If you want to synchronize only assigned groups that start with a specific prefix, you can specify them in the filter. Keep in mind that the prefix matching is case-sensitive.
![NetBird Jumpcloud Group Filter](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-scim-group-filter.png)
![The NetBird wizard step for filtering which groups to synchronize by prefix](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-scim-group-filter.png)
Click `Continue` to proceed to the next step.
@@ -53,19 +49,17 @@ Click `Continue` to proceed to the next step.
By default, all users from the groups assigned to the NetBird application will be synchronized. If you want to further filter and synchronize only users from specific assigned groups, you can specify those group names in the filter. The group name matching is case-sensitive.
![NetBird Jumpcloud User Group Filter](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-scim-user-group-filter.png)
Click `Continue` to generate your SCIM credentials.
**SCIM Credentials**
NetBird will generate the SCIM credentials required to configure JumpCloud. Make note of both the **Base URL** and **Token Key** as you will need them in the next section to complete the JumpCloud configuration.
![NetBird Jumpcloud SCIM Credentials](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-scim-credentials.png)
![The NetBird wizard showing the generated SCIM Base URL and Token Key](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-scim-credentials.png)
Click `Finish Setup` to complete the NetBird SCIM configuration.
![NetBird Jumpcloud SCIM Enabled](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-scim-enabled.png)
![The Identity Provider Sync tab showing the JumpCloud integration enabled](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-scim-enabled.png)
You can now proceed to configure the SCIM application in JumpCloud using the credentials generated above.
@@ -82,14 +76,12 @@ In the **Configuration Settings** section, enter the following SCIM Service Prov
* **Token Key**: Paste the Bearer token you copied from NetBird
* **Test User Email**: Provide a new, unused email address for testing (e.g., `test@yourdomain.com`)
![JumpCloud SCIM Configuration](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-scim-config.png)
![The JumpCloud Identity Management tab with the SCIM Base URL, Token Key, and Test User Email filled in](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-scim-config.png)
* Click `Test Connection` to verify the SCIM connection
If the connection is successful, you'll see a success message. Click `Activate` to enable SCIM provisioning.
![JumpCloud SCIM Test Success](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-scim-activated.png)
## Assigning Groups for SCIM Synchronization
To enable SCIM synchronization of groups and their memberships to NetBird, you need to assign user groups to the NetBird SCIM application.
@@ -101,8 +93,6 @@ In your [JumpCloud admin console](https://console.jumpcloud.com/):
* Select the groups whose members you want to synchronize to NetBird
* Click `Save` to apply the changes
![JumpCloud Assign Groups](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/jumpcloud-assign-groups.png)
Once saved, JumpCloud will automatically synchronize the selected groups and their user memberships to NetBird.
## Verify Synchronization
@@ -110,8 +100,6 @@ Once saved, JumpCloud will automatically synchronize the selected groups and the
After assigning groups in JumpCloud, the synchronization will begin automatically. You can verify that users and groups
have been successfully synchronized by navigating to `Team > Users` in your NetBird dashboard.
![NetBird Verify Users](/docs-static/img/manage/team/idp-sync/jumpcloud-sync/netbird-verify-users.png)
<Note>
SCIM provisioning will manage only resources that are created through Jumpcloud. Any resources created directly in NetBird will not be managed by SCIM.
</Note>
@@ -23,7 +23,7 @@ Before you begin the integration process, ensure you have the necessary permissi
Once the SCIM plugin is installed, you should see the SCIM section available in your Keycloak admin console.
![Keycloak SCIM Installed](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-installed.png)
![The Keycloak admin console sidebar showing the SCIM section added by the plugin](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-installed.png)
## Setting Up SSO with Keycloak
@@ -35,19 +35,15 @@ Once SSO is configured, and you can successfully log in to NetBird using your Ke
To enable SCIM synchronization in NetBird, navigate to `Integrations > Identity Provider Sync` in your NetBird dashboard.
![NetBird Keycloak Integration](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-connect.png)
![The Identity Provider Sync tab with the Connect Generic SCIM button](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-connect.png)
Click the `Connect Generic SCIM` button to begin the configuration process.
![NetBird Keycloak Getting Started](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-getting-started.png)
Click `Get Started` to launch the configuration wizard. You will be guided through several configuration options:
Click the `Connect Generic SCIM` button, then `Get Started` to launch the configuration wizard. You will be guided through several configuration options:
**Groups to be synchronized**
By default, all groups mapped in the Keycloak SCIM client will be synchronized. If you want to synchronize only groups that start with a specific prefix, you can specify them in the filter. Keep in mind that the prefix matching is case-sensitive.
![NetBird Keycloak Group Filter](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-group-filter.png)
![The NetBird wizard step for filtering which groups to synchronize by prefix](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-group-filter.png)
Click `Continue` to proceed to the next step.
@@ -55,19 +51,17 @@ Click `Continue` to proceed to the next step.
By default, all users from the mapped groups will be synchronized. If you want to further filter and synchronize only users from specific groups, you can specify those group names in the filter. The group name matching is case-sensitive.
![NetBird Keycloak User Group Filter](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-user-group-filter.png)
Click `Continue` to generate your SCIM credentials.
**SCIM Credentials**
NetBird will generate the SCIM credentials required to configure Keycloak. Make note of both the **Base URL** and **Token Key** as you will need them in the next section to complete the Keycloak configuration.
![NetBird Keycloak SCIM Credentials](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-credentials.png)
![The NetBird wizard showing the generated SCIM Base URL and Token Key](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-credentials.png)
Click `Finish Setup` to complete the NetBird SCIM configuration.
![NetBird Keycloak SCIM Enabled](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-enabled.png)
![The Identity Provider Sync tab showing the Generic SCIM integration enabled](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-enabled.png)
You can now proceed to configure the SCIM client in Keycloak using the credentials generated above.
@@ -77,12 +71,8 @@ To configure SCIM in Keycloak, you need to access the SCIM Administration Consol
Navigate to the SCIM Administration Console. On the first login screen, enter your realm name (e.g., `netbird`) and click `Start Login`.
![Keycloak SCIM Login](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-login.png)
Once logged in, navigate to the `SCIM Client` menu and click on `Remote SCIM Provider`. Then click the `+` button to add a new service provider configuration.
![Keycloak SCIM Remote Provider](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-remote-provider.png)
In the SCIM Remote Provider Configuration form, fill out the following sections:
**SCIM Provider Details:**
@@ -95,7 +85,7 @@ In the SCIM Remote Provider Configuration form, fill out the following sections:
* **Base URL**: Paste the Base URL you copied from NetBird (e.g., `https://api.netbird.io/api/scim/v2`)
* **Hostname-Verifier Enabled**: Enable this checkbox
![Keycloak SCIM Configuration](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-config.png)
![The Keycloak SCIM Remote Provider Configuration form with provider and connection details filled in](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-config.png)
**Authentication:**
* **Authentication Type**: Select `Long Life Bearer Token Authentication`
@@ -103,20 +93,10 @@ In the SCIM Remote Provider Configuration form, fill out the following sections:
Click `Add` to save the configuration.
![Keycloak SCIM Authentication](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-authentication.png)
After adding the configuration, click `Save Configuration` and then click `Use default Configuration` to apply the settings.
The default schema for the SCIM provider will be created automatically.
![Keycloak SCIM Default Schema](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-default-schema.png)
Next, assign the SCIM provider to your realm. Click the `Realm Assignment` tab to view all available realms.
![Keycloak SCIM Realm Assignment](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-realm-assignment.png)
Find your realm (e.g., `netbird`) and click `Assign to Realm` to enable SCIM synchronization for that realm.
![Keycloak SCIM Realm Assigned](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-realm-assigned.png)
Next, assign the SCIM provider to your realm. Click the `Realm Assignment` tab to view all available realms, find your realm (e.g., `netbird`), and click `Assign to Realm` to enable SCIM synchronization for that realm.
## Configure Resource Filtering
@@ -126,8 +106,6 @@ To control which specific groups and users should be synchronized, you need to c
Under the `SCIM Client` menu section, click on `Remote SCIM Provider`, then click `Edit` in the NetBird provider row.
Select the `Resource Filtering Rules` tab.
![Keycloak SCIM Resource Filtering](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-resource-filtering.png)
**User Filtering**
To synchronize only users from specific groups, configure the user filtering rule and click `Save Configuration`:
@@ -146,7 +124,7 @@ To synchronize only groups that match specific criteria, configure the group fil
* **Comparator**: Select `Contains`
* **Comparison Value**: Enter the text that should be contained in the group name
![Keycloak SCIM Filtering Configuration](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-filtering-config.png)
![The Keycloak Resource Filtering Rules tab with a user filter and a group filter configured](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-filtering-config.png)
## Initial Sync
@@ -160,7 +138,7 @@ Confirm the following settings:
* **Identifier**: Set to `Username`
* **Synchronization Strategy**: Set to `Get and (update or create) Strategy`
![Keycloak SCIM User Sync Settings](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-user-sync-settings.png)
![The Keycloak User Synchronization settings with Identifier and Synchronization Strategy selected](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-user-sync-settings.png)
Click `Count local and remote resources` to validate that the **Local User Count** and **Remote User Count** values are as expected.
@@ -174,8 +152,6 @@ Confirm the following settings:
* **Operation Type**: Set to `Create Group`
* **Synchronization Strategy**: Set to `Get and (update or create) Strategy`
![Keycloak SCIM Group Sync Settings](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-group-sync-settings.png)
Click `Count local and remote resources` to validate that the **Local Group Count** and **Remote Group Count** values are as expected.
Once validated, click `Synchronize all resources from startIndex` to sync all groups.
@@ -188,8 +164,6 @@ Confirm the following settings:
* **Operation Type**: Set to `Update Group Members`
* **Synchronization Strategy**: Set to `Get and (update or create) Strategy`
![Keycloak SCIM Group Membership Sync Settings](/docs-static/img/manage/team/idp-sync/keycloak-sync/keycloak-scim-group-membership-sync-settings.png)
Click `Count local and remote resources` to validate that the **Local Group Count** and **Remote Group Count** values are as expected.
Once validated, click `Synchronize all resources from startIndex` to sync all group memberships.
@@ -198,8 +172,6 @@ Once validated, click `Synchronize all resources from startIndex` to sync all gr
After completing the initial sync, you can verify that users and groups have been successfully synchronized by navigating to `Team > Users` in your NetBird dashboard.
![NetBird Verify Users](/docs-static/img/manage/team/idp-sync/keycloak-sync/netbird-verify-users.png)
<Note>
SCIM provisioning will manage only resources that are created through Keycloak. Any resources created directly in
NetBird will not be managed by SCIM.
@@ -207,4 +179,4 @@ After completing the initial sync, you can verify that users and groups have bee
<Note>
Synced groups will only be available for membership and will not change the role of user in NetBird
</Note>
</Note>
+15 -75
View File
@@ -20,8 +20,7 @@ to synchronize users and groups smoothly.
To set up SSO, go to `Integrations` in the NetBird admin console's left menu to access the Identity Provider integration page. Click the `Connect Okta` button to get started with the Okta-NetBird integration. This will open a pop-up window with detailed instructions on synchronizing NetBird and Okta.
![NetBird Okta Integration](/docs-static/img/manage/team/idp-sync/okta-sync/nwutb3Z.png)
![The Okta card on the Identity Provider Sync tab with its Connect Okta button](/docs-static/img/manage/team/idp-sync/okta-sync/nwutb3Z.png)
## Prerequisites
@@ -40,44 +39,21 @@ To check your user permissions in Okta:
Confirm that you have one of the required roles before proceeding with the integration.
![Okta Check User Permissions](/docs-static/img/manage/team/idp-sync/okta-sync/AGPXpZN.png)
## Installing the NetBird Integration
Once you have the necessary permissions, you can set up the NetBird application. First, on NetBird, click `Continue →` to show a summary of the necessary steps.
![NetBird Connect NetBird with Okta](/docs-static/img/manage/team/idp-sync/okta-sync/dlgCUXo.png)
Let's go through them one by one:
* In Okta’s admin dashboard, click `Applications` in the left menu.
* Select `Applications` from the submenu.
* Click the `Browse App Catalog` button.
![Okta Browse App Catalog](/docs-static/img/manage/team/idp-sync/okta-sync/fkSaYnn.png)
In the app catalog, enter "NetBird" in the search bar. Then, click the `Add Integration` button.
![Okta NetBird App](/docs-static/img/manage/team/idp-sync/okta-sync/dgxJ916.png)
Accept the default application name and click the `Done` button. On the next screen, click the `Assign` dropdown and select `Assign to People`.
![Okta Assign People To NetBird App](/docs-static/img/manage/team/idp-sync/okta-sync/WQ8O1l7.png)
You will see a list of users. Find your user account, click `Assign`, and save the changes. Verify your user is assigned to the NetBird app and click `Done`.
![Okta Verify User Added To NetBird](/docs-static/img/manage/team/idp-sync/okta-sync/bteoM6j.png)
After that, you will see your user listed in the NetBird application.
![Okta User Added To NetBird App](/docs-static/img/manage/team/idp-sync/okta-sync/IwaqFvj.png)
You will see a list of users. Find your user account, click `Assign`, and save the changes. Verify your user is assigned to the NetBird app and click `Done`. Your user now appears on the NetBird application's `Assignments` tab.
## Configuring SSO in Okta
@@ -85,28 +61,22 @@ The next step is to configure Okta-NetBird SSO integration.
In NetBird, click the `Continue →` button. A new wizard screen will appear, offering the instructions for retrieving Okta’s OpenID Connect credentials. You can click `Close` and navigate to Okta.
![NetBird Connect NetBird with Okta Sharing Credentials](/docs-static/img/manage/team/idp-sync/okta-sync/AYVAbEy.png)
* Click on the `Sign On` tab on Okta. Look for `OpenID Connect` under `Sign on methods` in the `Settings` section.
* Copy the `Client ID` value.
* Copy the `Client Secret` value.
Store these credentials securely, as you will need them soon.
![Okta Copy Credentials](/docs-static/img/manage/team/idp-sync/okta-sync/rl5Gelc.png)
![The Sign On tab of the NetBird app in Okta, showing the OpenID Connect Client ID and Client Secret](/docs-static/img/manage/team/idp-sync/okta-sync/rl5Gelc.png)
* Click `Edit` in the `Settings` section.
* In `Credential Details`, change the `Application username format` from `Okta username` to `Email`.
* Click the `Save` button
![Okta OpenID Credential Details](/docs-static/img/manage/team/idp-sync/okta-sync/FWPf0Cu.png)
![The Credential Details section with Application username format set to Email](/docs-static/img/manage/team/idp-sync/okta-sync/FWPf0Cu.png)
* On the top right, click on your username
* Copy your [Okta account domain](https://developer.okta.com/docs/guides/find-your-domain/main/) as shown below:
![Okta Copy Domain](/docs-static/img/manage/team/idp-sync/okta-sync/eITyobI.png)
* Copy your [Okta account domain](https://developer.okta.com/docs/guides/find-your-domain/main/), shown under your email address in that menu, for example `trial-1234567.okta.com`.
The final step is to [send an email to the NetBird team](support@netbird.io) with the authentication information you just retrieved:
@@ -121,47 +91,29 @@ This completes the first stage, enabling Single Sign-On (SSO) from NetBird's log
## Enabling Okta SCIM in NetBird
In NetBird, go to `Integrations > Identity Provider` and click on the `Connect to Okta` button.
![NetBird Connect to Okta](/docs-static/img/manage/team/idp-sync/okta-sync/QbzudIU.png)
You will see a reminder of the permissions your user will require in Okta. Click the `Get Started →` button to continue.
![NetBird User Permissions](/docs-static/img/manage/team/idp-sync/okta-sync/RBsJlzu.png)
If you haven't already, you'll need to set up SSO in Okta. If you've completed the previous section, skip this step and click the `Continue →` button.
![NetBird SSO in Okta](/docs-static/img/manage/team/idp-sync/okta-sync/XYpJYW3.png)
In NetBird, go to `Integrations > Identity Provider Sync` and click the `Connect Okta` button again. The first screen reminds you of the permissions your user needs in Okta. Click `Get Started →`. The next screen covers the SSO setup from the previous section, so click `Continue →` to skip it.
The next screen will show you how to enable NetBird API credentials in Okta. Copy the value of the `Authorization (Bearer)` token.
![NetBird Enable Okta SCIM](/docs-static/img/manage/team/idp-sync/okta-sync/aoPqKJR.png)
![The NetBird wizard step showing the Authorization (Bearer) token to copy into Okta](/docs-static/img/manage/team/idp-sync/okta-sync/aoPqKJR.png)
Navigate to the NetBird app in your Okta admin dashboard. Click the `Provisioning` tab, then select `Configure API Integration`.
![Okta Provisioning](/docs-static/img/manage/team/idp-sync/okta-sync/m27djab.png)
Follow these steps:
* Check the box to enable API Integration.
* Enter your NetBird API Token.
* Click `Test API Credentials` to verify the SCIM connection.
![Okta Entering NetBird Bearer Token](/docs-static/img/manage/team/idp-sync/okta-sync/Wn6f9Pj.png)
![The Okta API Integration form with Enable API integration checked and the token entered](/docs-static/img/manage/team/idp-sync/okta-sync/Wn6f9Pj.png)
If everything works as expected, you'll see the message: "NetBird was verified successfully!" as shown below. Click `Save` to continue.
![Okta Token Accepted](/docs-static/img/manage/team/idp-sync/okta-sync/7ELQBIA.png)
If everything works as expected, Okta shows the message "NetBird was verified successfully!". Click `Save` to continue.
## Configuring SCIM Provisioning to NetBird
On NetBird, click `Continue →`. You'll see instructions for configuring SCIM provisioning to NetBird.
![NetBird Configure SCIM provisioning to NetBird](/docs-static/img/manage/team/idp-sync/okta-scim-provisioning.png)
Back to Okta, click `Edit` as shown below.
![Okta Edit NetBird App](/docs-static/img/manage/team/idp-sync/okta-sync/AcuWP2G.png)
Back in Okta, stay on the `Provisioning` tab, select `To App` in the left-hand `Settings` list, and click `Edit` next to `Provisioning to App`.
Enable Okta to create, update, and deactivate NetBird users by checking the corresponding boxes:
@@ -171,45 +123,33 @@ Enable Okta to create, update, and deactivate NetBird users by checking the corr
When done, click `Save`.
![Okta Enable Create Users and More](/docs-static/img/manage/team/idp-sync/okta-sync/JD0EHVI.png)
![The Provisioning to App settings with Create Users, Update User Attributes, and Deactivate Users enabled](/docs-static/img/manage/team/idp-sync/okta-sync/JD0EHVI.png)
## Assigning NetBird Application to Okta Groups
In NetBird, click `Continue →`, you'll see the steps for assigning the NetBird integration to Okta groups.
![NetBird Sync Groups to NetBird](/docs-static/img/manage/team/idp-sync/okta-sync/fLHSNsd.png)
* Navigate to the `Assignments` tab.
* Similar than before when you assigned your user to NetBird app, click the `Assign` button
* This time, select `Assign to Groups`.
* Select Okta groups that you want to assign to the NetBird app.
![Okta Assign NetBird to Groups](/docs-static/img/manage/team/idp-sync/okta-sync/yGV0u5Y.png)
Once you assign the desired groups, click `Done`. You'll see the selected groups listed in Okta.
![Okta NetBird Groups](/docs-static/img/manage/team/idp-sync/okta-sync/mxkdWc0.png)
Once you assign the desired groups, click `Done`. The selected groups appear on the `Assignments` tab.
## Push Okta Groups to NetBird
One more time, go to NetBird and click `Continue →`. You'll see the final instructions to push Okta groups to NetBird.
![NetBird Sync Groups to NetBird](/docs-static/img/manage/team/idp-sync/okta-sync/8TAvguS.png)
* In Okta, navigate to `Push Groups` tab
* Click the `Push Groups` button
* Select `Find groups by name`
* Search for specific groups to push to NetBird.
![XX](/docs-static/img/manage/team/idp-sync/okta-sync/uqUiTtg.png)
![The Push Groups tab with the Push Groups dropdown open on Find groups by name](/docs-static/img/manage/team/idp-sync/okta-sync/uqUiTtg.png)
Once you finish, go back to NetBird and click `Finish Setup`. You can verify the synchronization by navigating to `Team > Users`
Once you finish, go back to NetBird and click `Finish Setup`. You can verify the synchronization by navigating to `Team > Users`. The users listed in NetBird should match those assigned to the app in Okta.
![XX](/docs-static/img/manage/team/idp-sync/okta-sync/GPTzvut.png)
The users listed in NetBird should match those you created in Okta.
![XX](/docs-static/img/manage/team/idp-sync/okta-sync/O1aoILr.png)
![The NetBird Users table listing the users pushed from Okta](/docs-static/img/manage/team/idp-sync/okta-sync/GPTzvut.png)
<Note>
SCIM provisioning will manage only resources that are created through Okta. Any resources created directly in NetBird will not be managed by SCIM.