Okta

Configuring Provisioning for ZScaler

This guide provides the steps required to configure Provisioning for ZScaler.

Important:

This application has been deprecated and is no longer supported by Okta. Instead, please use the Zscaler 2.0 OIN integration as this integration will receive future enhancements and is maintained by Zscaler.



Contents


Features

The following provisioning features are supported:


Requirements

In ZScaler

Before you configure provisioning for ZScaler you need to obtain an Organization ID, as follows:

  1. Login into your ZScaler account.

  2. Navigate to the Administration > Company Profile page:

    zscaler2.png

  3. Locate the Company ID field, and make a copy of the digital part of the value, as shown below, you will need to enter it into Okta:

    zscaler3.png

In Okta

Before you configure provisioning, make sure you have added the ZScaler app, and have configured the General Settings and Sign On options properly, as described below:

  1. Navigate to Admin > Add Application.

  2. Locate the ZScaler application and add it. If you cannot find the application, contact OKTA support to add it to your organization.

  3. Select the General Settings tab, then click Edit and enter the following:

    • Your ZScaler Domain: Provide your ZScaler domain.

    • User Display Name (optional): Select the push option to have ZScaler Display Name set to Okta user's first and last name.

    • Department Name (optional): Select the department attribute value from Okta to map to the SAML Response Attribute statement.

    • Group Name (optional): When push is enabled, Okta will send the user's groups to ZScaler (up to 128 items). Use the Group Filter to only send groups that match the configured regular expression.

    • Group Filter (optional): Create an expression that will be used to filter groups. If the Okta Group Name matches the expression, the group name will be included in the SAML Response Attribute statement,

      For Example:

      zscaler.*

      This includes all groups prefixed with the string zscaler. Use regular expression syntax. Max value length is 512 characters.

    • zscalerprovisioning1.png

  4. Click Next to proceed to the Sign-On Options tab. Here no specific options are available.

  5. Click Next to proceed to the Provisioning tab. See below for Provisioning Configuration Steps.


Configuration Steps

Configure your Provisioning settings for Zscaler as follows:

  1. Check the Enable API Integration box.

  2. Enter the Company ID value you copied from ZScaler (see Requirements) into the Organization ID field:

    zscalerprovisioning2.png

  3. Select To App in the left panel, then select the Provisioning Features you want to enable:

    zscalerprovisioning3.png

  4. Click Next to proceed to the Import Users tab.

  5. Assign people to the app, if needed, then click Finish to complete provisioning configuration.


Schema Discovery

ZScaler does not support User Schema Discovery.