Skip to main content
This is feature is only available if you are on the Enterprise tier or above. See Astro Plans and Pricing.
Astro supports integration with the open standard System for Cross-Domain Identity Management (SCIM). Using the SCIM protocol with Astro allows you to automatically provision and deprovision users and Teams based on templates for access and permissions. It also provides better observability through your identity provider for when users and Teams are created or modified across your organization. Specifically, you can utilize SCIM provisioning to complete the following Astro actions from your identity provider platform:
  • Create and remove users in your Organization.
  • Update user profile information.
  • Create and remove Astro Teams.
  • Add and remove Team members.
  • Retrieve user and Team information.
Some user management features on Astro behave differently after you set up SCIM provisioning. See Manage Teams for more information. Astro doesn’t support group nesting for SCIM provisioning. Access levels assigned to parent groups don’t automatically propagate to child groups, so each group must be individually assigned the required access levels.

SCIM and existing Astro users

If you set up SCIM provisioning for an Organization that already has users, your IdP sends a create-user request for each user it provisions. When the email in the request matches an existing Astro user, Astro links that user to your IdP instead of creating a new user. Linking changes the user’s Organization role:
  • Astro sets the user’s Organization role to Organization Member and marks the user as IdP-managed. This happens even if the user was an Organization Owner. To keep a user as an Organization Owner, reassign the role in Astro after the user is linked.
  • Astro doesn’t change the user’s Workspace or Deployment roles. Only the Organization role is overwritten.
  • If the user is the last Organization Owner in the Organization, Astro rejects the request and doesn’t change the user. Assign the Organization Owner role to another user before you provision the last Owner through SCIM. Teams with the Organization Owner role don’t count toward this check.
After a user is linked, Astro handles user updates from your IdP as follows:
  • Astro ignores activate, deactivate, and profile updates for a user who is currently an Organization Owner. Revoking or suspending an Organization Owner in your IdP doesn’t remove them from the Organization. To remove an Organization Owner, remove the user in Astro.
  • If your IdP sends a delete request instead of deactivating the user, Astro removes the user regardless of their Organization role. Okta doesn’t send delete requests, but Microsoft Entra ID does.
  • When your IdP deactivates a user, Astro removes the user from the Organization. This removes their Organization, Workspace, and Deployment roles, their Team memberships, and any pending invite for that Organization. If the user doesn’t belong to any other Organization, Astro deletes the user record.

Supported SSO identity providers

Astro supports SCIM provisioning with the following IdPs:

Supported Okta features

Okta’s Astro integration supports the following SCIM actions:
  • Create users
  • Update user attributes
  • Deactivate users
  • Group push

Prerequisites

Setup

Frequently asked questions

  1. In the Okta dashboard, open the Astro application and click Push Groups.
  2. Click the value in Push Status for the group that’s out of sync, then click Push now.
If you removed an Okta user but their Astro account remains, delete the account from Astro.If an Astro user isn’t appearing for an Okta user as expected, remove and re-assign the user in Okta.