This page explains how to configure enterprise SSO (SAML) and SCIM provisioning for Genezio, and how the two operate after the setup. With enterprise SSO, your team signs in to Genezio through your own identity provider (IdP). Examples are Okta, Microsoft Entra ID, OneLogin, Ping, or any SAML 2.0 IdP. SCIM provisioning does more. It makes your IdP the source of truth for who has a Genezio account and what each person can do. You configure the two for each customer, together with the Genezio team. They are not self-serve. This page tells you these items:
  • What you must do
  • What Genezio does
  • How SSO and SCIM operate after you start to use them

What enterprise SSO and SCIM give you

Single sign-on (SAML): Your users sign in with your corporate credentials, under your own MFA policies and session policies. You do not manage a separate Genezio password. SCIM provisioning: When a person joins the correct group in your IdP, Genezio automatically creates the account of that person. When the person leaves, Genezio removes the access. You do not send invitations manually, and no accounts stay active after offboarding. Then, an account Owner sets the roles in Genezio. Refer to Roles are assigned in Genezio, not in your IdP. Most organizations want the two. They solve different problems:
  • SSO answers this question: “Is this person the person that they say?”
  • SCIM answers this question: “Must this person have an account, and what can the person do with it?”

SSO does not create accounts

SSO does not create accounts. A successful sign-in proves the identity of the person. It does not give access to your Genezio account. A first-time user can authenticate through your IdP but have no Genezio account and no pending invitation. Genezio then refuses the user and shows a message that the user needs an invitation. Thus, a user must first exist in Genezio. SCIM or an invitation from an account Owner creates the user. If you use SSO without SCIM, you must invite each user manually.

How the SSO and SCIM setup operates

Ask your Genezio representative to start the process. Genezio then does these actions:
  • It registers your email domains and creates the connection to the identity provider for your organization.
  • It sends you the two values that you need to configure the SAML application in your IdP: the Identifier (Entity ID) and the Reply URL (Assertion Consumer Service URL).
  • It enables SCIM on your account.
Until Genezio enables SCIM, your account settings do not show the SCIM entry. Then, do these steps:
1

Configure SAML

Configure SAML in your IdP with the two values. Send Genezio the SAML metadata XML of your IdP.
2

Test with one pilot user

Test with one pilot user. This user must already have a Genezio account or a pending invitation.
3

Connect SCIM

Connect SCIM with a token that you make in Genezio. Provision the same pilot user.
4

Look for email conflicts

Look for email conflicts before you provision all users. Refer to Troubleshooting.
5

Provision your team

Provision your team. Then, an Owner gives a different role to each user who needs more than the default Member role.
6

Test the offboarding

Deactivate a test user. Make sure that the user has no access.

Connect your identity provider with SAML 2.0

The SSO setup is an exchange in two directions. Genezio sends you two values, and you send Genezio one file. What Genezio gives you. Create a standard SAML 2.0 application in your IdP and enter these values: The two values are specific to the connection of your organization. Use the values that Genezio sends you. Do not copy them from a different tenant. What you send to Genezio. Export the SAML metadata XML of your IdP and send it to your Genezio representative. Genezio uses it to complete the federation. Nothing occurs until Genezio has this file. Thus, this step usually causes the delays in a rollout. If your IdP can give you only a metadata URL, tell Genezio. Genezio can use the URL. Send the email as an attribute. The email is mandatory. Send it as the NameID in the emailAddress format, as an explicit email attribute, or as the two. The display name is optional, but we recommend it. Without it, Genezio uses the part of the email before the @. The email must be exactly the same. Genezio compares the address from your IdP with the address that the user typed on the sign-in page. Upper case and lower case are not important, but all other differences are. These differences cause the sign-in to fail:
  • An alias
  • A UPN that is different from the mail attribute
  • A legacy domain
Make sure that the attribute that you send is the address that your users know as their work email. Give Genezio all domains. SSO uses email domains as the key. Thus, include secondary domains and the domains of acquired companies. Each domain connects to one identity provider. You cannot divide one domain between two identity providers. The sign-in starts at Genezio. Users go to the Genezio sign-in page and enter their work email. Genezio then sends them to your IdP. Genezio does not support a sign-in that starts at the IdP. If you want a tile in your app catalog, make the tile a bookmark to the Genezio sign-in page.

Enable SCIM provisioning

You must have the Owner role, and SCIM must be enabled on your account.
1

Open the SCIM settings

Go to Settings -> SCIM.
2

Create a token

Create a token. Give it a name that you can identify later, for example “Okta production”. Optionally, set an expiry date.
3

Copy the token

Copy the token immediately. Genezio shows it only one time, and you cannot get it again later. Only the first characters stay visible. Thus, you can identify each token.
4

Configure your IdP

In the provisioning settings of your IdP, paste the token and the base URL that Genezio shows next to it. Use bearer-token authentication.
You can do these actions on a token:
  • Rotate it: The token gets a new secret with the same name and expiry date. The old secret stops immediately.
  • Disable it and enable it again.
  • Delete it permanently.
Each token operates for only one Genezio account. It can act only on the users that it provisioned. Treat the token as a high-value credential and keep it in the secret store of your IdP.
When you disable or delete a token, provisioning stops. But no user loses access. To offboard users, first deprovision them through your IdP. Then remove the connection.

Roles are assigned in Genezio, not in your IdP

Genezio does not support SCIM groups. The SCIM implementation of Genezio includes only the lifecycle of users: it creates, updates, deactivates, and removes users. It does not have a Group resource. Thus, your IdP cannot send groups or assign roles. Each user that SCIM creates has the Member role. To give a user a different role, an account Owner changes it in the Genezio dashboard under Users. You change roles only in the application. Your IdP cannot change roles. Genezio has three account roles: Thus, provisioning and permissions are two separate tasks. Your IdP sets who has an account. An Owner sets what each user can do. For most teams, this is one step for each person, one time only. Member is the correct role for most users.

SCIM connector settings

Genezio uses SCIM 2.0. Thus, each connector that agrees with the standard operates. Configure these items:
  • Keep group provisioning and role provisioning off. Genezio shows only the User resource. Thus, a group push has no target. Be careful with Microsoft Entra ID, because it enables group mapping by default. Disable it.
  • Disable bulk operations and sorting. Genezio provisions one user at a time.
  • Keep the filters simple. Genezio supports only equality filters on a single attribute.
  • Do not synchronize passwords. SCIM users authenticate through your IdP, not with a Genezio password.
The provisioning validator of Entra shows bulk, sort, and etag as not supported. This is expected and does not stop the provisioning.

What occurs when a person leaves the organization

When you deactivate or delete a user in your IdP, Genezio immediately removes the membership of the user in the Genezio account. It also removes all permissions of the user. If this was the only Genezio account of the user, Genezio also revokes the active session. A person who is also in a different Genezio account keeps the access to that account. Know this limit: SSO does not disable the sign-in with a password. SSO gives your users one more method to sign in. It does not remove a password that a user already has, and it does not prevent its use. Today, Genezio has no setting that permits only SSO sign-in for a domain. If your security review requires this, tell Genezio before you plan the rollout. This function needs development work from Genezio. A change of the configuration is not sufficient.

Troubleshooting

Look for email conflicts. Some persons registered for Genezio themselves before your enterprise rollout. They already have an account with their work email, and their provisioning fails. Find these persons and solve the conflicts with Genezio support before you provision all users.

What to send to Genezio for the setup

For a quick setup, prepare these items:
  • All email domains that your users sign in with
  • The name of your identity provider
  • The SAML metadata XML of your IdP (Genezio cannot continue without this file)
  • The attribute that you send as the email, with a confirmation that it is the same as the work emails of the users
  • The Genezio account that SCIM must manage, and the email of its Owner