USM Content
Okta Directory
The integration with Okta Directory allows System Admins to simplify user management in Smartsheet by synchronizing with their Okta Directory service. This integration is based on the System for Cross-domain Identity Management (SCIM), an industry-standard in identity management.
System Admins can easily add, change, and remove users from Smartsheet using information from their existing Directory service, ensuring that users can no longer access Smartsheet after they are removed from your enterprise directory. This approach minimizes the time spent on user management and leverages automated processes developed by IT for efficient user administration.
SCIM is different from Single Sign On (SSO). When used together, SSO and SCIM enhance account security and significantly reduce the time System Admins spend managing users. For further details regarding SSO, check out the SSO and SAML best practices guide.
Use cases
Here's how Okta Directory streamlines user management in Smartsheet:
- Provisioning users: Leverage Okta directory groups to provision users to Smartsheet with the right role
- Managing user profile data: Synchronize user profile data into their Smartsheet user profile, including first name, last name, user name, primary email, alternate email, title, Cost center, division, and department. Phone numbers can’t be synced.
- Managing user access and permissions: When a user is deprovisioned in your Okta enterprise directory, they can no longer access Smartsheet, and their user status in Smartsheet will be updated to read “deactivated.”
- Any content the deactivated user owns will remain in the same hierarchy, and any solutions built using referential links to those items will continue to work
- Deactivated users can also be reactivated
- Deprovisioned users aren't fullly deleted. To completely remove a deactivated user, you must temporarily deactivate the Okta Directory Integration within the Smartsheet Admin Center, remove the user, and re-activate Okta Directory.
Known limitations
Key considerations include:
- The Okta Directory integration with Smartsheet is not available for Smartsheet Gov or Enterprise Plan Manager
- Access to Smartsheet add-ons can’t be managed through Okta Directory
Importing or updating groups from Okta Directory is only supported through the Smartsheet V3 endpoint. These group syncs are unidirectional, operating only from Okta to Smartsheet.
- For Smartsheet US, use https://scim.smartsheet.com/v3
- For Smartsheet EU, use https://scim.smartsheet.eu/v3
Alternatively, you can manually create or update Smartsheet-specific groups within Smartsheet.