๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

Set up single sign-on and automatic user provisioning

A task guide: the pages to use, in order.

Flow: register Lavawall as an OpenID Connect app with your identity provider, enter the issuer, client ID, domains and secret, test discovery, switch sign-on on, test it, then require it and add a SCIM token so accounts are created and deactivated automatically.
The same steps are listed below, with links to each page's article.

Steps

  1. Copy the redirect URI. Identity provider tab
  2. Create an OIDC web app at your provider. Authorization code with PKCE; scopes openid, email, profile
  3. Enter issuer, client ID, domains and secret. Save secret, then Save settings
  4. Click Test discovery. It should read your signing keys
  5. Switch single sign-on on and test it yourself. Use a private browser window
  6. Create a SCIM token. SCIM provisioning tab; copy it once
  7. Check new accounts arrive. Deactivated users show as Locked
  8. Turn on Require single sign-on. Password sign-in is refused for your domains

Articles for the pages in this guide

← All task guides