Provision Users and Groups with OneLogin (SCIM)

Updated 3 weeks ago by Rashmi Nanda Sahoo

You can use OneLogin to provision users and groups in Harness.

Harness' SCIM integration enables OneLogin to serve as a single identity manager for adding and removing users. This is especially efficient for managing large numbers of users.

This topic describes how to set up OneLogin provisioning for Harness Users and User Groups.

In this topic:

Before You Begin

Step 1: Add Harness App to OneLogin​

The first step is adding the Harness app to your OneLogin Applications.

  1. In Applications, click Add App.
  2. Search for Harness. The Harness Application appears.
  3. Click the Harness app to open its Configuration page and click Save.

When you are done, the Harness OneLogin app appears.

For more information on adding apps, see OneLogin's documentation: Introduction to App Management.

Step 2: SCIM Base URL

Next, add a special Harness account URL to the OneLogin app's SCIM Base URL.

  1. Log into your Harness account.
  2. Copy the Harness account ID from the Account Overview of your Harness account.
  3. Add your account ID to the end of the following URL:<account_ID>
For Harness On-Prem, the URL will use your custom domain name and gateway is omitted. For example, if your On-Prem domain name is harness.mycompany.com<account_ID>
  1. Copy the full URL.
  2. In OneLogin, open the Harness OneLogin app.
  3. Click Configuration.
  4. In SCIM Base URL, paste the Harness URL you copied.

Next, we will use a Harness API access key for the SCIM Bearer Token setting in your Harness OneLogin app.

Step 3: SCIM Bearer Token

The SCIM Bearer Token value is used to authenticate requests and responses sent between the OneLogin SCIM provisioning service and Harness.

  1. In Harness Manager, create an API token by following the instructions in Add and Manage API Keys.
  2. Copy the new API token.
  3. In OneLogin, paste the API token in the SCIM Bearer Token setting in your Harness OneLogin app.
  4. Ensure that the API Status is enabled and click Save.

Step 4: Set Up Harness OneLogin App Provisioning

Next, you will set the required provisioning settings for the Harness OneLogin app.

Ensure these settings are set up exactly as shown below.

  1. In the Harness OneLogin app, click Provisioning.
  2. In Workflow, ensure the following are selected:
  • Enable provisioning
  • Create user
  • Delete user
  • Update user
  • When users are deleted in OneLogin, or the user's app access is removed, perform the below action: Delete.
  • When user accounts are suspended in OneLogin, perform the following action: Suspend.

When you are done, it will look like this:

  1. Click Save.

Option: Provision OneLogin Users to Harness

Next, we will add users to the Harness OneLogin app. Once OneLogin SSO is enabled in Harness, these users will be provisioned in Harness automatically.

  1. In OneLogin, click Users.
  2. Click a user.
  3. In User Info, ensure that the user has First nameLast name, and Email completed.
Only First nameLast name, and Email are permitted for Harness OneLogin SCIM provisioning. Do not use any additional User Info settings.
  1. Click Applications.
  2. In the Applications table, click the add button (+).
  3. In the Assign new login settings, select the Harness OneLogin App and click Continue.
  4. In NameID, enter the email address for the user. This is the same email address in the NameID setting.
  5. Click Save. The status in the Applications table is now Pending.
  6. Click Pending. The Create User in Application settings appear.
  7. Click Approve. The Provisioning status will turn to Provisioned.

If provisioning fails, you might see something like the following error:

The most common reason is incorrect SCIM Base URL or SCIM Bearer Token settings in the OneLogin app.

Verify Provisioning in Harness

Now that you have provisioning confirmation from OneLogin, let's verify that the provisioned user is in Harness.

  1. In Harness, click Account Settings, and then select Access Control.
  2. Click Users.
  3. Locate the provisioned user.

The provisioned users will receive an email invite from Harness to sign up and log in.

Option: Provision OneLogin Roles to Harness Groups

You can create, populate, and delete Harness User Groups using OneLogin.

Due to OneLogin currently not supporting group deletion via SCIM, you must remove User Groups using OneLogin. If you try to delete OneLogin-provisioned User Groups within Harness, you will get the error message, Cannot Delete Group Imported From SCIM. Once the group is removed from OneLogin, contact Harness Support to have it removed from Harness.

To perform Harness User Group provisioning using OneLogin, you assign the Harness OneLogin app and OneLogin users to a OneLogin role.

Next, you create a rule in the Harness OneLogin app that creates groups in Harness using the role.

The OneLogin roles become User Groups in Harness.

You cannot provision OneLogin users to Harness User Groups if they are already provisioned in Harness. Simply remove them from Harness and then provision them using the step below.

Add User Provisioning to the Harness OneLogin App

  1. Ensure the Harness OneLogin app is added and configured as described in steps 1 through 5 in this topic.
  2. In OneLogin, open the Harness OneLogin app.
  3. In Parameters, in Optional Parameters, click on Groups.
  4. In Edit Field Groups, select Include in User Provisioning and click Save.
  5. Click Save to save the Harness OneLogin app.

Next, we'll create the OneLogin role that will be used as your Harness User Group.

Create OneLogin Role

  1. In OneLogin, click Users and select Roles.
  2. Click New Role.
  3. Enter a name for the new role and click Save.
  4. In Roles, open the new role.
  5. Click Users.
  6. In Check existing or add new users to this role, enter the name(s) of the users to add.
  7. When you have located each user name, click Check.
  8. For each user, click Add to Role. When you are done, the user(s) are listed in Users Add Manually.
  9. Click Save. You are returned to the Roles page.
  10. Open the role.
  11. In the role, click Applications.
  12. Click the Add Apps button.
  13. In Select Apps to Add, click the Harness OneLogin app.
  14. Click Save.

Now that the role has users and the Harness OneLogin app, we can add the Harness OneLogin app to each OneLogin user.

Add Harness OneLogin app to Users

For each of the OneLogin users you have added to the role, you will now add the Harness OneLogin app.

  1. In OneLogin, click Users, and then select each user you want to add.
  2. On the user's page, click Applications.
  3. Click the Add App button.
  4. In Assign new login, select the Harness OneLogin app, and click Continue.
  5. In the Edit settings, in Groups, select the role you created and click Add.
  6. Click Save.

Now that each user is associated with the Harness OneLogin app and role, you will learn /add a rule to the Harness OneLogin app. The rule will set groups in the Harness OneLogin app using the role you created.

Add Rule to Harness OneLogin App

Next, you create a rule in the Harness OneLogin app to create groups using the role you created.

  1. Click Application, and then select the Harness OneLogin app.
  2. In the app, click Rules.
  3. Click Add Rule.
  4. Name the rule.
  5. In Actions, select Set Groups in [Application name].
  6. Select Map from OneLogin.
  7. In For each, select role.
  8. In with value that matches, enter the name of the role you create or enter the regex .*.
  9. Click Save.
  10. Click Save to save the app.
If you have created users prior to adding the mapping rule, click Reapply Mappings in your Harness application User settings:

Now that the app has a rule to set groups in Harness using the role you created, you can begin provisioning users using the app.

Provision Users in Application

Each of the OneLogin users that you added the Harness OneLogin app to can now be provisioned.

  1. In the Harness OneLogin app, click Users. The users are listed as Pending.
  2. Click each user and then click Approve.

The Provisioning State for each user is changed to Provisioned.

See the Provisioned User Group in Harness

Now that you have provisioned users using the Harness OneLogin app, you can see the new group and users in Harness.

  1. In Harness, click Access Management.
  2. Click User Groups.
  3. Locate the name of the User Group. It is named after the role you created. Click the User Group.

You can see the User Group and Users that are provisioned.

Repeat the steps in this process for additional users.


This integration does not support updating a provisioned user's Email in OneLogin. Once the user is provisioned in Harness, the user's email address must remain the same. If you change the email address in OneLogin and then try to remove the user from Harness, the removal will fail.

Once a user is provisioned in Harness, you cannot delete the user in the Harness Manager. You must delete the user in OneLogin.

The provisioned user cannot use the Harness OneLogin app to log into Harness unless OneLogin is also set up for OneLogin SAML authentication in Harness. They must use their email address and password.

Copy Groups

When you provision groups using OneLogin, they get added to your Account scope. To add them to your Org or Project scope, use the Copy option. This copies the specified group to the desired scope.

Any modifications you make to this User Group through SCIM are reflected in the User Groups in the Account scope as well as all other scopes where it has been copied.

Here is an example to copy a group from the Account scope to Organization scope:

In Harness, go to Account Settings->Access Control. Click User Groups.

Click more options () next to the User Group you want to copy.

Click Copy. The Copy group settings appear.

Select the Organization where you want this User Group to be copied.

To copy User Group to Projects within the scope of this Organization, click Copy to project(s) and then select Projects.

At any one moment, you can copy a User Group to a single Organization and numerous Projects.

Click Save.

The User Group and its members are copied to the selected Organization.

If you click Copy to project(s), the User Group is copied only to the selected projects and not the Organization.

Assign Permissions Post-Provisioning

Permissions can be assigned manually or via the Harness API:

Please Provide Feedback