Skip to main content

Replacing SCIM Integration with Netskope REST APIv2 in Okta

  • July 10, 2025
  • 0 replies
  • 174 views

Mario Garcia
Netskope Employee
Forum|alt.badge.img+6

AD_4nXeSdNVkLxG3jrbt4Wr33CCELT8ch6fVh-hbeeNLjaPNCwjQn2inavUE0INOC27bHF7YUKyDlJBIBlQ046zW5ur-aGN9Z4hddOmvVw4q_Vd3C7hzJhpQ-faE_DZG5ek2JhM42DFlbg?key=X5IfFsa2VsQOv6Q8uswRhefy

Netskope Global Technical Success (GTS)

Replacing SCIM Integration with Netskope REST APIv2 in Okta

 

Netskope Cloud Version - 122

 

Objective

This article aims to explain how to replace the soon to be deprecated “SCIM Integration” with Netskope APIv2 for users/groups provisioning on Okta.

 

For further information, please visit the following articles:

Netskope Product EOL Announcements
SCIM Settings for User Provisioning

 

Note: EoL is targeted for 21st of March, 2025.

 

Context

SCIM integration between Netskope and Okta for the users and groups provisioning uses an OAuth token to access provisioning service in the cloud via URL: “addon-*.goskope.com/SCIM/v2”, this will be deprecated in March next year, and customers must take actions prior to its deprecation.

SCIM integration

Path: Netskope Tenant UI >>> Settings >>> Tools >>> Directory Tools >>> SCIM Integration as shown below: 

AD_4nXeOGMcGSab6MHOMtrP7WT4jFA2YjrdIl7FBQaDOznswdF9HyZf-0dMVpDCatzufEFtHx7LO9XYy5K51Ys2USANSAPEjo8EBeaobrLcRbjN0tbt0F-VuXtPHFR8Wl9LMB-S6Z3qt?key=X5IfFsa2VsQOv6Q8uswRhefy

 

Procedure

ℹ️  If your tenant has been already migrated to RBACv3 please define the Service Account with the needed API v2 endpoint as explained here: https://docs.netskope.com/en/scim-user-provisioning-with-rbacv3

 

Step 1 - Create a new token as follows:

Path: Netskope Tenant UI >>> Settings >>> Tools >>> REST API V2 AD_4nXdy4mLm2OYSFz2qljVLJIcgPA1aOluJNrhiRTFgcNo9OEdrveNP6P8k_mZ2YEgfda9ipEXYnrO_ke5DKbMOUuNqr7y0DYJFa7e0oXLlfcGxJ25hNrysI0gLpqV3UTmiy3iWW7mdzLwtynqeqAlAG5a4N04?key=DcLc5TVPBuRycojopm5_WQ

 

After that you click “SAVE”, please ensure you get the API V2 token by clicking the “COPY TOKEN” as shown below. Please make sure to store it in a safe place:

AD_4nXeE1mS1x-NeU23F63LzS7bc3i2BLGCLv0TLcJoJrVQVSP-XKBn5rqlkn7JysuWzK3sjPKrKEybyGVztgz4tfUv8V9LIZcQHEjc7InJRJqYrPUbT0gA06zeHdbBmAqRLLEfKZVPxLOT4WneUr29dNqxUrX85?key=DcLc5TVPBuRycojopm5_WQ

 

⚠️#1. Ensure that the Rest Api v2 feature is turned on AD_4nXcHb7vZVTnzmGXqBOfoZKULOhNruWqMUo6L_Cz5Mc7K1KYacSWHnn95-UaTvD63iTasSYa5RaWi8Zopw1AyrhOBTE7zcmTfe8Ak_znkHbLuAhhiaq9E6z-OYyfmBLemid4y5NLKIm7wlKf3Va1EWeiDUH0?key=DcLc5TVPBuRycojopm5_WQ

         ⚠️#2. Every REST API V2 token has an expiration  AD_4nXez0Ht9VTtWnsqK5YRCdvvBlqYhcWybeO94GxuknjmnGQsOiUFEdYL6lcNR3A6N260NLqo8o0RRn4hMjqrezzKVjyV3Y0e-HlhQrqkO0fQDRc8wGvdlOtlaEFnyK4UanCOF1S_4WYGJlYwlKIYMOVVJPhk5?key=DcLc5TVPBuRycojopm5_WQ!
remember to extend its own duration or reissue it before the expiration.

AD_4nXcGWhLHhpOIGnE0Grm_yP0o0AXPaN45Z3IaW0I8F73VcI9B5-eEgZzxMB1G6uGxhle4VraKiEb-O0-FGSdGcSOIn8WRvf5trX2j9XbJYmyfkgBc_slTonePpjcLOwMy59GA_ljzXXTfCF9AEI0tNU0H0BM?key=DcLc5TVPBuRycojopm5_WQ

 

 

Step 2. On Okta Admin Console, in Applications, locate the “Netskope User Enrollment” App (*App name may change)

AD_4nXdZwOwaC5ibqh4-I441nRwHHeMQLfZj1bl5z8zq9xfA7GNygMO-lWfi9li_a8a0KKEGfvo-RsQUZlqdWUiyVjGCpR5EdPsFEugBdomg9uh3VLgV8wad4sc1ZuI-4b0whLEcmTyNnQ?key=X5IfFsa2VsQOv6Q8uswRhefy

 

Step 3. In the Provisioning tab change the URL and the Token as shown below:

 

AD_4nXdJmvy3S60-5CNYQM8k9ZieugcKPa07DuOSDEUE9AmsKEnl6xg4MscsXKLE7U3va5imVKgTd1i8naWmzqMZJaU27sTtX4LpGRSryWA49ZPVS1RLjVZEJxYi9DEO2MVX7THXPUT8RA?key=X5IfFsa2VsQOv6Q8uswRhefy

 

Replace with:

 

AD_4nXc23MWchsYoycocWB6j7y9OhGx4IiUX6WI-0YdoUvxJXHfGNv5LaHW3F_ODTyQMk9DJUFDseqW5m7T9MyrkQy3hqq7hMfYxXU6iS-27MFtq599ngeXr0gdAQo7o3NgG6NPJ8tvR-A?key=X5IfFsa2VsQOv6Q8uswRhefy


 

 

Current value

New Value

URL

https://addon-<tenantname>[.region].goskope.com/SCIM/v2

https://<tenantname>[.region].goskope.com/api/v2/scim

Token

Old token got from the “Settings >>> Tools >>> Directory Tools >>> SCIM Integration”

New token got at Step #1

 

Step 4. Test the connection to ensure it is successful, if so then save the configuration:

 

AD_4nXdvpUonpKRqsNyA44IOyv6A5PZXlPqRKI06sUCjISZvuEJhPeXhx7Ojd62BBO6vE8H9flGvkdsCq8pXTn3Nj0orjZOKrDYXLDi3y8ByYJRlmY0GH7NpIXF1tGTIm9X-KGy9qbna?key=X5IfFsa2VsQOv6Q8uswRhefy

 

 

⚠️ As mentioned on the Netskope Product EOL Announcements, If your Netskope tenant is hardened using IP Allowlist (Settings >>> Administration >>> IP Allowlist - see screenshot below), then you must ensure you add the respective source IP addresses of your integrated REST API V2 services to the Custom IP list.

AD_4nXfuL0OjRxQl9qIr3r_IEuo1xZ6k8Ff-XODaU4Cvk4nTBvW6tnKGs6trqEBQl3Az1O6lNUlmGUxNp4bvLebUXicyEOV4650v4G7foK9tOxglvQWN-5JZ_dmkQZcw2Y8c6KaJxw9x1k5b9ZJhnkWOWOSAuVmX?key=DcLc5TVPBuRycojopm5_WQ

Important: Okta provides its IP ranges in the article below.

List of IP Addresses that Should Be Allowlisted for Inbound Traffic

 

 

Step 5. After some days of monitoring, please proceed to remove the old token under Settings >>> Tools >>> Directory Tools >>> SCIM Integration page as shown below

 

AD_4nXccSROUNIf_FaaTYdKLRkCQk7OvcymKRu5bKk38UO9duyeNxahYB65nUPYDRUteExTZHl_rBuXNgEgz-rxEeAmTOb-6ao-cwk7wq1TouuRt7Tni7VO0CxktAX9aXTtl0tVXHiCqXA?key=X5IfFsa2VsQOv6Q8uswRhefy

 

Terms and Conditions

  • All documented information undergoes testing and verification to ensure accuracy.
  • In the future, it is possible that the application's functionality may be altered by the vendor. If any such changes are brought to our attention, we will promptly update the documentation to reflect them.

 

Notes

  • This article is authored by Netskope Global Technical Success (GTS).
  • For any further inquiries related to this article, please contact Netskope GTS by submitting a support case with 'Case Type – How To Questions'.

 

This topic has been closed for replies.