Fathom 2.0's SCIM and SAML Integrations with Okta Streamline User Management and Authentication
In today's digital landscape, managing user access across multiple systems requires robust integration frameworks. Fathom 2.0, a platform for team collaboration and video management, has implemented System for Cross-domain Identity Management (SCIM) and Security Assertion Markup Language (SAML) integrations with Okta to streamline user provisioning and authentication. These integrations enable seamless teamwork while maintaining security and control. In this article, we'll explore how to set up and configure these critical integration points, troubleshoot common issues, and understand their impact on team management and access control.
Fathom 2.0 implements SCIM (System for Cross-domain Identity Management) to enable seamless user provisioning between the platform and Okta. This integration supports core functions including user creation, attribute updates, and deactivation, as well as group management capabilities through user account push.
The implementation process requires careful configuration within Okta and Fathom's interface:
Team-specific Access: Begin by logging into Fathom under the desired Team.
Okta Application Configuration: Open the Fathom application within Okta and ensure the Application username format is set to Email.
Provisioning Setup: Navigate to the Provisioning tab and initiate integration under the Integration section.
OAuth 2.0 Connection: Complete the connection process by authorizing OAuth 2.0 access.
Data Synchronization: Configure the data fields to sync, recommending at least the Create Users option.
User Assignment: Finalize setup by assigning users and groups to the Okta application.
For advanced control, Fathom enables specific configuration options:
Group Management: Access the Push Groups settings to manage team names. Disabling the Rename Groups option allows for customized team naming conventions.
Role Assignment: Ensure all Team management occurs through Okta, with roles assigned based on group membership.
Common issues and best practices include:
SCIM-managed users will receive Fathom Team roles based on their assigned groups
Users not included in pushed groups will not have Fathom Team membership
All Team management is handled through Okta's Synchronized Groups functionality
The SCIM integration between Fathom 2.0 and Okta requires precise configuration to ensure smooth user provisioning and authentication. The process begins by logging into Fathom under the desired Team, then navigating to the Okta application where the Application username format must be set to Email.
Under the Provisioning tab, users initiate integration through the Integration section, where an OAuth 2.0 connection must be established. For successful data synchronization, Fathom recommends enabling the Create Users option under To App settings. Additionally, users must assign both users and groups to the Okta application for comprehensive management.
Optional configuration allows for enhanced control over team management. Disabling the Rename Groups option under Push Groups settings maintains custom team naming conventions. All Team management functions are handled through Okta's Synchronized Groups functionality, ensuring all team-related activities are managed within this integrated framework.
Optional settings include the Rename Groups option within Fathom's SCIM configuration, allowing administrators to control how team names are managed. Disabling this feature maintains any custom team naming conventions that may have been implemented. All Team management functions remain integrated through Okta's Synchronized Groups functionality, ensuring that group membership directly impacts user assignment to Fathom teams.
When configuring SCIM settings, it's important to note that only users associated with pushed groups will receive Fathom Team membership. Those not included in these groups will not be granted team access, maintaining a clear distinction between group membership and team participation. The platform prioritizes Okta's synchronized groups for all Team management activities, ensuring consistent and controlled user access across both systems.
Common issues and their resolutions include:
User Assignment Based on Group Membership: Users will be assigned Fathom Team roles only if they are associated with a Push Group through SCIM. Those not included in these groups will not receive team membership. To troubleshoot, verify that the correct group membership is configured in Okta and that the Push Groups setting is properly set up in Fathom's SCIM configuration.
Management of Team Roles through Okta: All Team management functions are handled through Okta's Synchronized Groups functionality. This means that role assignments should be made and managed within Okta, with Fathom respecting these changes. If role changes are not reflecting in Fathom, check the Okta configuration to ensure the correct group membership and role assignments are in place.
Additional considerations for troubleshooting include:
Ensuring the Application username format in Okta is set to Email
Verifying that all required data fields are correctly configured for synchronization (e.g., first name, last name, email)
Checking that the OAuth 2.0 connection has been properly established between Fathom and Okta
Confirming that all users and groups have been correctly assigned to the Okta application
Reviewing the Push Groups settings in Fathom's SCIM configuration to ensure proper team management functionality
Fathom 2.0 supports SAML 2.0 integration with Okta, enabling both SP-initiated and IdP-initiated Single Sign-On (SSO) mechanisms. This integration requires activation by Fathom's Customer Success Manager (CSM) or support team, who will provide the necessary Metadata URL from the Okta configuration.
To configure SAML, several key elements must be properly set up:
Email Domain Association: The Okta instance must have its email domains correctly associated with the Fathom integration. This configuration ensures that user email addresses are properly mapped between the two systems.
Application Username Format: It's essential to set this to "Email" format within Okta to ensure seamless user authentication during SSO processes.
Metadata URL: This URL is provided by Fathom and must be configured within Okta's SAML 2.0 settings for the Fathom application.
Login URL: Users can access the system through Fathom's specified SSO URL: https://fathom.video/users/sign\_in/sso.
It's important to note that Fathom does not provide an alternative backup sign-in URL for users who need to sign in using their regular credentials. If SAML integration needs to be disabled, users should contact Fathom Support directly.
This integration process facilitates secure and efficient access management, aligning with best practices for enterprise-level authentication systems.