Configuring provisioning for ZScaler Private Access

Provision users from IBM® Verify to a ZScaler Private Access application.

Before you begin

You need a ZScaler Private Access account with administrator access.

About this task

Provisioning provides the following features.
Create new users
New users that are created through Verify are also created in the ZScaler Private Access application.
Delete users
Deactivating the user or disabling the user's access to the application through Verify deletes the user in the ZScaler Private Access application.
Modify user profile
Updates made to the user's profile through Verify are pushed to the ZScaler Private Access application.
User suspend and restore
Suspending a user through Verify deactivates the user and restoring the user through Verify activates the user in the ZScaler Private Access application.
User account synchronization and remediation
The ZScaler Private Access application supports user account synchronization, remediation, and group synchronization features.
  • User account synchronization fetches all the target application user accounts in Verify and matches the fetched accounts with users in Verify. The adoption policy that is defined on the application specifies the matching attributes for adoption of the synchronized user accounts.
  • Remediation policy can be configured to remediate user accounts with attribute values that differ between Verify and the target application.
  • Verify Supports the following three remediation policies:
    1. Do not remediate non-compliant accounts automatically.
    2. Update Verify account attribute values with the target application values.
    3. Update target application account attribute values with Verify values.
  • Group synchronization fetches all the target application groups in Verify.

Procedure

  1. Log in as an admin user to your ZScaler Private Access account by using the following URL:
    https://admin.zscalerbetprivate.zscaler.com
  2. Navigate to Administration > IdP Configuration.
  3. Select the identity provider that you want to modify and click the edit icon.
  4. In the Edit Idp Configuration window, select Enabled for SCIM Sync.
  5. Copy the SCIM Service Provider Endpoint.
  6. Click Generate New Token to create a bearer token.
    The SCIM Service Provider Endpoint and token are needed to configure user provisioning in Verify.