Configuring Just-in-Time (JIT) provisioning for Slack

This guide details the steps to configure JIT provisioning between ManageEngine ADSelfService Plus and Slack.

SAML-based SSO must be configured to enable JIT provisioning. To learn how to configure SSO for Slack, click here.

Slack (Service Provider) configuration steps

  1. Log in to Slack as a workspace owner or workspace admin.
  2. On the left pane, select Configure apps in the Account section.
  3. Slack
  4. On the App Directory page, click Build in the top-right corner.
  5. Slack
  6. In the Slack API page, click Create New App.
  7. Slack
  8. In the Create an app pop-up, select the From scratch option.
  9. Slack
  10. Enter the App Name as ADSelfService Plus and select a workspace to develop your app in from the drop-down.
  11. Click Create App.
  12. Slack
  13. The app will be created, and you’ll be redirected to the Basic Information page of the app.
  14. Under the Install your app to your workspace section, click the permission scope link.
  15. Slack
  16. Under the Scopes section, select Administer the workspace option from the Select Permission Scopes drop-down.
  17. Slack
  18. In the left menu, under the Settings section, click Install App.
  19. Click Install to Workspace
  20. Slack
  21. You’ll be redirected to a new page where you need to grant permission to the app to administer your workspace. Click Allow.
  22. Slack
  23. Copy the OAuth Access Token displayed.
  24. Slack

ADSelfService Plus (Identity Provider) configuration steps

  1. Login to ADSelfService Plus with administrator credentials.
  2. Navigate to Configuration > Self-Service > Password Sync/Single Sign On > Add Application, and select Slack from the applications displayed.
  3. Note: You can also find Slack from the search bar located in the left pane or the alphabet wise navigation option in the right pane.

  4. Enter the Application Name and Description.
  5. Enter the Domain Name of your Slack account. For example, if you use johndoe@thinktodaytech.com to log in to Slack, then thinktodaytech.com is the domain name.
  6. In the Assign Policies field, choose the policies for which you want the application to be assigned.
  7. Note: ADSelfService Plus enables you to create OU and group-based policies for your AD domains. To create a policy, go to Configuration > Self-Service > Policy Configuration > Add New Policy.

  8. Click SCIM and select Enable Just-in-Time Provisioning.
  9. In the OAuth Access Token field, paste the OAuth Access Token value copied in Step 14.
  10. In the License Consumption Limit field, enter the maximum number of licenses you want to be consumed in this application. This will ensure that only the specified license count is used when creating user accounts in the application. The number of licenses consumed will be displayed next to this field. If license consumption exceeds the specified limit, then the user account creation process is stopped.
  11. Note:
    • The license usage details will be visible when editing the application configuration.
    • If a user already has an account in the application, their access attempt through ADSelfService Plus will also be counted towards the license count.
  12. Click Add Application.
  13. Slack

You have now successfully configured JIT provisioning for Slack. User accounts that do not exist in Slack will be created automatically during SSO login.

Go to Top

Thanks!

Your request has been submitted to the ADSelfService Plus technical support team. Our technical support people will assist you at the earliest.

 

Need technical assistance?

  • Enter your email ID
  • Talk to experts
  •  
     
  •  
  • By clicking 'Talk to experts' you agree to processing of personal data according to the Privacy Policy.

Don't see what you're looking for?

  •  

    Visit our community

    Post your questions in the forum.

     
  •  

    Request additional resources

    Send us your requirements.

     
  •  

    Need implementation assistance?

    Try onboarding

     

Copyright © 2024, ZOHO Corp. All Rights Reserved.