This guide covers how to migrate SSO & SCIM configuration from the Udemy Business (Legacy) Okta app to the latest Udemy Business Okta app and is only relevant to you if your Okta SSO connection is configured using the Udemy Business (Legacy) app. The Udemy Business (Legacy) app will be deprecated at the end of the year.
- If you don't have an existing SSO connection with the Udemy Business (Legacy) Okta app but instead have an existing SSO connection with the Udemy Business Okta app, and are looking to complete your SSO reconfiguration, please review this guide.
Table of contents
Before you begin
You will need:
- Administrator access to both your Udemy Business account and your Okta organization.
- A short maintenance window. SSO will be unavailable for a few minutes during the migration, so we recommend scheduling outside peak usage hours and notifying your learners.
- If you use SCIM provisioning on the legacy Okta app, allow extra time, additional steps are required to preserve user and group sync (see Path B below).
Important: Avoid lockout
Do not enable Login via SSO Provider Only until you have successfully tested the new connection end-to-end. If SSO is not properly configured, all users in your organization will be locked out of Udemy Business. You may disable this option while carrying out the reconfigure flow, please proceed to the instructions below.
Choose your path
- Path A: Migrate without SCIM: Your organization signs users in via SSO but does not use SCIM provisioning on the legacy Okta app.
- Path B: Migrate with SCIM: Your organization uses both SSO and SCIM provisioning on the legacy Okta app.
If you're not sure, check your Okta admin panel: open the Udemy Business (Legacy) app and look at the Provisioning tab and look under Integration. If provisioning is enabled, follow Path B.
Path A: Migrate without SCIM
Step 1: Set up the new Udemy Business app in Okta
In Okta, add the new app and prepare its metadata. Follow Steps 1-3 in this Help Center article.
Step 2: Reconfigure SSO in Udemy Business
Navigate to Step 4 in this Help Center guide.
- Follow Steps 4.1 and 4.2.
- Skip Steps 4.3 and 4.4. Select Reconfigure SSO instead of Start Setup. Okta and SAML are already selected based on your prior connection.
- Important: If you have SSO-only login selected while editing the settings, deselect it before hitting save. This prevents you from being fully locked out of your account in case there's an issue with your new SSO settings. You can enable it again when you have successfully tested the new SSO connection.
- Follow Steps 4.5, 4.6 and 4.7
Your organization is now using the new SSO experience through the new Udemy Business Okta app.
Path B: Migrate with SCIM
This path applies if your organization uses both SSO and SCIM provisioning on the legacy Okta app.
Step 1: Disable provisioning
In Okta, open the Udemy Business (Legacy) app, go to the Provisioning tab, and disable provisioning. Check under Integration in order to disable provisioning.
Users will remain in Udemy Business but will no longer be SCIM-managed. SCIM will be re-enabled on the new app in Step 3.
Step 2: Set up the new Udemy Business app in Okta
In Okta, add the new app and prepare its metadata. Follow Steps 1-3 in this Help Center article.
Step 3: Reconfigure SSO in Udemy Business
Navigate to Step 4 in this Help Center guide.
- Follow Steps 4.1 and 4.2.
- Skip Steps 4.3 and 4.4. Select Reconfigure SSO instead of Start Setup. Okta and SAML are already selected based on your prior connection.
- Important: If you have SSO-only login selected while editing the settings, please deselect it before hitting save. This prevents you from being fully locked out of your account in case there is an issue with your new SSO settings. You may enable it again when you have successfully tested the new SSO connection.
- Follow Steps 4.5, 4.6 and 4.7
Your organization is now using the new SSO experience through the new Udemy Business Okta app.
Step 4: Configure SCIM on the new app and import users and groups
Navigate to the section in this Help Center resource that outlines how to migrate an existing integration to bearer token to enable use of the new Udemy Business app in Okta.
- Follow Step 1
- For Step 2
- Skip Steps 2.1 and 2.2. You've already configured the new app in a previous step.
- Follows Steps 2.3 - 2.6
- Set up your SCIM attributes so that they have parity with your setup in the legacy app
- Skip Step 3, you won't keep the old app once complete.
- Follow Steps 4 and 5
Step 5: Remove the legacy app
Once SSO sign-in and SCIM provisioning are both working on the new app and you're satisfied with the setup, deactivate or delete the Udemy Business (Legacy) app in Okta.