...
Info |
---|
The service user which until now synced the changes from Zitadel (events) with Unique FinanceGPT requires now more privileges (IAM Org Owner Viewer & IAM User Manager). This service user now needs to also be able to create, modify and delete users from any organisation on Zitadel via API (IAM User Manager). But also fetch information about Organisations to be able to assign roles and IDPs to new created users (IAM Owner Viewer). |
[Zitadel] Adjusting permission of service user
Login to Zitadel with a user that has IAM Owner capabilities (instance manager).
Switch to Cluster IAM organisation on top left.
...
Switch to the instance view on top right.
...
Open the instance users managing view.
...
There should be a service user (robot icon) which has currently at least
IAM Owner Viewer capability called
user-sync
orscope-management-user
.
...
Adjust the Permission of this user including
IAM Owner Viewer
andIAM User Manager
...
[MS Portal] Creating the SCIM Enterprise Application
...
Add Configuration
Fill URL and Token
...
Info |
---|
The <API-URL> is the base API URL on which the Unique FinanceGPT backend services are available. Normally its something similar like: https://gateway.xxx.unique.app. But especially for customer managed tenant this can vary. |
Test and create
Adjust the attribute mapping
...