Skip to main content
MichelB
BeyondTrust Employee
BeyondTrust Employee
September 10, 2026

Pathfinder SCIM - Okta - setup guide

  • September 10, 2026
  • 0 replies
  • 6 views

BeyondTrust Pathfinder SCIM API can be used for provisioning into all BT products or modules. It replaces the standalone SCIM API found in Password Safe, Endpoint Privilege Management or EPM Windows & Mac, and Privileged Remote Access or PRA.

 

This guide is a complement to Documentation - SCIM Provisioning

 

The first step is to create a SCIM token as the SCIM service account, and note the Org ID in the upper right corner.  The User must be Administrator in individual BT modules.

 

Create new Application.

 

Under Provisioning, click Configure API integration.

 

Provide Base Url and token.

 

Note:  Url is https://api.beyondtrust.io/api/{organization-id}/platform/auth/scim/v2 and you need to replace {organization-id} with Org ID from Pathfinder.

 

Under Provisioning → To App, enable Create User, Update User Attributes and Deactivate Users.

 

Testing

 

Create a new test Group and add a new test User.

 

Back to the Application, assign the test Group.

 

Test User should be assigned automatically via Group.

 

Push the test Group.

 

After Push Group, the test Group should be Active.

 

The test User should now exist in Pathfinder.

 

In module (e.g. EPM Win & Mac) the SCIM Group can be assigned a Role that will be inherited by members.

 

SCIM test Group can also be added to PRA or Remote Support Group Policy.