For the complete documentation index, see llms.txt. This page is also available as Markdown.

Integrations

Common questions about connecting Harmony to Okta, Jira, Microsoft, Dayforce, and other platforms

A user was added to an Okta group and SCIM-provisioned in Harmony, but receives an error when attempting to SSO. How can this be resolved?

This issue can occur when there is a delay or inconsistency between SCIM provisioning and SSO authentication. If a newly provisioned user encounters an error during SSO login, wait a few minutes for the provisioning sync to complete, then ask the user to attempt login again.

If the error persists after retrying, contact Harmony support to investigate the provisioning state of the account.


What is the difference between the Okta SSO/SAML/SCIM setup and integrating an additional Okta tenant?

There are two distinct Okta integrations in Harmony:

  1. SSO/SAML/SCIM setup: A single connection used for authentication and user provisioning. It is configured once and handles single sign-on and SCIM-based provisioning for your organization.

  2. Additional Okta tenant integration: Additional Okta tenants can be connected via the integrations catalog. These connections are used for inventory purposes: Harmony fetches apps, users, and groups from the tenant to track account ownership across your organization.

These two integrations serve different purposes and are configured independently. You can also configure Okta groups against the SSO app to enable role-based access control within Harmony.


Can I connect a second Okta tenant to Harmony, and will it create duplicate users?

Yes, you can connect multiple Okta tenants through the Integrations page.

If your tenants are linked via an Org2Org setup, be aware that users existing in both tenants may appear as duplicates in Harmony. When connecting a second tenant, review your user data to identify and deduplicate any overlapping accounts before or after the connection is established.


Does the Jira integration support standard Jira projects, or is it limited to Jira Service Management?

The Jira integration supports both Jira Service Management (JSM) and standard Jira projects.

For standard Jira users, the integration currently provides:

  • Automatic ticket transitions: Harmony can automatically transition Jira tickets to a specified status based on activity in Harmony.

Coming soon for standard Jira:

  • Create a Jira issue from a Harmony ticket: The ability to create a single Jira issue directly from a Harmony ticket.

Note: The JSM-specific portion of the integration is used to import JSM tickets into Harmony, which is not applicable if you are using standard Jira.


Is read-only permission in Jira sufficient for the Harmony integration?

No. Because Harmony needs to write responses back to Jira (e.g., comments or ticket updates), the integration account requires more than read access. The account should be added as a Service Desk Team Member to allow Harmony to post replies on Jira tickets.


What operations does the GitHub integration support?

The GitHub integration is designed to enable user and group management directly through GitHub. Planned operations include:

  • Adding or removing users from groups

  • Adding or removing users from repositories

Note: This integration is currently in early stages, and additional capabilities may be added over time.


Can multiple Microsoft tenants (Intune, Teams, Entra ID) be connected to Harmony?

Support for connecting multiple instances of Microsoft integrations is being rolled out incrementally.

  • Intune: Multiple tenant connections are supported.

  • Microsoft Teams: Multiple tenant connections are supported. If you need to connect an additional tenant, the option will appear in the integration settings once it becomes available for your account.

  • Entra ID: Entra ID can be connected via the IDP (Identity Provider) section. This connection enables the Harmony Agent to add users to Microsoft 365 Groups. Note that if your primary IDP is a third-party provider (e.g., Okta), connecting Entra ID solely for M365 Group management may require additional configuration, such as a custom app registration with the appropriate Microsoft Graph API permissions.

If you do not yet see the option to add an additional tenant for a given integration, the feature may still be pending availability for your account. Contact Harmony support for the current status or to request early access.


Can I rename an existing Intune integration instance?

Renaming an existing Intune integration instance is not available as a self-service action. Please contact Harmony support with the desired name, and the team will update it for you.


The recommended Access Token Lifetime is 600 seconds.

While Harmony does manage token refresh requests, a shorter lifetime (such as the default 60 seconds) will:

  • Slow down data collection

  • Increase the number of requests made to your Jamf instance

Setting the token lifetime to 600 seconds strikes the right balance between security and performance.


How do I open the Harmony agent view in Microsoft Teams without using the Copilot menu?

You can access the Harmony agent directly through the Microsoft Teams Apps tab:

  1. Open Microsoft Teams.

  2. Navigate to the Apps tab in the left sidebar.

  3. Find and select the Harmony app.

  4. The agent view will be available as an Agent tab within the app.


When a Slack channel is connected to Harmony, will the bot notify users in that channel when a ticket is opened?

Yes. When a Slack channel is linked to Harmony, the bot will automatically reply to each message in that channel to confirm that a ticket has been opened. Users will see a response in the thread.

Additionally:

  • The reply is minimal: a brief confirmation message with no additional content.

  • Images shared in the channel are also synced to the system and will be available in the web interface.


Why are newly added users from Dayforce not appearing in my Harmony tenant?

There are two common reasons newly added users may not appear as expected after a Dayforce sync:

Users not visible in the user list

Harmony's user list applies an Active status filter by default. Users who have been recently added but have not yet reached their start date may be present in the system but hidden by this filter.

To see all synced users:

  1. Navigate to the user list in your Harmony tenant.

  2. Remove or clear the default Active status filter.

  3. The newly added users should now appear.

Incorrect start date for pre-start employees

For users with a future start date, Harmony reads employment status data from Dayforce. New employees are assigned a PRESTART status in Dayforce prior to their start date. In this state, the correct start date is reflected in the EffectiveEnd field of that status record, not the EffectiveStart field.

If a user's start date appears incorrect in Harmony, this is likely the cause. Contact Harmony support to ensure your tenant is configured to handle PRESTART status records correctly.


What configuration is required in Dayforce to enable the Harmony integration?

After connecting Harmony to your Dayforce instance, data is pulled automatically on a 24-hour cycle. No manual action is needed to start the sync. However, the Harmony integration user in Dayforce must be assigned a role with the following permissions configured correctly.

Features Tab

Expand HCM Anywhere → Web Services, then enable:

  • Explorer

  • Read Data

  • Patch/Post HR Bulk Job

Authorization Tab

Enable Can Read for:

  • Employee Contact Information (and Business variant)

  • Employee Number

  • Employee Own Contact Information (and Business variant)

  • Employee Personal Information (and XrefCode variant)

  • Employee Properties

  • Employee Status Information

  • Employee Work Assignment (Primary and Secondary Records)

  • User Information

Web Services Field-Level Access Tab

Expand RESTful Service → Employee and enable all subfields for: CommonName, Contacts, DisplayName, EmployeeManager, EmployeeNumber, EmployeeOrgUnits, EmployeeStatus, EmployeeWorkAssignment, EmploymentStatus, EmploymentType, FirstName, HireDate, HomeOrganization, LastName, OriginalHireDate, SeniorityDate, StartDate, XRefCode.

Also expand SOAP Services → GetEmployeeXRefCodesResponse and enable XRefCode.

For bulk export, expand RESTful Services → Human Resources and enable all subfields for EmployeeExportParameters, EmployeeExportBackgroundJobStatus, and EmployeeExportBulkResponse.

Location Access Tab

Select the highest-level Location in your organization hierarchy.

What data is synced

Harmony syncs the fields shown in the Overview section of each user's profile. Note that Location is sourced from your IdP (Okta or Entra), IdP Status and Last Login from Okta, and Start Date from EmploymentStatuses.EffectiveStart in Dayforce.

Onboarding and Offboarding Agents use synced Dayforce data (start date, end date, role, manager, location) to automatically trigger workflows a configurable number of days before an employee's start or end date.


How does Harmony compute last activity for Entra ID users, and does it support automatically disabling inactive accounts?

Last activity computation

Harmony determines a user's last activity by taking the most recent sign-in timestamp across both interactive and non-interactive sign-in types in Entra ID. The interactive/non-interactive distinction is used solely as an input to this calculation; it is not surfaced as a standalone signal.

Automatic account disabling

The intended workflow is:

  1. Filter to enabled accounts only (using the Entra ID account lifecycle state).

  2. Identify users whose most recent sign-in (across both sign-in types) is older than 40 days.

  3. Automatically disable those accounts, excluding service accounts.

This automated enforcement is planned but not yet available. Current user activity data, including IdP status, is available for review in the People table.


Last updated

Was this helpful?