Skip to main content

Using Okta for User Provisioning

  • December 12, 2023
  • 9 replies
  • 322 views

dandrews
Helper I
Forum|alt.badge.img+1

Hi all, 

We are moving to Okta for our user provisioning and have been running into a few issues with our IT team. It sounds like Okta is not integrated for this purpose (idea pending) but I’m curious. Who else is using Okta for this and how are you doing it so that you can get all the correct fields mapped into the system?

Thanks, 

D’Arcy 

9 replies

KMallette
Hero II
Forum|alt.badge.img+9
  • Hero II
  • December 12, 2023

Hi, @dandrews We use Okta and found the conversion very simple. Field mapping is pretty easy, We do have a specific additional field that we use for the branch code.

 

 


dandrews
Helper I
Forum|alt.badge.img+1
  • Author
  • Helper I
  • December 12, 2023

@KMallette are you doing this through the API connection?


alekwo
Guide III
Forum|alt.badge.img+1
  • Guide III
  • December 12, 2023

@dandrews we are using Okta as well, it works with no issues with the standard SAML configuration. We only pass username, email, and first and last name from Okta when creating a user. 

 


dandrews
Helper I
Forum|alt.badge.img+1
  • Author
  • Helper I
  • December 12, 2023

@alekwo @KMallette Do yall have any issues deleting or disabling users? ie, how to disable folks? It sounds like this set up with user provisioning does not allow for that (or at least what my IT team is telling me) 


KMallette
Hero II
Forum|alt.badge.img+9
  • Hero II
  • December 12, 2023

@dandrews  We just use it for login, and there by account creation. We’re using the SAML 2.0 configuration, not API. I would think that offboarding would work with the API as a separate ‘function’ … you’d need Okta to assign the username when the account gets created so that you can match them up correctly.


alekwo
Guide III
Forum|alt.badge.img+1
  • Guide III
  • December 12, 2023

@dandrews it’s a one-way street - we only create and update users when they log in, we don’t deactivate users based on their status in Okta.


dandrews
Helper I
Forum|alt.badge.img+1
  • Author
  • Helper I
  • December 12, 2023

Ok that’s what I thought which is why I was getting push back for this method. How do you then disable your users? @ale

 


alekwo
Guide III
Forum|alt.badge.img+1
  • Guide III
  • December 12, 2023

It depends, for employees we have a separate API-based integration with our HR system.

For customers, we only disable them manually in case we receive a bounced email from them. 


dandrews
Helper I
Forum|alt.badge.img+1
  • Author
  • Helper I
  • December 12, 2023

Thank you @alekwo