Skip to content

Okta

This article includes information on adding Okta as an integration to sync objects to Oblique. To use Okta as an identity provider to authenticate to Oblique, see Single sign-on.

When you connect an Okta tenant to Oblique, Oblique will automatically sync the tenant’s users and their profile attributes, its groups, and its apps and their assignments.

As you add or remove users, groups, or app assignments in Okta, these changes are automatically synced to Oblique. If connected in read-write mode, Oblique can also change Okta group membership and app assignments for users.

You can add multiple Okta tenants to Oblique. These function as separate integrations and are distinguished by their tenant base URI and Okta organization ID.

Oblique syncs the following from your Okta tenant. In read-write mode, Oblique can also change Okta group membership and app assignments for users.

Okta objectOblique objectCapability
UsersUsersRead-only
Profile attributesUser attributesRead-only
UsersAccountsRead-only
GroupsResourcesRead-only
AppsResourcesRead-only
Group membershipEntitlementsRead-write
App assignments for usersEntitlementsRead-write
App assignments for groupsEntitlementsRead-only

Oblique also syncs active group rules and group push mappings for apps.

Oblique syncs each user in your Okta directory as an Oblique user.

Oblique uses the following profile attributes from Okta to identify users:

  • id
  • firstName
  • lastName
  • email
  • secondEmail

Oblique syncs the following profile attributes from Okta as user attributes:

  • employeeNumber
  • userType
  • manager
  • managerId
  • title
  • department
  • division
  • organization
  • costCenter
  • primaryPhone
  • city

Oblique also syncs custom profile attributes with the data type string. Custom profile attributes are attributes defined by your organization in Okta that aren’t part of the default Okta user profile.

Oblique also syncs each user in your Okta directory as an Oblique account.

Okta accounts are matched to Oblique users by id.

Oblique syncs the following from Okta as resources:

  • Each group in your Okta tenant
  • Each app in your Okta tenant

A group deleted in Okta is soft deleted in Oblique.

Oblique reads both individual and group app assignments as entitlements.

The Okta integration doesn’t read information about roles in Okta.

Oblique connects to Okta through an API Service Integration, authenticating with OAuth 2.0 client credentials issued by Okta. You can install the integration from the Okta Integration Network in either read-only or read-write mode.

You must be an admin to add an integration.

To install this integration, you must be an Okta administrator with a administrator role that allows you to install API Service Integrations, such as a Super Administrator.

The Oblique app is installed with these scopes:

Okta API scopeWhat Oblique uses it for
okta.orgs.readIdentify which Okta org the connection belongs to
okta.users.readImport users and their attributes, status, and last sign-in
okta.groups.readImport groups and their memberships
okta.groups.manageCreate groups and change their membership
okta.apps.readImport applications and their assignments
okta.apps.manageChange application assignments

A read-only connection only requests the read scopes.

Adding the Okta integration requires adding Oblique as an API Service integration in Okta, and then sharing the generated client ID and secret with Oblique.

You can read more about adding an API service integration in Okta’s documentation.

In Okta’s Admin Console, navigate to Applications > API Services Integrations:

  1. Select Add Integration.
  2. Search for and select Oblique. Select Next.
  3. Review the requested Okta API scopes. Select Install & Authorize.
  4. Copy the client secret that is provided. It will not be shown again. Store this securely. You will need to provide this to Oblique. Select Done.
  5. Under Client Credentials, also copy the Okta Domain and Client ID.
  1. Navigate to the Integrations page.
  2. Select Add integration.
  3. Select Okta.
  4. Enter your Okta Domain as the Okta domain base URI, such as https://example.okta.com. Enter your Client ID and your Client secret from the installation.
  5. Under Connect, select Read-write to let Oblique manage Okta groups and app assignments, or Read-only to only use your Okta org as a source, and not as a destination. By default, this is read-write.
  6. Select Add integration.

You can change the Okta integration’s scopes or its credentials.

To change your integration from read-only to read-write, or vice versa, remove the integration and then add it again.

You must be an admin to replace an integration's credentials.

If the integration’s credentials expire, are revoked, or need rotating, replace them without removing the integration. From the integration’s detail page:

  1. Navigate to the Settings tab.
  2. Under Connection, select Replace OAuth client credentials….
  3. Paste the new values and select Replace.

Oblique uses the new credentials from the next sync. You will still need to revoke the old credentials in Okta.

Oblique can manage Okta groups and act as the source of truth for group membership.

Oblique supports both creating entitlements for Okta groups and Okta apps. You can add or remove a user from an Okta group, or assign a user directly to an Okta app.

However, you can’t create an entitlement that assigns an Okta app to an Okta group. If you assign an Okta app to an Oblique group, Oblique flattens that group when it writes to Okta: each member receives an individual app assignment rather than a group-level one.

Most organizations with an existing Okta setup prefer Oblique to write to Okta groups rather than directly to Okta apps, especially if they already have Okta push groups configured for those apps. In this setup, Oblique manages group membership and Okta handles everything downstream of it.

Okta groups appear in Oblique as resources that users can request access to. When access is granted — to an individual user, or to an Oblique group or team — Oblique writes the membership into the Okta group. Okta then handles what that group membership grants, including app assignment (provisioning the user in the app) and group push (syncing group membership into the app).

You must be an admin to remove an integration.

To remove an Okta integration, from the integration’s detail page:

  1. Navigate to the Settings tab.
  2. At the bottom of the page, under Delete integration, select Delete integration….
  3. In the confirmation dialog, type the text to confirm, then select Delete integration.

This will immediately stop all syncing and remove all resources from the integration. Access that Oblique granted in Okta stays as it is.

Adding the integration reports that the domain is already in use

Section titled “Adding the integration reports that the domain is already in use”

Each Okta tenant can only be connected to an Oblique tenant once. Check the Integrations page for an existing integration with the same domain base URI.

Verify if you connected Oblique to Okta as a read-only integration. From the integration detail, under Settings, look under Connection, then Permissions.

Change the Okta integration scopes to start writing access changes.

Oblique can’t manage Okta groups of some source types. Native Okta groups (source type BUILT_IN) and application groups (source type APP_GROUP) are managed in Okta.

If a problem isn’t covered here, contact support.