Okta
This article includes information on adding Okta as an integration to sync objects to Oblique. To use Okta as an identity provider to authenticate to Oblique, see Single sign-on.
When you connect an Okta tenant to Oblique, Oblique will automatically sync the tenant’s users and their profile attributes, its groups, and its apps and their assignments.
As you add or remove users, groups, or app assignments in Okta, these changes are automatically synced to Oblique. If connected in read-write mode, Oblique can also change Okta group membership and app assignments for users.
You can add multiple Okta tenants to Oblique. These function as separate integrations and are distinguished by their tenant base URI and Okta organization ID.
Supported options
Section titled “Supported options”Oblique syncs the following from your Okta tenant. In read-write mode, Oblique can also change Okta group membership and app assignments for users.
| Okta object | Oblique object | Capability |
|---|---|---|
| Users | Users | Read-only |
| Profile attributes | User attributes | Read-only |
| Users | Accounts | Read-only |
| Groups | Resources | Read-only |
| Apps | Resources | Read-only |
| Group membership | Entitlements | Read-write |
| App assignments for users | Entitlements | Read-write |
| App assignments for groups | Entitlements | Read-only |
Oblique also syncs active group rules and group push mappings for apps.
Oblique syncs each user in your Okta directory as an Oblique user.
Oblique uses the following profile attributes from Okta to identify users:
idfirstNamelastNameemailsecondEmail
Attributes
Section titled “Attributes”Oblique syncs the following profile attributes from Okta as user attributes:
employeeNumberuserTypemanagermanagerIdtitledepartmentdivisionorganizationcostCenterprimaryPhonecity
Oblique also syncs custom profile attributes with the data type string. Custom profile attributes are attributes defined by your organization in Okta that aren’t part of the default Okta user profile.
Accounts
Section titled “Accounts”Oblique also syncs each user in your Okta directory as an Oblique account.
Okta accounts are matched to Oblique users by id.
Resources
Section titled “Resources”Oblique syncs the following from Okta as resources:
- Each group in your Okta tenant
- Each app in your Okta tenant
A group deleted in Okta is soft deleted in Oblique.
Oblique reads both individual and group app assignments as entitlements.
The Okta integration doesn’t read information about roles in Okta.
Add Okta integration
Section titled “Add Okta integration”Oblique connects to Okta through an API Service Integration, authenticating with OAuth 2.0 client credentials issued by Okta. You can install the integration from the Okta Integration Network in either read-only or read-write mode.
Prerequisites
Section titled “Prerequisites”To install this integration, you must be an Okta administrator with a administrator role that allows you to install API Service Integrations, such as a Super Administrator.
Requested Okta API scopes
Section titled “Requested Okta API scopes”The Oblique app is installed with these scopes:
| Okta API scope | What Oblique uses it for |
|---|---|
okta.orgs.read | Identify which Okta org the connection belongs to |
okta.users.read | Import users and their attributes, status, and last sign-in |
okta.groups.read | Import groups and their memberships |
okta.groups.manage | Create groups and change their membership |
okta.apps.read | Import applications and their assignments |
okta.apps.manage | Change application assignments |
A read-only connection only requests the read scopes.
Configuration steps
Section titled “Configuration steps”Adding the Okta integration requires adding Oblique as an API Service integration in Okta, and then sharing the generated client ID and secret with Oblique.
You can read more about adding an API service integration in Okta’s documentation.
Install the Oblique app in Okta
Section titled “Install the Oblique app in Okta”In Okta’s Admin Console, navigate to Applications > API Services Integrations:
- Select Add Integration.
- Search for and select
Oblique. Select Next. - Review the requested Okta API scopes. Select Install & Authorize.
- Copy the client secret that is provided. It will not be shown again. Store this securely. You will need to provide this to Oblique. Select Done.
- Under Client Credentials, also copy the Okta Domain and Client ID.
Connect the integration in Oblique
Section titled “Connect the integration in Oblique”- Navigate to the Integrations page.
- Select Add integration.
- Select Okta.
- Enter your Okta Domain as the Okta domain base URI, such as
https://example.okta.com. Enter your Client ID and your Client secret from the installation. - Under Connect, select Read-write to let Oblique manage Okta groups and app assignments, or Read-only to only use your Okta org as a source, and not as a destination. By default, this is read-write.
- Select Add integration.
Change Okta integration
Section titled “Change Okta integration”You can change the Okta integration’s scopes or its credentials.
Change Okta integration scopes
Section titled “Change Okta integration scopes”To change your integration from read-only to read-write, or vice versa, remove the integration and then add it again.
Change Okta integration credentials
Section titled “Change Okta integration credentials”If the integration’s credentials expire, are revoked, or need rotating, replace them without removing the integration. From the integration’s detail page:
- Navigate to the Settings tab.
- Under Connection, select Replace OAuth client credentials….
- Paste the new values and select Replace.
Oblique uses the new credentials from the next sync. You will still need to revoke the old credentials in Okta.
Manage entitlements
Section titled “Manage entitlements”Manage Okta group membership
Section titled “Manage Okta group membership”Oblique can manage Okta groups and act as the source of truth for group membership.
Manage Okta app assignments
Section titled “Manage Okta app assignments”Oblique supports both creating entitlements for Okta groups and Okta apps. You can add or remove a user from an Okta group, or assign a user directly to an Okta app.
However, you can’t create an entitlement that assigns an Okta app to an Okta group. If you assign an Okta app to an Oblique group, Oblique flattens that group when it writes to Okta: each member receives an individual app assignment rather than a group-level one.
Most organizations with an existing Okta setup prefer Oblique to write to Okta groups rather than directly to Okta apps, especially if they already have Okta push groups configured for those apps. In this setup, Oblique manages group membership and Okta handles everything downstream of it.
Okta groups appear in Oblique as resources that users can request access to. When access is granted — to an individual user, or to an Oblique group or team — Oblique writes the membership into the Okta group. Okta then handles what that group membership grants, including app assignment (provisioning the user in the app) and group push (syncing group membership into the app).
Remove Okta integration
Section titled “Remove Okta integration”To remove an Okta integration, from the integration’s detail page:
- Navigate to the Settings tab.
- At the bottom of the page, under Delete integration, select Delete integration….
- In the confirmation dialog, type the text to confirm, then select Delete integration.
This will immediately stop all syncing and remove all resources from the integration. Access that Oblique granted in Okta stays as it is.
Troubleshooting
Section titled “Troubleshooting”Adding the integration reports that the domain is already in use
Section titled “Adding the integration reports that the domain is already in use”Each Okta tenant can only be connected to an Oblique tenant once. Check the Integrations page for an existing integration with the same domain base URI.
Oblique isn’t writing access to Okta
Section titled “Oblique isn’t writing access to Okta”Verify if you connected Oblique to Okta as a read-only integration. From the integration detail, under Settings, look under Connection, then Permissions.
Change the Okta integration scopes to start writing access changes.
Oblique won’t create an Okta group
Section titled “Oblique won’t create an Okta group”Oblique can’t manage Okta groups of some source
types.
Native Okta groups (source type BUILT_IN) and application groups (source type
APP_GROUP) are managed in Okta.
Get help
Section titled “Get help”If a problem isn’t covered here, contact support.