Skip to content

Commit b2b1dd3

Browse files
authored
Update okta.mdx
1 parent 3712883 commit b2b1dd3

File tree

1 file changed

+3
-1
lines changed
  • src/content/docs/cloudflare-one/identity/idp-integration

1 file changed

+3
-1
lines changed

src/content/docs/cloudflare-one/identity/idp-integration/okta.mdx

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -133,7 +133,9 @@ The Okta integration allows you to synchronize IdP groups and automatically depr
133133

134134
14. In the **Assignments** tab, add the users you want to synchronize with Cloudflare Access. You can add users in batches by assigning a group.
135135

136-
**Note:** Ensure that all groups used in policy evaluation and device profiles are included in the SCIM assignment. SCIM group membership updates will overwrite any groups on a user for policy evaluation.
136+
:::note
137+
Groups in this SCIM app integration should match the groups in your base [OIDC app integration](/cloudflare-one/identity/idp-integration/okta/#set-up-okta-as-an-oidc-provider). Because SCIM group membership updates will overwrite any groups in a user's identity, assigning the same groups to each app ensures consistent policy evaluation.
138+
:::
137139

138140
15. In the **Push Groups** tab, add the Okta groups you want to synchronize with Cloudflare Access. These groups will display in the Access policy builder.
139141

0 commit comments

Comments
 (0)