Skip to content

Commit d45c2ca

Browse files
kennyj42ranbel
andauthored
Update okta.mdx (#17696)
* Update okta.mdx add callout about matching up OIDC and SCIM groups * Update okta.mdx --------- Co-authored-by: ranbel <[email protected]>
1 parent 00e8b89 commit d45c2ca

File tree

1 file changed

+4
-0
lines changed
  • src/content/docs/cloudflare-one/identity/idp-integration

1 file changed

+4
-0
lines changed

src/content/docs/cloudflare-one/identity/idp-integration/okta.mdx

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -133,6 +133,10 @@ The Okta integration allows you to synchronize IdP groups and automatically depr
133133

134134
14. In the **Assignments** tab, add the users you want to synchronize with Cloudflare Access. You can add users in batches by assigning a group.
135135

136+
:::note
137+
Groups in this SCIM app integration should match the groups in your base [OIDC app integration](/cloudflare-one/identity/idp-integration/okta/#set-up-okta-as-an-oidc-provider). Because SCIM group membership updates will overwrite any groups in a user's identity, assigning the same groups to each app ensures consistent policy evaluation.
138+
:::
139+
136140
15. In the **Push Groups** tab, add the Okta groups you want to synchronize with Cloudflare Access. These groups will display in the Access policy builder.
137141

138142
Provisioning will begin immediately. To verify the integration, select **View Logs** in the Okta SCIM application.

0 commit comments

Comments
 (0)