Question

Can you use a wildcard with Okta 'Remove from Group' action?

  • 5 January 2021
  • 7 replies
  • 18 views

Userlevel 3
Badge +3

With the Okta "remove from group" option is there a way to use a wildcard to target specific groups that might have different names? ie just removing anyone from groups that have "Team" in them?


7 replies

Badge +1

I've never found anything like this nor did our Implementation Specialist. I'm in the middle of creating many 'dynamic' groups (department/division) and this would save a lot of time during setup if I could have one remove workflow rather than one for every department/division.


Open Thread in Slack
Userlevel 3
Badge +3

yeah - I'm mainly interested in this for people who 'transfer' departments. Instead of trying to figure out what department they would be transferring from - I just want to remove any 'department' groups (i.e. Team Marketing, Team Legal) but leave anything that's more general (i.e. Staff group,)


Open Thread in Slack
Badge +1

Hey @marquesstewart and @greg.hupke. There isn’t currently a wildcard option here but I recommend voting on this feature request for it: https://www.saasops.community/ideas/use-wildcard-based-expressions-within-actions-6833 I’m sure both of you are aware of this functionality, but you could setup Okta Group rules that automatically adds a user to a set of groups based on the membership of a “parent” group: Then you can use BetterCloud to automatically remove and re-add users to those parent Groups with Workflows based on Department Change events or something like that. Obviously not ideal… and requires some setup on your end, but figured I’d throw it out there!


Open Thread in Slack
Userlevel 3
Badge +3

Yeah @emmett.dresler that's currently what I have setup. The downside to that process (connecting to 'remove from all Okta groups') is the fact that it would temporarily 'disable' the user in any connected apps to that group. Its more annoying then an actual problem


Open Thread in Slack
Badge +1

Ah yeah, I can see why. I wish we had a better workaround.. The only other option I can see is to create multiple Workflows for each scenario you have with multiple “Remove from Group” Actions that target each Group you want to remove the user from. Not much better 😞 Definitely upvote that feature request though!


Open Thread in Slack
Userlevel 3
Badge +3

Upvoted, thanks


Open Thread in Slack
Badge +1

Also upvoted. Thanks @emmett.dresler


Open Thread in Slack

Reply