Are the people you want to assign not supposed to be in any Ou?
They’re supposed to be in a wide variety of OUs. I’m assigning an entire org to their G Suite, so potentially up to 10ish OUs.
I had previously just been using individual assignments in Okta but group assignments is way cleaner.
Plus if I do group assignments then I can’t do OU changes with BC workflows unless I unassign them in okta in an earlier step?
I guess people probably use more granular group assignments but my situation is just a little more macro than that.
That's a very interesting use case - because usually someone is part of one OU consistently, but different groups.
yeah… It’s not that I don’t have groups for the same OU categories - they are just more flexible. Folks are allowed to stay in the PDX group even if they move away. But you can only be in one OU.
Plus with the posting permissions of those groups… our leadership is in all of them. What would Okta do with that? lol I can just see the admin log confusion now….
Hmm....I guess you could just have it where Okta doesn't update GSuite and have BC handle that part?
Okta creates the account in an initial group, but doesn't update it after that
But then the directory won’t update profile changes….
this is true...so in an ideal world you want Okta to just update the user profile but NOT update the OU setting for users?
OU isn’t a profile field I can use, though, I don’t think.
correct - I don't think it is either.
Already have an account? Login
Enter your username or e-mail address. We'll send you an e-mail with instructions to reset your password.
Sorry, we're still checking this file's contents to make sure it's safe to download. Please try again in a few minutes.
Sorry, our virus scanner detected that this file isn't safe to download.
We use 3 different kinds of cookies. You can choose which cookies you want to accept. We need basic cookies to make this site work, therefore these are the minimum you can select. Learn more about our cookies.