Announcing the Saviynt Knowledge Exchange unifying the Saviynt forums, documentation, training,
and more in a single search tool across platforms. Read the announcement here.

Okta connector security roles: only assigned roles are synchronized

JustSalva
Regular Contributor
Regular Contributor

Hi all,

We configured the Okta reconciliation connector as per documentation (https://saviynt.freshdesk.com/support/solutions/articles/43000535913-okta-connector-guide)

but we noticed that unassigned security roles are not synchronized in Saviynt.

Is there a way to reconciliate also unassigned security roles?

Kind regards,

Matteo

1 REPLY 1

ejeong
Valued Contributor
Valued Contributor

I had a similar issue since this is limitation of okta api..

It goes through every single users to check their security roles..

Okta doesnt provide api to get list of roles and get membership for each role with API. However, its supported with custom roles

So two option

1) create custom roles in okta with same permission and dont use default roles

2) assign AD group for each security roles and user request AD group for role assignment.