How to integrate ADManager Plus with Okta Workforce Identity Cloud

How to integrate ADManager Plus with Okta Workforce Identity Cloud

Overview

Okta is a cloud-based identity management platform that provides authentication, authorization, and user management solutions for organizations. Integrating ADManager Plus with Okta's identity management system allows for synchronisation and enhanced management of user identities, permissions, and access across the network. This streamlines user provisioning, providing a more centralised and efficient system for managing user identities within the organization.


    Key highlights of integrating ADManager Plus with Okta
    1. Centralized Identity Management: Streamlines user identity management by syncing user data and permissions, ensuring consistency across systems.
    2. Workflow-controlled automation: Implement multi-level business workflows to oversee and control automations.


    Actions supported

    Upon integration, administrators can configure automations to carry out desired tasks. These automations can be monitored and controlled by implementing multi-level business workflows, which ensure that they are reviewed and approved before execution. The following actions can be automated:

    • Create user accounts

    • Add users to groups

    • Modify user attributes

    • Remove users from groups

    • Modify user accounts by Template

    • Create mailbox

    • Reset passwords

    • Disable or delete mailbox

    • Unlock user accounts

    • Move Home Folder

    • Enable user accounts

    • Delete Home Folder

    • Disable user accounts

    • Revoke Microsoft 365 licenses

    • Delete user accounts

    • Manage users' photos

    • Run custom scripts

    • Disable Lync accounts

    • Move users across groups

    • Configure auto reply settings

     

    How to integrate ADManager Plus with Okta to streamline identity life cycle management

    1. Log in to ADManager Plus.

    1. Navigate to the Automation tab. Click Application Integrations under Configuration.

    1. Click Okta.

    1. In the Authorization section, copy the Callback URL which will be used in the future step to obtain credentials from Okta.

    1. Enter the Client ID and Client Secret values as obtained from the Steps to obtain Client ID and Client Secret in Okta given below.

    1. Click Configure.

    1. In the endpoint configuration section, replace the {domain} in the Endpoint URL with the subdomain of your Okta instance and click Test & Save.
       

    1. The response schema will be displayed, you can verify and click Proceed.

    1. Click Data Source - LDAP Attribute Mapping to map AD LDAP attributes with the respective attributes in Okta.

    1. Enter the Configuration Name and Description and select the Automation Category from the drop-down menu.

    1. In the Select Endpoint field, select the primary key column that has unique values for each user (e.g. employeeIdenifier)

    Note: When multiple endpoints are configured, this attribute must hold the same value in all the endpoints. 

    1. In the Attribute Mapping field, select the attribute from the LDAP Attribute Name drop-down menu and map it with the respective column in Okta.

    1. Click Save.

    While configuring an automation in ADManager Plus, select Okta as the Data Source and automate user management in a flash. Click here to learn more about automation configuration.

     

    Steps to obtain Client ID and Client Secret in Okta 
    1. Log into the Okta portal and click Admin button on the right corner of the window
       

    1. Click Applications from the left panel.

    1. Click Create App Integration button, select the OIDC - OpenID Connect option as the sign-in method and click Next.

    1. Select the application type as Web Application, and click Next.

    1. Provide the App integration name, enable Refresh Token and then paste the Callback URL copied from the previous step in the Sign-in redirect URIs field.

    1. Select any one of the Controlled access option and click Save.
       

    1. The upcoming page will display the the ClientID and Client Secret values.

    Go to Okta API Scopes tab search for okta.users.read scope and click Grant.



     


                      New to ADSelfService Plus?