Mapping attributes from Okta profile vs. user sync

%3CLINGO-SUB%20id%3D%22lingo-sub-334775%22%20slang%3D%22en-US%22%3EMapping%20attributes%20from%20Okta%20profile%20vs.%20user%20sync%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-334775%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20currently%20federating%20with%20Okta%20and%20initially%20choose%20the%20profile%20sync%20option%20in%20Okta%20which%20is%20the%20most%20limited%20when%20it%20comes%20to%20the%203%20types%20of%20syncs%20offered.%20We've%20written%20some%20backend%20code%20that%20pulls%20attributes%20such%20as%20manager%2C%20location%2C%20department%2C%20etc%20from%20our%20HR%20DB%20and%20it%20syncs%20perfectly%20with%20AD%2FOkta.%20The%20issues%20is%20those%20attributes%20will%20not%20be%20exposed%20in%20Okta%20unless%20we%20switch%20to%20user%20sync.%20We%20tried%20this%20in%20our%20test%20environment%20and%20notices%20a%20couple%20things%20on%20the%20Office%20365%20side.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1)%20Things%20like%20aliases%20can%20no%20longer%20be%20created%20in%20office%20365%20admin%26nbsp%3B%3C%2FP%3E%3CP%3E2)%20A%20couple%20onmicrosoft%20users%20somehow%20vanished%26nbsp%3B%3C%2FP%3E%3CP%3E3)%20Users%20in%20azure%20active%20directory%20switched%20from%20azure%20managed%20to%20AD%20managed%20(our%20Okta%20is%20syncing%20from%20AD)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20know%20it%20sounds%20more%20like%20an%20Okta%20question%20but%20it%20seems%20to%20be%20more%20troublesome%20with%20Office%20365.%20For%20example%2C%20Okta%20allows%20you%20to%20create%20custom%20attributes.%20Other%20apps%20will%20read%20and%20map%20them%20however%2C%20office%20365%20will%20not.%20Just%20curious%20if%20anyone%20has%20had%20any%20experience%20with%20this.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-334775%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdmin%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Highlighted
Occasional Contributor

Hello, 

 

We are currently federating with Okta and initially choose the profile sync option in Okta which is the most limited when it comes to the 3 types of syncs offered. We've written some backend code that pulls attributes such as manager, location, department, etc from our HR DB and it syncs perfectly with AD/Okta. The issues is those attributes will not be exposed in Okta unless we switch to user sync. We tried this in our test environment and notices a couple things on the Office 365 side. 

 

1) Things like aliases can no longer be created in office 365 admin 

2) A couple onmicrosoft users somehow vanished 

3) Users in azure active directory switched from azure managed to AD managed (our Okta is syncing from AD)

 

I know it sounds more like an Okta question but it seems to be more troublesome with Office 365. For example, Okta allows you to create custom attributes. Other apps will read and map them however, office 365 will not. Just curious if anyone has had any experience with this. 

0 Replies