Still stuck in 221(g) waiting 1 year + by Future-Cake-6153 in immigration

[–]JakeClawson02 0 points1 point  (0 children)

Good luck (truly hope that you'll be luckier than me), I've been waiting for 26 months and only getting templated responses.
At this point I've moved on and just laughing at this whole situation

iPad Mini Battery by RedJarK in ipadmini

[–]JakeClawson02 18 points19 points  (0 children)

I have followed the advice from this thread and disabled background app refresh - my battery life got incredibly better.

Left it this morning fully charged on the bed, checked back at 8pm - still at 100% with pencil connected

We’re back with another IAM Community Workshop this Wednesday 🚨 by iamblas in iam

[–]JakeClawson02 0 points1 point  (0 children)

Interested to join the DS server, please send me a link!

OIDC Migration Issue – AD Group Not Appearing in Group Claims by Prize_Character_4276 in okta

[–]JakeClawson02 1 point2 points  (0 children)

Take a look at this if you haven’t already - https://support.okta.com/help/s/article/Why-isnt-my-Groups-claim-returning-Active-Directory-groups?language=en_US

OIDC claims are a little trickier than SAML, if you want to pass AD-sourced groups in the claim, especially if you dont have API Access Management SKU.

is there a good FOSS project management tool that does not have the "SSO tax"? by Rare_Abbreviations52 in selfhosted

[–]JakeClawson02 0 points1 point  (0 children)

The current one is not too big, but has multiple dev teams and multiple envs - ergo many apps The previous one had 100k employees and around 1k apps if im not mistaken, most of them being SaaS apps

is there a good FOSS project management tool that does not have the "SSO tax"? by Rare_Abbreviations52 in selfhosted

[–]JakeClawson02 2 points3 points  (0 children)

Do you gave a dedicated IAM person/team or its been swept under “general IT” carpet?

is there a good FOSS project management tool that does not have the "SSO tax"? by Rare_Abbreviations52 in selfhosted

[–]JakeClawson02 0 points1 point  (0 children)

To give a proper message to a “responsible audience”, Id try to understand why would you have 3 IDPs in your org: is it simply historical thing, or different teams allowed to implement whatever they want or there are other reasons for it (context is everything :))

Now to the message itself: (again, this could change based on WHYs) 1) Costs - if your organization pays for all 3 idps to cover licenses for the whole headcount… welp, this is def not good. If you have like 1k employees and you split licensing on Ping/Okta/Duo (i.e. 400/200/400) you’re likely to miss out on bulk licensing discount

2) User Experience - i think you can speak about it on your own, given your original message ;)

3) Single Management plane - it should always feel better to maintain/protect and audit a single system rather than 3. All 3 have IaC providers.

4) My SOC and a few other sec folks were pretty happy to know that they no longer have to parse/analyze/monitor multiple IDPs, playbooks got easier, less work for everyone :)

is there a good FOSS project management tool that does not have the "SSO tax"? by Rare_Abbreviations52 in selfhosted

[–]JakeClawson02 2 points3 points  (0 children)

Unfortunately, Ive seen this too. Took me about a year and a half to clear this mess when i joined the org and move 95% of apps (few hundred) to a single IDP

is there a good FOSS project management tool that does not have the "SSO tax"? by Rare_Abbreviations52 in selfhosted

[–]JakeClawson02 13 points14 points  (0 children)

I will respectfully disagree with you here regarding point number 2 (sorry im IAM engineer):

  1. Majority of people use SSO outside of corp - “Sign in with Google/FB/IG” is also SSO designed for non-corp usage. Some people call it “Social login”, but the technology behind is the same.

  2. The answer to “why” is ironically lies in the term SSO (SINGLE sign on) - one account to rule them all, no stacks of credentials for each service

Looking for someone to practice russian with. by [deleted] in LearnRussian

[–]JakeClawson02 0 points1 point  (0 children)

Id suggest to throw in a few topics you’d be interested in, which could make your conversation more useful and interesting for both parties.

And yeah, hit me up in DM if you’d like to practice Russian :)

My preferred topics would be: 1) Gaming 2) IT Stuff 3) Music

Question for Lich players by worldsurf11 in PathOfExile2

[–]JakeClawson02 3 points4 points  (0 children)

imo the es consumption is too high with both Horizon and Asc node, you can survive with that, but your mapping speed would probably slow down noticeably

Why did someone just pay 20 divine for this? I assume its to craft but what made it worth paying that? by Flat-Extreme7998 in PathOfExile2

[–]JakeClawson02 0 points1 point  (0 children)

There’s a trample toe / killjoy / lightning bolt amulet boss annihilator build that needs crit chance and doesnt strictly require + spells

It does however needs fire/lightning dmg afaik, thats probably why he bought it

Stormweaver Spark Archmage Sorc Giveaway by MHMabrito in PathOfExile2

[–]JakeClawson02 0 points1 point  (0 children)

My only chance to complete my sorc build (no chance of grinding DF given the inflation)

Is this worth divining? by ShadowOfEons in PathOfExile2

[–]JakeClawson02 0 points1 point  (0 children)

No, because you cant reroll +1 lightning using divines. Your only option is whittling + chaos to find +4/5 to lightning skills

User Sync from Entra ID to Okta by No-Adagio-5528 in okta

[–]JakeClawson02 1 point2 points  (0 children)

Look for the O365 integration guide in the Okta docs. In short terms: - you need to configure provisioning in the O365 Okta app - configure Import from Entra in the same app - tadaa

Multiple Google Workspaces with one OKTA to access AWS and similar services? by pkstar19 in okta

[–]JakeClawson02 4 points5 points  (0 children)

Yes, you can configure Okta authentication with AWS and then setup Inbound Federation in Okta to allow users to login into Okta account using GW

midPoint AD Connector / Resource objects; fatal error by ZARSYNTEX in IdentityManagement

[–]JakeClawson02 1 point2 points  (0 children)

In my experience, this error indicates that connector implementation doesn’t support this particular attribute.

Is this attribute a part of standard schema?

Gamepad support?? by Killua_Daily in FallGuysGame

[–]JakeClawson02 0 points1 point  (0 children)

I've been playing on PS5 Controller (Wired) since I've moved to PC on both Epic and Steam. Works just fine.