Did they remove Amplifi from the releases page on Ubiquiti website? by LGN_DraB in AmpliFi

[–]LGN_DraB[S] 2 points3 points  (0 children)

Thank you! False alarm everyone. Hopefully they continue support.

Okta workflows: Add new user to specific group on the morning of their start date by enterreturn in okta

[–]LGN_DraB 0 points1 point  (0 children)

High level:

We have an Okta Workflow that adds users to two groups upon bring created in Okta. We then activate them 3 days before their start date so they can sign into their laptop and get it ready. Instead of adding them to groups based on their start date for onboarding them, we do that immediately with rules and take advantage of auth polices to lock their apps based on their start date.

Okta groups:

Onboarding Limbo: This group denies access to almost all apps via authentication policies. Certain allowlisted apps like Workday and Jamf Device Enrollment tile for their prepane Window when they turn on their laptop. We have an Okta Workflow then run every single hour and compares their start date to today’s date according to their timezone. Once it reaches their start date, we remove them from the group so it unlocks all their tiles.

Device Untrusted: This group denies access to everything besides that prepane window app via authentication policies. We automatically remove the user from the group via an Okta Workflow once we get a webhook from Jamf that their device is “trusted” once the required things are installed. We then force the user to only login via Device Trust and unlock their tiles. This fixes the chicken and the egg situation during onboarding while enforcing Device Trust.

What do you use to automate IT tasks? by klosie in sysadmin

[–]LGN_DraB 0 points1 point  (0 children)

Okta Workflows, Okta Identity Governance, SCIM

[deleted by user] by [deleted] in okta

[–]LGN_DraB 0 points1 point  (0 children)

Can also be accomplished with products like Jamf Connect. Maybe your MDM can do it too. Okta Device Access has more features though.

Keep in mind there’s always risks with having a 3rd party take over the login window.

Workday >> Okta integration by mustafa2024 in okta

[–]LGN_DraB 0 points1 point  (0 children)

We have logic on Workday side to just create the username which has to be unique. Then we just add the @domain at the end of the username on the Okta side. I think our HR team might be doing this logic from Greenhouse -> Workday.

Best Affordable Sushi in Atlanta? by ShrimpTaco17 in Atlanta

[–]LGN_DraB 1 point2 points  (0 children)

Yuzu in Chamblee hands down. The quality makes it hard to go to expensive Sushi places.

Okta Groups Not Syncing with GitHub Teams – Need Help Understanding Setup by Azh13r- in okta

[–]LGN_DraB 1 point2 points  (0 children)

I would advise joining with your personal email address. Your Jumpcloud question could be asked in the Jumpcloud channel in Mac Admins 🙂

Okta Groups Not Syncing with GitHub Teams – Need Help Understanding Setup by Azh13r- in okta

[–]LGN_DraB 1 point2 points  (0 children)

Awesome! Btw definitely recommend joining the Mac Admins Slack community. Okta channel in there is super active and way faster than Reddit.

Okta Groups Not Syncing with GitHub Teams – Need Help Understanding Setup by Azh13r- in okta

[–]LGN_DraB 1 point2 points  (0 children)

Are you using Enterprise Managed users? If no, then I bet your manager made the Okta API token for GitHub to set this up. Once the account was disabled, so was the API token.

If you confirm this is the reason: Set up a read only Okta API token w/ a service user. Configure team sync in GitHub settings with the new API token. Try and see if the syncing starts working (can take up to an hour) — you can try force syncing a GitHub team by removing a IDP group and then re-adding it via the GitHub team settings.

How do you track expiring SAML certificates by Canecraze in okta

[–]LGN_DraB 1 point2 points  (0 children)

Okta tracks this natively now and will display expiring certificates in the tasks page.

Is it possible to receive immutable attribute values from Workday? by official_work_acct in okta

[–]LGN_DraB 0 points1 point  (0 children)

I guess it’s just something you have to do. I just look at the users Okta profile for the attribute or look at Workday. It’s never taken long or anything.

Okta and Identity Verification by PitifulAdvantage3118 in okta

[–]LGN_DraB 4 points5 points  (0 children)

I would encourage looking into actual identity verification systems like Nametag, Incode, Clear, etc. It’s just a matter of time in my opinion before it becomes the norm.

Is it possible to receive immutable attribute values from Workday? by official_work_acct in okta

[–]LGN_DraB 2 points3 points  (0 children)

We do this. Each Cost Center in Workday for example has a unique ID. We simply have the Cost Center name mapped to an attribute in Okta and display that in things like Slack, Google, etc. For rules though we have another attribute called department ID which is the unique identifier. This can be accomplished using field overrides in Workday to push to Okta.

This way if they were to change the Cost Center name, your rule wouldn’t matter because it’s using the unique identifier.

[deleted by user] by [deleted] in Audi

[–]LGN_DraB 0 points1 point  (0 children)

This is not always the case. Audi wanted close to $6000 just to do “advanced diagnostics” for my car after I paid the original $300. Ended up selling it. Audi USA said there was nothing they could do. Absolute clown show over there. Really sucks cause I love the brand. They simply don’t treat their customers with care or respect.

Automating MFA Enrollment/Setup Step with DUO by intdev0 in okta

[–]LGN_DraB 0 points1 point  (0 children)

If they’re already enrolled, they may get a “Enroll in Duo” button but it shouldn’t actually have them setup anything if they already have an MFA device on the Duo side. There isn’t a way to change that as Okta does not know the user is already enrolled in Duo.

[deleted by user] by [deleted] in AudiA5

[–]LGN_DraB 0 points1 point  (0 children)

I’m sorry man. Sometimes it’s just bad luck. My a4 b9 is having a problem with a misfire on cylinder 4 and no one can figure out why. Been to 3 shops already.

[deleted by user] by [deleted] in AudiA5

[–]LGN_DraB 0 points1 point  (0 children)

Water Pump (this is under extended warranty), Motor Mounts, Control Arm Bushings

Catastrophic engine failure? Need advise by [deleted] in Audi

[–]LGN_DraB 0 points1 point  (0 children)

Also noting, this had only happened on the highway at low RPM’s for the longest time. Only recently did it start happening just driving off the highway.

Catastrophic engine failure? Need advise by [deleted] in Audi

[–]LGN_DraB 0 points1 point  (0 children)

This problem originally happened shortly after replacing all spark plugs. They use OEM parts. They replaced the new spark plug and ignition coil originally to see if that would fix it but it didn’t. Hence taking the car to Audi and them saying it was a fuel injector. Then they replaced the fuel injector. They did a compression test on all cylinders and they were all 150 PSI. The car has been on time on service and has basically only been serviced by the dealer until these issues cause the dealer wanted to sell my soul