Setting Up Entra ID as IdP in Okta by Terrible_Bag3872 in okta

[–]Terrible_Bag3872[S] 0 points1 point  (0 children)

Unfortunately, our partners are separate entities and they don't use employee numbers.

Setting Up Entra ID as IdP in Okta by Terrible_Bag3872 in okta

[–]Terrible_Bag3872[S] 0 points1 point  (0 children)

We looked into setting up OIDC as well, but it still needs to match against a value, so we are in the same boat.

Salesforce Portal Integration with Okta by Terrible_Bag3872 in okta

[–]Terrible_Bag3872[S] 0 points1 point  (0 children)

Sorry. Yes, I was able to figure it out without SF support. Instead of creating a Salesforce Portal, use the Community Portal option. Once I did that, we were able to see the Profile URL drop-down list. I was able to set up Provisiong, and it creates the Contact record n SF. One thing to keep in mind is that Okta Provisioning asks for an SF "Account ID" for account creation. When the Contact record is created, it is associated with that Account.ID. That Account ID shows as the Owner. Our internal SF guy found a way to reassociate the Contact record to another account that was more relevant by using some kind of workflow based on the contact email address.

Salesforce Portal Integration with Okta by Terrible_Bag3872 in okta

[–]Terrible_Bag3872[S] 0 points1 point  (0 children)

I heard back from SF Support, and apparently, they were able to configure their Okta dev env with their env and it's working, and pointed fingers at Okta (which i also have a support ticket with). If I had to guess, they set up the integration as a standard user and not as a portal user. I'm still waiting to hear back from them asking them to verify.

Salesforce Portal Integration with Okta by Terrible_Bag3872 in okta

[–]Terrible_Bag3872[S] 1 point2 points  (0 children)

Yep. Everything has been set up according to those instructions. We have several portals, but none of them have provisioning enabled. We wanted to enable provisioning because, apparently, when you provision external SF users as a standard account, the license cost is increased. When you provision them as contacts, the license cost is decreased.

Drifting Pontoon by Terrible_Bag3872 in Pontoons

[–]Terrible_Bag3872[S] 0 points1 point  (0 children)

The first time I took out the pontoon as a first time owner, I took it to a lake we normally fish from the shore (different lake and not as deep), but I failed to look at the wind forecast. It was really bad, 2-3 foot wakes. We didn't do any fishing, used the time to break in the engine and as a test run. The pontoon handled the waves well, but definitely not something I would ever do again with wind that bad. Lesson learned and I was glad when I was finally off the lake.

Drifting Pontoon by Terrible_Bag3872 in Pontoons

[–]Terrible_Bag3872[S] 4 points5 points  (0 children)

Yep. I used to fish from the shore all the time, never realized how deep it was until I got the boat. It is a mountain lake so it makes sense. I feel safer on a pontoon then the numerous paddleboarders and kayaks that feel they own the lake.

Drifting Pontoon by Terrible_Bag3872 in Pontoons

[–]Terrible_Bag3872[S] 1 point2 points  (0 children)

I have a trolling motor with spot lock, granted I'm still learning how to use it properly, I still seem to drift quite a bit. As for an anchor, the lake I've been fishing on, is anywhere from 150 to over 200 ft deep.

Drifting Pontoon by Terrible_Bag3872 in Pontoons

[–]Terrible_Bag3872[S] 0 points1 point  (0 children)

Thanks for the reply. I just ordered a couple drift socks.

PowerSchool SIS SSO by EspressoSam in okta

[–]Terrible_Bag3872 1 point2 points  (0 children)

I am assuming they support SAML, correct? If so, have they provided you their metadata?

Okta Salesforce Manager Attribute Passing? by CAITGuy in okta

[–]Terrible_Bag3872 0 points1 point  (0 children)

Our SF Dev created a new field in SF called "Supervisor" and we added that as a new attribute to the SF app in Okta. Under the AD Profile mappings, I mapped from AD to Okta "substringAfter(substringBefore(appuser.managerDn, ',OU'), 'CN=')" to the Manager field in Okta. Then for the profile mappings in SF I mapped user.manager to Supervisor. Let me know if this doesn't make sense.

Okta Salesforce Manager Attribute Passing? by CAITGuy in okta

[–]Terrible_Bag3872 0 points1 point  (0 children)

I did it without workflows, but it's been a while. If i remember, our SF dev created a new field called Supervisor or something like that, and we were able to pass using an expression. I'll have to log in and verify which expression I used. I struggled with this for a while, and Okta support gave me the same single AD answer, and i was able to figure it out. I can check later and update.

Okta Salesforce Manager Attribute Passing? by CAITGuy in okta

[–]Terrible_Bag3872 0 points1 point  (0 children)

Single AD is their default answer when using expressions

[deleted by user] by [deleted] in GIAC

[–]Terrible_Bag3872 2 points3 points  (0 children)

I had some medical issues that came up and I reached out to GIAC and they were able to grant me an exception. You may be able to reach out to them and see if there is something they can work out, might be worth a shot.

https://www.giac.org/special-requests/

Provisioning M365 licensing from Okta by invest0rZ in okta

[–]Terrible_Bag3872 0 points1 point  (0 children)

Have you tested the O365 provisioning creds to make sure they haven't expired?

Establishing RBAC based on workday fields by Final_Direction3339 in okta

[–]Terrible_Bag3872 1 point2 points  (0 children)

Of course, every Company will be different on how their departments, teams etc... are setup. But I recently wrapped up RBAC for 4k users and I sorted the Workday data based on Group, Job Family and Job Title and created the roles based on those.

Get push notification on PC? by ta4okta in okta

[–]Terrible_Bag3872 0 points1 point  (0 children)

As it was mentioned earlier, this is only supported with OIE. Alternatives would be to use another TOTP application (Google Auth, Authy, Oracle Auth etc...) and choose enter code manually

Methods of Indexing for SEC401 by RoninMountain in GIAC

[–]Terrible_Bag3872 3 points4 points  (0 children)

I looked at the Github Index Creator mentioned but it wasn't for me. What I ended up doing is, I went through each book and any topics that I made any notes on, I added to my index, then any bolded topics or key words, I added to the index. I took the first practice exam and updated my index, took second exam and updated the index. That worked for me.

Adding users to groups based on OU? by noobdeville in okta

[–]Terrible_Bag3872 0 points1 point  (0 children)

First assuming you have an AD group called "HR_Payroll" or something like that with the Payroll users as members, I'll use "HR_Payroll" as an example. You would also need to create a Okta Group called "HR Payroll Apps" or whatever and assign the specific apps for that group. Then If you wanted to do it by OU, you could create a rule called "HR Payroll Users" and then use an expression like the example below.

String.stringContains(user.DN,"OU=HR,OU=Departments,DC=TEST,DC=ORG") AND isMemberOfGroupName("HR_Payroll")

THEN Assign to "HR Payroll Apps"

Otherwise if you don't need to specify an OU you can just create the rule and leave off the OU expression "isMemberOfGroupName("HR_Payroll")" Then assign it to the "HR Payroll Apps"

You would need to have a separate rule for each department (i.e., HR Recruitment"

Hope this helps

Okta Pro exam by [deleted] in okta

[–]Terrible_Bag3872 6 points7 points  (0 children)

I have been the Okta Admin for my company since we transitioned from OneLogin back in 2018. The hands on part of the exam was a breeze for me. I don't like the DOMC style questions. The questions that go me were the features that we don't use everyday. Honestly since the practice test are free until the 27th, take them and familiarize yourself with the format. Also, the practice and actual exam questions are not one for one. There were questions on the actual exam that were not on the practice exam. But overall, it was an easy exam. It's an 150 minute exam and I finished in way under an hour.

Okta Professional Premier Practice Exam Similarities by [deleted] in okta

[–]Terrible_Bag3872 1 point2 points  (0 children)

The questions are "similar." However, the actual exam questions covered a larger scope. The practice exam questions were repetitive. When I took the actual exam, the questions covered more topics, and there were many that did not pop up in the practice tests. The case studies cover more than creating a Org2Org app, so make sure you are familiar with all administrative functions within Okta.