Okta Requirements for Microsoft Office 365 Global Administrator Accounts
Last Updated:
Overview
Applications supporting the System for Cross-domain Identity Management (SCIM) protocol require authentication, such as a service account, a delegated OAuth token, or an API token, to provision user identities through Create, Read, Update, and Delete (CRUD) operations, group provisioning, and other operations that are supported under the vendor implementation. Microsoft Office 365 requires a service account with the Global Administrator role and enabled Multi-Factor Authentication (MFA) to authorize the Web Services Federation (WS-FED) process and grant access to the Microsoft Graph API Client.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Microsoft Office 365 (O365)
- Provisioning
Solution
What are the requirements for the Microsoft Office 365 service account?
Configure the Microsoft Office 365 account used to integrate Okta with Microsoft Office 365 for provisioning and Web Services Federation (WS-FED) with the following requirements.
- Assign the Global Administrator role to the account.
- Enabled Multi-Factor Authentication (MFA) for this account on the Microsoft Office side.
