<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Allow Non-Super Admins to Run Imports for Active Directory Integrations
Okta Classic Engine
Directories
Okta Identity Engine
Overview

This article details how to configure Custom Roles and Resource Sets to allow for a non-super admin to perform import actions for Active Directory integrations with Okta.

Applies To
  • Directories
  • Imports
  • Custom Roles
  • Resource Sets
Cause
Non-Super Admins may be unable to view or access the Import menu for Active Directory integrations configured with Okta. This behavior is expected when the non-Super Admin account does not have sufficient permissions to run Imports for the Active Directory application.
Solution

Follow the steps or video below.

 

Create a Custom Role

  1. Navigate to Security > Administrators > Roles.
  2. Select Create new role.
"Create new role" button
  1. Ensure the option Run Imports is checked under the Profile source permissions settings.
    • Configure remaining role permissions as desired.
"Profile source permissions" settings

Create a Custom Resource Set

  1. Navigate to Security > Administrators > Resources.
  2. Select Create new resource set.
"Create new resource set" button
  1. Designate a name and description for the new resource set. Select Add Resource.
"Add Resource" button
  1. In the "Find a resource type" search bar, select Applications from the drop-down menu. Then, click Save selection.
"Save selection" button
  1. Select the option for Select applications.
  2. Search "Active Directory" and select the option for All Active Directory applications. Select Save selection.
"Save selection" button
  1. Now, the newly created Role(s) and Resource set(s) can be configured for Administrators by navigating to Security > Administrators > Admins.
    • These settings will allow for non-super admin accounts to run imports from Active Directory integrations from the Admin Console, so long as they are configured for the non-super Admin account.
 
Loading
Allow Non-Super Admins to Run Imports for Active Directory Integrations