<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Office 365 OIN Application Account Permissions for Configuration
Okta Integration Network
Okta Classic Engine
Okta Identity Engine
Overview

This article discusses why the Global Admin role is needed for the service account used for federation or enabling provisioning for Microsoft Office 365.

Applies To
  • Office 365
  • Federation
  • Provisioning
  • Permissions
Cause

Administrators are concerned about leaving Global Admin Permissions enabled for the account used to Authenticate Provisioning or Federation.

Solution

Okta needs Global Admin permissions for the service account used to federate and provision between Okta and Microsoft Office 365, and these permissions need to remain even after the initial configuration. Microsoft and Okta require these permissions for security reasons. Therefore, only admins can consent to larger scopes and more significant permissions, while users’ consent is scoped to the users' data and capabilities.

See the scenarios below for more information:

  • The O365 Global Admin Account used for Automatic Federation must remain a Global Admin.
  • The O365 Global Admin Account used for Authenticating Provisioning can be placed in the least privileged state, as we rely on the Graph API to perform Provisioning actions.
    • NOTE: Please re-authenticate the API. The O365 Account Global Admin permissions must be granted again.
  • If the same account is used for Automatic Federation and Authenticating Provisioning, the Global Admin Permissions must remain.

Related References

Loading
Office 365 OIN Application Account Permissions for Configuration