<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

User Access after Org2Org is Removed

Okta Integration Network
Okta Classic Engine
Okta Identity Engine

Overview

This article explains what happens to the user's access after the Org2Org integration is removed.

The following must be confirmed to verify that the use case below is accurate:

  1. The user is provisioned to an Okta account via Org2Org Provisioning.
  2. If Org2Org is removed, can the user still log into the Hub Okta instance if the account is active?

Applies To

  • Org2Org
  • User Lifecycle Management
  • Password Sync
  • Okta Classic Engine
  • Okta Identity Engine (OIE)

Solution

Access to the hub will depend on the previous configuration of the spoke. In an org2org setup, users cannot directly access the hub unless they are syncing the Okta password from the spoke to the hub via password sync.

If that is the case, then users should be able to access the hub org directly and use their Okta password to log in to the Okta dashboard. If not, Admins would need to reset the passwords for the active users on the hub org. This is because when Admins initially assign the users to the org2org app, Okta generates a random password (assuming the active_with_pass option was selected during the app assignment). Before resetting their passwords, please have one of the users try to log into the hub directly using their Okta password.

NOTE: This assumes the users are sourced from Okta and not a third-party application or IdP like Active Directory or Workday.

Below is the password sync option that is being referenced: 
Password Sync 


Related References

Loading
Okta Support - User Access after Org2Org is Removed