Pablo (Customer) asked a question.
0D50Z00008G7UxnSAFOkta Classic EngineAdministrationAnswered2024-04-17T12:43:50.000Z2015-09-17T18:10:12.000Z2016-08-08T14:11:12.000Z
Have you used 'hub and spoke orgs' for an acquisition or a divestiture?
We are working through a divestiture and are looking to the hub-and-spoke configuration to make this process easier and in a secure way. Has anyone done this before?
This question is closed.
Recommended content

- SAML apps that you still want employees in the spokes to be allowed to access
- AD Agent (Desktop SSO/ AD authentication for domain connected PC's) for the hub with the OU container selected for hub employees
- O365 app for Federation partnership with the mail/mx/DNS domain record owned by the hub for email
In the spokes- AD Agent with the OU container selected for each set of spoke employees
- O365 app for Federation partnership with the mail/mx/DNS domain record owned by the hub for email
- inbound SAML partnership between the spokes and the hub to allow employees in the spokes access to those apps the hub still wants to share
- Above assumes the spokes at least start of by sharing the AD DC - but that mail could be divested straight away using separate O365 tenants
Next steps chat to your Enterprise cloud architect @ Okta!- Hub of shared apps (HSA) -- shared apps between two companies.
- Company 1 spoke (C1S) -- apps only available to company 1.
- Company 2 spoke (C2S) -- apps only available to company 2.
- Compnay X spoke (CXS) -- apps only available to company X.
Spokes access the hub but would require admins/joint admins for the hub: C1S --> HSA <-- C2S Inbound SAML: