<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00009hMRwrSAGOkta Classic EngineAdministrationAnswered2024-04-16T10:41:29.000Z2020-10-16T00:57:30.000Z2020-10-27T23:43:51.000Z

d6l7s (d6l7s) asked a question.

suspended users that still have full access

Going through my user logs and I have several current employees with suspended accounts in okta but still have full access to all the apps. These are all employees that were existing before the rollout. Unfortunately I was not part of the rollout and I am taking over the IT department.


  • d6l7s (d6l7s)

    Yes, basically my feeling is that it's only halfway implemented and rolled out. I do not think they worked with anyone at Okta when implementing​. I feel like I'm somewhere between implementing and operational since it's live with 3/4 of the employees. And it's working fine for me and other employees that were added after it was implemented. Would definitely like to speak to somewhere somewhere between solution engineer and success manager. As far as provisioning nothing is set up to provision except a few things I recently added.

    Expand Post
    Selected as Best
  • Hi Eric, Suspended users which are not longer active can be deactivated.

    If there's a way you can identify these users are termed, by any of the ways like comparing from an HR feed etc, you can write a script using Okta APIs to deactivate the terminated users which are suspended.

    If the app's LCM flow is set to Disable users on Deactivations, the deactivated users will no longer have access to the apps.

     

    Expand Post
    • d6l7s (d6l7s)

      It seems you don't understand. I want them to have access. They are current employees with suspended accounts but still have full access to everything even though Okta should theoretically be blocking access. Basically, Okta is not preventing anyone from using our apps.

  • User15851122134349081871 (North Central-Enterprise)

    Taking a step back from Priti's good suggestions, Eric: your expectation is that Okta-deactivated users should have access to their target accounts removed too. Is that valid? It doesn't have to be the case, and it depends on what you've bought and what you've got configured. Does your Okta implementation map values between Okta and downstream apps that would make a user's app account inactive? Do you have LifeCycle Manager (LCM) to do provisioning and de-provisioning of accounts in target accounts?

    Expand Post
  • d6l7s (d6l7s)

    Well that's the thing, I wasn't here for the roll out and I'm cleaning up the mess.​ My expectation is that Okta was controlling full access to anything set up as an app. However what is appearing as if someone already had an account in say g suite They are still able to access it and completely bypass Okta control with their old credentials. But the upstream downstream thing is clicking so I do need to look at that. I was just under the assumption if somebody didn't have an active account there's just absolutely no way to access any apps that we have associated. Currently there is no LCM. Accounts are all created manually and each app. It is my goal though. I just need to clean up a very hasty roll out and config.

    Expand Post
    • User15851122134349081871 (North Central-Enterprise)

      It depends on what sort of authentication and apps you have integrated to Okta, but if some of them use SAML then it sounds like you might want to set up SP-initiated flows where even if a user tries to sign in directly to an app's page they get redirected back to Okta. See this: https://support.okta.com/help/s/article/Beginner-s-Guide-to-SAML

      Bottom line: it's clear that work needs to be done to determine the gap between the system you have configured today vs the system you think you should have (or want). I'd suggest that's going to be a bigger effort than you're likely going to be able to resolve via these discussion forums. 😁

      Do you have a team from Okta you're already working with? A Sales or Solution Engineer if you're still implementing, or a Customer Success Manager if you're operational?

      Expand Post
  • d6l7s (d6l7s)

    Yes, basically my feeling is that it's only halfway implemented and rolled out. I do not think they worked with anyone at Okta when implementing​. I feel like I'm somewhere between implementing and operational since it's live with 3/4 of the employees. And it's working fine for me and other employees that were added after it was implemented. Would definitely like to speak to somewhere somewhere between solution engineer and success manager. As far as provisioning nothing is set up to provision except a few things I recently added.

    Expand Post
    Selected as Best
    • Hi Eric,

       

      Let me know if you'd like me to get a Sales Engineer to contact you to find out what options you have available to you to get your instance cleaned up so you can get fully rolled out.

       

      Thanks!

      Tim (the other one)

      Okta, Inc.

       

      Expand Post
This question is closed.
Loading
suspended users that still have full access