<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y0000ALpr3eSQBOkta Classic EngineLifecycle ManagementAnswered2021-01-26T21:42:01.000Z2021-01-26T20:44:17.000Z2021-01-26T21:42:01.000Z

JesseB.86765 (Customer) asked a question.

Best Practices Using Life Cycle Management With Salesforce

I'm looking for some best practices to manage provisioning and de-provisioning of Salesforce using LCM - specifically best ways to organize groups in okta to manage provisioning in Salesforce. I.e. Should I create Okta Groups that align with Salesforce Profiles? Is there a better method?


  • User15851122134349081871 (North Central-Enterprise)

    There have been past posts here that indicate other Okta admins have gotten into trouble when they've tried to map Okta groups from Salesforce Profiles & Roles. The reasons for this are (1) that there are often a very large number of Profiles and Roles, and those don't all align, so you'd need a very large number of Okta Groups to correlate to them all, and (2) Profiles and Roles can change a lot, which would mess up your mapping. Those posters said their solution was to let Okta create the initial account with Role and Profile attributes but then not update them after.

     

    If you watch the video in our walk-through tutorial I believe he uses Department as the workflow value to determine provisioning options, because presumably that might change permissions less often?

    Expand Post
  • JesseB.86765 (Customer)

    That makes me feel a lot better, I was thinking the same thing, just trying to automate as much as I possibly could - I suppose I could try and do it by role also - like Developers, Solution Architects, Project Managers - see where I can find some crossover in those.. Thank you!

     

This question is closed.
Loading
Best Practices Using Life Cycle Management With Salesforce