<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00006yO4mOCASOkta Classic EngineAdministrationAnswered2024-03-25T20:02:55.000Z2021-05-13T01:41:17.000Z2021-05-16T04:19:55.000Z

wjw8p (wjw8p) asked a question.

Isolating org admins from adding users to sensitive groups

We have a traditional setup where IT owns the Okta org and all admin functions. We'd like to integrate our Okta directory with some cloud infrastructure services and grant access to users via specific groups that a different team manages - however, we also want to prevent the chance of a compromise of our IT team being used to move sideways into these other cloud infrastructure services. In other words, prevent IT from unilaterally adding users to our groups controlling access in these 3rd party systems.

 

Is the only solution to have a completely separate Okta organisation that we manage ourselves, or is there another way to do this within the one Okta organisation?


  • Cristian (Vendor Management)

    Hello Oliver,

     

    Thank you for contacting Okta. Cristian here with the Support Team.

    Unfortunatelly you cannot limit Super admin access to certain appliations ( Active Directory in this scenarios). As you mentioned the best approach would be to create separate organisations.

    If you need further assistance with the integration please open a ticket with our Support Team and we will be happy to assist you.

    Have a great day!

    Expand Post
This question is closed.
Loading
Isolating org admins from adding users to sensitive groups