<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00006z2dWnCAIOkta Classic EngineAdministrationAnswered2024-08-23T09:00:43.000Z2021-05-26T14:45:34.000Z2021-05-30T11:11:44.000Z

ChrisC.91230 (Customer) asked a question.

API Token Creation for HR Master

I would like to create an Admin user just for the purpose of creating API Tokens. These would be used to connect an HR Master (Rippling) and be able to create/suspend users as well as update profile info. I'm not sure what minimum permission level this Admin user needs to do this.


  • User15871004093001868702 (Vendor Management)

    Hi Chris,

     

    This is Florin from Okta support. Normally we recommend that you use a Super Admin service account to perform this actions. You can also check the comparison table in the link below:

    https://help.okta.com/en/prod/Content/Topics/Security/administrators-admin-comparison.htm

    So as for the question what is the minimum requirement it should be App admin + Group admin as a bare minimum, I will also add Read only admin in the mixt for more visibility. Hope this helps!

     

    Expand Post
  • ydce6 (ydce6)

    Hello, remember least privilege!!’ The above from Okta is a reply for ease of doing it and super bad practice! Super admin is just wrong lol.

    The admin groups stated give app and group edit access as the name reflects and not user edit if user is not in said app.

    i would suggest app admin to the individual domain. We do this as ad is considered an app. Join Facebook okta help tips and tricks for a growing community.

     

    Expand Post
This question is closed.
Loading
API Token Creation for HR Master