
ChrisC.91230 (Customer) asked a question.
I would like to create an Admin user just for the purpose of creating API Tokens. These would be used to connect an HR Master (Rippling) and be able to create/suspend users as well as update profile info. I'm not sure what minimum permission level this Admin user needs to do this.

Hi Chris,
This is Florin from Okta support. Normally we recommend that you use a Super Admin service account to perform this actions. You can also check the comparison table in the link below:
https://help.okta.com/en/prod/Content/Topics/Security/administrators-admin-comparison.htm
So as for the question what is the minimum requirement it should be App admin + Group admin as a bare minimum, I will also add Read only admin in the mixt for more visibility. Hope this helps!
Hello, remember least privilege!!’ The above from Okta is a reply for ease of doing it and super bad practice! Super admin is just wrong lol.
The admin groups stated give app and group edit access as the name reflects and not user edit if user is not in said app.
i would suggest app admin to the individual domain. We do this as ad is considered an app. Join Facebook okta help tips and tricks for a growing community.