
tqcgw (tqcgw) asked a question.
Hi,
We try to propagate groups in the claim to the OIDC-enabled application (Elasticsearch).
Do we have to create custom authorization server in Okta to do that or we can just configure Okta’s Org Authorization Server as showed in the screenshot below:

Hello @iuoho (iuoho),
You can create an authorization server using the scope find in the org, you can use the link below to verify and confirm the information provided:
https://developer.okta.com/docs/guides/customize-authz-server/main/#create-rules-for-each-access-policyhttps://help.salesforce.com/s/articleView?id=000326027&type=1
Let us know if this article was helpful and if allows you to meet your goal.
Regards,
Natalia
Okta Inc.