
User16435512093095459509 (Customer) asked a question.
For the Office365 SSO via WS-Federation and for provisioning, we are required to supply a user name and password for an Office365 admin user. Is it possible to see exactly what actions the user will perform in the AD tenant, so that we can assign the user a more locked down role than Global Admin?

Hello
Thanks for posting.
When you integrate Okta with Office one of the steps requests your Office 365 Administrator Username and Password.
Something very important is to Ensure your administrator credentials for the Office 365 are NOT in the domain you are federating.
This will lock you out of the Office 365 domain. You won’t be able to authenticate yourself in Microsoft 365 Admin Center as you have to authenticate through Okta, where you will be treated as a user, not as an admin. Ensure you are using administrator credentials for an account that is on your default Office 365 domain. This domain is by default yourtenant.onmicrosoft.com.
Now, this user will not have ANY access to the Okta tenant or the AD, they are not related unless that same O365 Admin account be an AD user at the same time, which is not something common.
More information about the integration here:
https://help.okta.com/en/prod/Content/Topics/Apps/Office365-Deployment/configure-sso.htm#Configur2
Let us know if this helps you.
Daniela Chavarria.
Okta Inc.