<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00007rpyjDCAQOkta Classic EngineIntegrationsAnswered2024-05-07T10:56:03.000Z2022-07-29T14:19:45.000Z2022-07-29T22:44:38.000Z

SunilP.89679 (Customer) asked a question.

Org2Org user push from spoke to hub with same username, group push , application push

Hi,

 We are using Okta Org2Org application purely for user provisioning with password synch and groups push from spoke to hub.

I have below questions regrading this

1) What happens if there is a user with same username in hub ? which user password will be retained in hub , is it of user present in hub or the user present in spoke ? what are the linked users in okta ?

2) When we enable group push , all the users accounts assigned to this group in spoke will be pushed to hub ? or do I need to assign this group to "Okta Org2Org" application so that these users are pushed to Hub?

3) once all users from Spoke are pushed to hub , can I shut down the spoke okta tenant and use only hub for signing in the users ?

4) Can I use inline hooks in hub when a user is being created in hub from spoke ? I need to be able specifically differentiate that the user is being created through Okta Org2Org application .

5) how to push applications also from spoke to hub ?

 

Thanks in advance.


  • Hi @SunilP.89679 (Customer)​ , Thank you for reaching out to the Okta Community!

     

    I'll try to answer your questions one by one, but please keep in mind that there are many possible variables and there might not necessarily be a straight answer for all your questions. 

     

    1) What happens if there is a user with same username in hub ? which user password will be retained in hub , is it of user present in hub or the user present in spoke ? what are the linked users in okta ?

    • It all depends on what configuration you have - the pushed users could get a new account, or could be matched with the preexisting ones. 

    Pasted Graphic2) When we enable group push , all the users accounts assigned to this group in spoke will be pushed to hub ? or do I need to assign this group to "Okta Org2Org" application so that these users are pushed to Hub?

     

    3) once all users from Spoke are pushed to hub , can I shut down the spoke okta tenant and use only hub for signing in the users ?

    • Yes, but again it depends on the configuration - if the spoke is configured as a IDP for the user, then you'll have to sever the link before you can sign in. Password resets might also be required. 

     

    4) Can I use inline hooks in hub when a user is being created in hub from spoke ? I need to be able specifically differentiate that the user is being created through Okta Org2Org application .

    • There is no explicit marker for a user profile in relation to the source of creation. At best, if the Org2Org implementation is also configured as the IDP, the users page would show a message that says "Profile Sourced by Org2Org" - see below example:

    O Reset Password More Actions v 

    5) how to push applications also from spoke to hub ?

    • Applications or application configuration currently cannot be pushed to other orgs. You can suggest this as a feature enhancement on the Okta Community page by going to the Community Ideas tab. Features suggested in our community are reviewed and can be voted and commented on by other members. High popularity will increase the likelihood of it being picked up by the Product Team and it being implemented. 

    More details here: 

     

    If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you. 

     

    Hope it helps! 

    Expand Post
This question is closed.
Loading
Org2Org user push from spoke to hub with same username, group push , application push