
DavyC.46853 (Customer) asked a question.
Hello,
We (CISO/CTO) are looking for a way to delegate onboarding/offboarding parts to our internal support team while giving the least possible access to okta in general. (Idea being pre-defined roles that can be configured during onboarding, and offboarding that can be done when needed, potentially even with approval).
Do you have any recommendations on how to do this, or other best practices how this is typically delegated by IT to HR/support?
Thanks

Hi @DavyC.46853 (Customer),
Thank you for posting on the Okta community page!
I have done some research regarding your inquiry and I have managed to find the below documentations that provide information about each administrator permissions and about how you can create custom administrator roles:
Additionally, you can leverage group rules to add specific users to an administrator group automatically based on user attribute or group membership.
On another note, the Okta Community Catalysts Program is now live. Collect online badges when you participate in the Okta Help Center Questions community. Learn more here.
I hope the above information is useful!
[image: Doctena] <http://doctena.com/>
Davy COX
*Chief Information Security Officer*
Phone: +352 27 86 79 14
Email: davy.cox@doctena.com
Website: www.doctena.com
*Are you a health professional? Check out DOCTENA PRO
<https://www.doctena.com/en-lu?utm_source=email-signature&utm_medium=email-pro&utm_campaign=doctena-email-signature>*
[image: image]
This e-mail message may contain confidential and/or privileged information.
If you are not an addressee or
otherwise authorized to receive this message, you should not use, copy,
disclose or take any action based on
this e-mail or any information contained in the message. If you have
received this material in error, please
advise the sender immediately by reply e-mail and delete this message.
Thank you.
Thank you for the answer, I will be asking this of my leadership also so I can get the access going without the extra needed for full admin request.