<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z000097LpeFCASOkta Identity EngineIdentity GovernanceAnswered2025-04-28T09:00:55.000Z2023-04-26T16:45:39.000Z2023-04-27T15:31:46.000Z

x1fdm (x1fdm) asked a question.

Walkthrough on how to switch from profile sync to universal sync?

Is there a complete tutorial on what happens when switching from profile sync to universal sync. I have reviewed the tablet on the Okta website, but I looking for a step to step guide. I am very apprehensive about enabling universal sync and my user not being able to login to their email.

Will user access to mailboxes be affected? Will user logins be affected?


  • x1fdm (x1fdm)

    Does Switching to universal sync makes OKTA that identity provider./? we have to disable AD Directory sync. How are the AD groups going to sync with O365 after the switch? Does OKTA handle that? Is there a sync cycle like AD sync every 30 mins?

     

    Universal Sync creates additional attributes in AD. Do we need to create these attributes ahead of time or do we map them when enabling Universal Sync? Does Universal Sync affect O365 licensing?

     

    Does Universal Sync make AD the identity provider? 

    Expand Post
  • Mihai N. (Okta, Inc.)

    Hi @x1fdm (x1fdm)​ , Thank you for reaching out to the Okta Community!

     

    From what I can see on my end, you've already opened a ticket with the Support team, so please continue working with my colleagues if you have any questions and concerns. 

     

    In the meantime for any one else in the Community looking to get some answers, the O365 Provisioning types are described in the following articles:

    https://help.okta.com/en-us/Content/Topics/Apps/Office365/References/provisioning-types.htm

    https://support.okta.com/help/s/article/Office-365-Provisioning-Type-Universal-Sync?language=en_US

     

    Will user access to mailboxes be affected? Will user logins be affected?

    • The Provisioning feature is independent of the SSO feature, login is not impacted 

     

    Does Switching to universal sync makes OKTA that identity provider?

    • Profile sourcing is not changed. 

     

    We have to disable AD Directory sync?

    • this is covered by the articles and is also displayed in the Provisioning UI. ("Universal Sync can’t be used with Directory Synchronization, Azure Active Directory (AAD) Sync, or Azure Active Directory Connect.")

     

    How are the AD groups going to sync with O365 after the switch? Does OKTA handle that?

    • This is an optional feature that can be configured under the O365 app's Provisioning tab. (see example below)

    Pasted 

    Is there a sync cycle like AD sync every 30 mins?

    • If you have AD integrated with Okta as the Profile Source, the frequency depends on you chosen import settings. (min. 1h - max. 2days *elapsed from the moment the previous import finished)  

     

    Universal Sync creates additional attributes in AD. Do we need to create these attributes ahead of time or do we map them when enabling Universal Sync?

    • I'm not sure that I understand what you meant by "created additional attributes in AD" - but the assumption is that a list of attributes already exists, the Okta Provisioning feature just facilitates the transfer to the downstream app via default mapping which might need tweaking in accordance to your organization's requirements. 

     

    Does Universal Sync affect O365 licensing?

    • Covered by the articles, but yes. All provisioning types handle license and role management.  

     

    Does Universal Sync make AD the identity provider? 

    • Switching Provisioning Type does not affect Profile Sourcing, if that is what you mean by identity provider.   

     

     

     

    If my answers helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you. 

     

    Hope my answer helps! 

    --------------------------------

    Community members help others by clicking Like or Select as Best on responses. Try it today.

    Expand Post
This question is closed.
Loading
Walkthrough on how to switch from profile sync to universal sync?