<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00009JbJdfCAFOkta Classic EngineAdministrationAnswered2024-04-17T12:01:56.000Z2023-06-15T07:51:37.000Z2023-06-15T15:56:33.000Z

el52v (el52v) asked a question.

How will okta react to G suite service account associated to applications

Hello,

I have g suite service accounts in our organisation for different applications which are associated with real user accounts. G suite to okta integration will be done but i wanted to understand how okta will react to those service accounts and what will be the process of making that integrations


  • NiallM.34104 (Atlas Identity)

    You're moving to having G-Suite as a source of identities, and you want a service account in G-Suite to be linked to existing Okta profiles ? Or you are enabling G-Suite for SSO and LCM from Okta ?

     

    Either way, the link from the human account to the service account is they key. Okta allows you to define this, and if those follow a pattern that you can apply logic to it will be easier.

     

    If it's G-Suite as a source, look at your import settings. If Okta doesn't find a match, the account will remain in the import table and you can manually assign it to an existing Okta account.

     

    If it's G-Suite for SSO and LCM you're looking at a custom User ID expression language to ensure Okta finds the relevant match. Again if there are naming standards in play that would allow you to code the user to the service account, you're in a better position.

     

    Do these real users also have a Google standard account ? The mapping is 1 to 1.

    Expand Post
  • el52v (el52v)

    I am integration G-suite(SAML Integration) with okta and wanted to ask what will happen to service accounts when the integration is in place. These service accounts are from G-suite.

  • NiallM.34104 (Atlas Identity)

    Hi Ovais. OK. Nothing will happen to those accounts. That might not be what you want though. So let's turn it around. What do you want the end result to be ? Presume you want the real user that 'own' those accounts to be logging into Okta as themselves, but log into G-Suite as the admin account ?

     

    Also if they are flagged as administor accounts in G-Suite they will need to login to G-Suite with user/password anyway. SSO doesn't apply to admin accounts in G-Suite by default.

    Expand Post
  • el52v (el52v)

    So for some service account there're email coming and some are there to access application. After Google sso enabling the user account will be routed to okta for opening gmail how this service accounts will see there email when they don't have access to okta as a user ?.

     

This question is closed.
Loading
How will okta react to G suite service account associated to applications