<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00009TDgxHCATOkta Classic EngineLifecycle ManagementAnswered2023-08-28T14:17:15.000Z2023-07-21T18:01:53.000Z2023-08-28T14:17:15.000Z

SteveF.61090 (Customer) asked a question.

What Okta Groups/RBAC best practices are you using?

We've been using Okta for some time now, but have been assigning apps to individuals or creating generic app groups. I'm considering creating role specific permissions in Okta where everyone in that role will be assigned and the apps that they need access to are assigned. OIG and similar access requests systems seem to go the route of creating app groups where individuals can request access. I'm curious how everyone is implementing some level of RBAC within Okta.


  • User16594883467582706479 (Customer Support Online Experience)

    Hi, @SteveF.61090 (Customer)​ 

     

    Thank you for posting on our Community page!

     

    Here is an article that might help:

    https://support.okta.com/help/s/article/Requesting-Roles-Through-OIG-Access-Requests?language=en_US

     

    We'll leave this question open for other members to chip in with their experience.

     

    Thank you for reaching out to our Community and have a great day!

    _____________________________________________________________________________

    Community members help others by clicking Like or Select as Best on responses. Try it today.

    _____________________________________________________________________________

    Expand Post
  • SteveF.61090 (Customer)

    Thanks. What I'm looking for is advice on best practices for implementing RBAC.

     

    For example, the approach I'm currently taking is:

     

    Group (individual role - for example, customer success manager)

    • Applications (with permissions for this specific role)
    • Users are assigned to this role based on specific profile attributes using the group rules

     

    The other approach could be:

    Groups (individual apps with specific permissions)

    • Assign users to the groups based on specific profile attributes using group rules

     

    The difference is how I use groups. Is there another approach or is one of the above approaches considered a best practice or better than the other?

    Expand Post
This question is closed.
Loading
What Okta Groups/RBAC best practices are you using?