
8jzx9 (8jzx9) asked a question.
I am very interested in the automation found in Okta for onboarding and offboarding employees. As I understand it, in order to do that, I need to add Okta as an IdP using Azure App Registration. A co-worker of mine has made the statement that this will override Azure as our existing IdP. My understanding is that it will allow Okta to see our Active Directory and perform onboarding and offboarding in the various systems that we use. As I understand it, our Azure will continue to be an IdP. For example, our AD Sync will continue to function without issue, correct? Our Microsoft 365 will continue to function being synced to Azure, etc., correct? As I understand it, an organization can have multiple IdPs, correct?

Hi, @8jzx9 (8jzx9)
Thank you for posting on our Community page!
This is a very broad question and a complex implementation depending on the requirements that can’t be covered via a Community post but a high level explanation would be as follows:
It all depends on how you want the information to flow.
If you want to handle license/role/user lifecycle from the Okta side and have Okta handle authentication, you could piggyback on the Office 365 implementation that has WS-FED SSO and Provisioning:
https://help.okta.com/en-us/content/topics/apps/office365/o365-main.htm
*certain provisioning types are not compatible with Directory Synchronization, Azure Active Directory (AAD) Sync, or Azure Active Directory Connect.
https://help.okta.com/en-us/content/topics/apps/office365/references/provisioning-types.htm
There are also some integration options for Azure AD via Okta Workflows:
https://help.okta.com/wf/en-us/content/topics/workflows/connector-reference/azuread/azuread.htm
If you want information to flow from Azure AD to Okta, then you could look into the following:
https://support.okta.com/help/s/article/how-to-sync-azure-ad-with-okta?language=en_US
For more in depth suggestions based on your needs, I would suggest contacting our Sales department.
Ask the Experts: Now Thru 1/31 Okta FastPass Engineering and Product Teams Answer Your Questions
Community members help others by clicking Like or Select as Best on responses. Try it today.
_________________________________________________________________________