| Push new users |
- You can create new users in Pulumi Cloud when you assign the app to users in Okta. Provisioned users are added with the default role of Member.
- Entitlement management isn't available for this integration. Manage user roles for Pulumi Cloud in the Pulumi Cloud admin console.
- Pulumi Cloud enforces global email uniqueness. If a user's email address is already associated with an existing Pulumi Cloud account, the user creation fails.
|
| Push profile updates |
- Updates that you make to a user in Okta are pushed to Pulumi Cloud.
- Pulumi Cloud sets the username at creation. You can't change the username afterward.
|
| Push user deactivation |
- Deactivating a user or removing the user's access to the app in Okta also deactivates the user's account in Pulumi Cloud and removes the user's access to the org.
- Pulumi Cloud performs a soft deactivation. The user record is retained, and you can reactivate the user later.
|
| Reactivate users |
- Reactivating a user in Okta restores the user's access to the Pulumi Cloud org.
|
| Import new users |
- You can import users and teams that Pulumi Cloud provisioned through SCIM into Okta.
- Only users that Pulumi Cloud provisioned through SCIM are available to import. Users added to Pulumi Cloud through other methods aren't imported.
|
| Push groups |
- Groups that you push from Okta are created as teams in Pulumi Cloud. See Manage Group Push.
- You can update only the team name from Okta. Team names must be unique in the org and aren't case-sensitive.
- You can add or remove team members at any time from Okta.
- Pulumi Cloud manages team roles in its own admin console. Role management for teams isn't available from Okta.
|