| Push new users |
- New users that you assign to the app in Okta are pushed to MongoDB Atlas as organization invitations.
- A username in email format and at least one organization role are required.
- In non-governance orgs, the
ORG_MEMBER role is assigned by default. In governance orgs, an organization role is required and project roles are optional. When you assign an organization-level role, MongoDB Atlas automatically assigns the corresponding project-level roles. See MongoDB Atlas User Roles.
Warning: MongoDB Atlas limits invitations to 10 per minute and 500 users per organization.
|
| Push profile updates |
- Username and email are immutable after account creation and can't be updated.
- In non-governance orgs, no parameters are updatable. New users provisioned through Okta receive the default organization role, and existing imported users keep their current roles.
- In governance orgs, you can update organization roles and project roles. An organization role is required and must contain at least one role.
|
| Push user deactivation |
Deactivating a user, or disabling their access to the app, in Okta deletes the user from the MongoDB Atlas organization. |
| Import new users |
Okta imports active and pending (invited) user accounts from the MongoDB Atlas organization. |
| Import profile updates |
- Okta downloads updates made to a user's profile in MongoDB Atlas and applies them to the corresponding profile fields in Okta.
- In non-governance orgs, no parameters are updatable. New users provisioned through Okta receive the default organization role, and existing imported users keep their current roles.
- In governance orgs, you can update organization roles and project roles. An organization role is required and must contain at least one role.
|
| Push groups |
- Groups pushed from Okta are created as teams in MongoDB Atlas. See Manage Group Push.
- Team names must be unique within the organization and aren't case-sensitive. Names can contain numbers, but can't contain special characters other than
:, ,, @, -, and _.
- You can only update the team name. Teams don't support a description field.
- When you push a large number of group members, for example 250, to a team, some requests might intermittently fail. Running push sync again completes the remaining members.
Warning: A MongoDB Atlas organization supports a maximum of 250 teams, and a team can have a maximum of 250 members. See Service Limits for MongoDB.
|
| Entitlement Management |
- You can manage app entitlements for MongoDB Atlas in Okta at the organization and project levels. Entitlement management requires Okta Identity Governance.
- An organization role is required when you create a user. Project roles are optional.
- You can assign multiple roles to a user.
|