| Push new users |
- Okta provisions new users created in Okta in Tines.
- The username must be a valid email address. It's the unique identifier for the user account.
- Users are created in an active state by default.
- The default user type is USER. To assign the TENANT_OWNER user type, you must configure it explicitly from the Okta Identity Governance instance. A user must be provisioned as USER before being assigned TENANT_OWNER. The TENANT_OWNER user type grants full admin access immediately.
- The basic fields required to create a user are username, first name, and last name.
|
| Push profile updates |
- You can update the first name, last name, and user type fields.
- Once SCIM is enabled on a Tines tenant, all user field edits for first name, last name, and user type must come through SCIM from Okta. The Tines UI blocks manual edits to these fields to prevent conflicts with Okta as the source of truth.
- Updates made to a user's role in Okta are pushed to Tines.
|
| Push user deactivation | Deactivating a user or disabling their access to the app in Okta deactivates their account in Tines. The account record is retained but marked as deactivated. It isn't deleted. |
| Import new users |
- Okta imports users created in Tines.
- If a user is missing a first name or last name, Okta assigns placeholder values of FNU and LNU, respectively.
- Tines doesn't have a separate field for email addresses, so Okta sets the username to the user's email address when importing users.
|
| Import profile updates | Okta downloads updates made to a user's profile in Tines and applies them to the profile fields stored locally in Okta. |
| Reactivate users | Reactivating or enabling a user in Okta reactivates their Tines account. |
| Entitlement Management |
- Tines supports Entitlement Management. If you use Okta Identity Governance, you must enable this feature.
- Tines supports only two entitlements through the userType field: USER (default) and TENANT_OWNER (admin).
- Map admin roles or groups in Okta to TENANT_OWNER.
|
| Push groups |
- You can push groups and their members to Tines. See Manage Group Push.
- Tines doesn't provide a UI for managing groups. All group operations must be performed through the SCIM API.
- Group membership can be managed only through Okta or directly through SCIM endpoints. Removing a user from a group only removes their group membership. It doesn't delete the user.
- Only the display name is required when creating a group in Tines.
- Tines doesn't support the description field, so group descriptions aren't synced from Okta. If an Okta group has a description, it's discarded during sync.
- Group names aren't case-insensitive. For example, EngineeringTeam and engineeringteam are treated as different names.
- Groups with emoji in their display name aren't imported to Okta. Other special characters are supported.
- Deleting a group performs a hard delete. All group data is permanently removed and members are automatically unassigned.
|