| Push new users |
- Users created in Okta are also created in Domo. The Username and
Email values for a user must match.
- For non-governance instances, users are created with the default role that's configured in the Domo Admin panel.
- For governance instances, selecting a user role is optional. Selecting an unconfigured policy assigns the default role.
- The integration supports all standard and custom Domo roles.
|
| Push profile updates |
- Updates to the Okta user profile are pushed to Domo.
- You can update the First name and Last name fields.
You can't update the Username or Email fields.
- To change a username or email, you must unassign the current user and create a new user profile with
the desired credentials. The username and email values must match.
- Modifying a username doesn't edit the current profile. Doing this creates a user account that has the
modified username and a matching email address.
|
| Push user deactivation |
CAUTION: Deactivating a user or disabling their access in Okta permanently deletes the user in Domo. There is no soft deactivation and no way to recover the account.
If a Domo user owns assets such as Cards, Pages, DataSets, or DataFlows, the deactivation fails with an error. Before deactivating the user in Okta, an admin must log into Domo and reassign ownership of all associated assets to another active user.
|
| Import new users |
Users and groups from Domo are imported into Okta.
|
| Reactivate users |
Reactivating a user in Okta recreates the user in Domo.
Note: Because deactivation permanently deletes the user record, reactivation creates a brand new user account. All previous data and group memberships from the original account are permanently lost.
|
| Entitlement Management |
- Domo supports Entitlement Management. You must have Okta Identity Governance (OIG) enabled on your Okta org.
- If no role is provided during user creation, Domo assigns the default role that's configured in the Domo UI.
- If no role is provided when updating a user, the existing role remains unchanged.
Note: You can't remove or reverse a role after assigning it. You can only update it or
change it to another active role.
To lower elevated privileges, explicitly reassign the user to a lower-privilege role.
|
| Push groups |
- You can push groups and their members to Domo. See Manage Group Push.
- SCIM only manages directory groups (for example, Active Directory and LDAP groups). Other group types aren't supported.
- Directory groups can't be managed through the Domo UI. Members can only be added or updated through Okta or the Domo SCIM API.
- You can add any active user in the org as a member.
- You can update group display names and descriptions.
- Group names are case-insensitive for uniqueness, but their original casing is preserved.
- Avoid using special characters such as
#, @, !, and & in group names, as they may cause group creation or update failures. Use only letters, numbers, spaces, hyphens, and underscores.
|