Prioritize groups

When you assign a group to an application, there might be information in the target application that you want to assign to the user.

For example, in Salesforce there is Profile and Role data. When a user is a member of more than one group assigned to the application, it might be confusing which Profile and Role they get. Group priority determines this.

To set group priority:

  1. In AdminAn abbreviation of administrator. This is the individual(s) who have access to the Okta Administrator Dashboard. They control the provisioning and deprovisioning of end users, the assigning of apps, the resetting of passwords, and the overall end user experience. Only administrators have the Administration button on the upper right side of the My Applications page. Console, go to Applications.
  2. Select an application.
  3. Click Assignments, and then click the GroupsGroups allow you to organize your end users and the apps they can access. Assigning apps to large sets of end users is made easier with groups. tab.
  4. Change the order of the groups by grabbing the dotted bar next to the group name and moving the group to the desired position in the list.ClosedScreenshot

Apply Options

Group Priority options can be accessed during attribute creation, as shown below, and can be changed later.

  1. In Admin Console, go to Directory > Profile Editor.
  2. Click Profile for an appAn abbreviation of application. Essentially, it is a web-based site used to perform any number of specific tasks, and requires authentication from end users by signing in..

  3. Click Add Attribute to add a new attribute, or scroll down to an existing attribute and edit it.

    You can then choose to Use Group Priority or Combine values across groups.

    Choosing Combine values across groups enables you to prioritize which individual attributes should be honored when a user belongs to more than one group.

  4. Click the Add or Save Attribute button.

Note: Attributes using this feature must use an array data type, and cannot be marked as User personal.

Combine values across groups example

The Office 365 app serves as a good example of how Combine values across groups works.

One very common attribute that Office 365 brings into Okta is Licenses. This is an attribute that might easily be shared by various groups within an organization. If a user is assigned to two different groups, Engineering and Sales, for example, which have overlapping attributes, choosing Combine values across groups would be the best choice because it unifies all the attributes.

For example, a user named Mike Barnes is given the Office 365 app. Mike is a member of both the Engineering and Sales teams, shown as groups in Okta.

Both groups receive License data from Office 365. If an admin chooses the Use Group Priority option in UD, Mike would only receive attributes from the Engineering team because the group holds priority on the group level.

If you choose Combine values across groups in UD, Mike would receive the attributes from both the Engineering and Sales groups because their attributes are combined.