Provisioning for Single Sign-on (SSO) enabled apps can be enabled in Okta without breaking the SSO functionality. To avoid making changes to your SSO-enabled app, you can create another instance of the app where Okta provisioning is enabled. The SSO-enabled app and the provisioning-enabled app are "linked" through the use of the same user folders. This affords provisioning functions to the SSO-enabled app.
The provision-enabled app runs in the background and is not accessible to end users. (The app is not in the end-user org.) End users will only have access to the SSO-enabled app. The provision-enabled app is only for user and app management.