Configure assignments

Configure assignments end-to-end: create relationships as needed, add principals with relationships, and select resources.

About this task

Early Access release

You can create up to 10,000 assignments per team. Each assignment can include up to 10,000 resources and up to 1,000 relationship-assignments (principal-relationship pairs). See Assignments quotas and limits for all team-wide limits.

When you create an assignment, you can create new relationships inline if needed, or select from existing relationships in your catalog.

Before you begin

Procedure

  1. In the Okta Privileged Access console, go to Security Administration > Assignments.
  2. Click Create Assignment.
  3. Enter an assignment name and an optional description.
    Use descriptive names that reflect what the assignment represents (for example, "Finance DB Team," "Dell Linux Fleet").
  4. Click Create Assignment.
    The assignment detail page opens, where you can add relationships and principals.
  5. Select a relationship from the dropdown menu, or click Create relationship to define a new one.
  6. Select principals to add to this relationship:
    1. In Groups, click the dropdown menu and select one or more groups.
    2. In Users, click the dropdown menu and select one or more users.
    3. In Workload roles, click the dropdown menu and select one or more workload roles.
  7. Repeat steps 5–6 to add more relationships as needed.
  8. In Resources, select a resource type.
  9. Search for or select the resources to include in this assignment.
    You can select individual resources or click Select all to include all available resources of that type.
  10. Click Save Assignment.
    The assignment is saved with all relationships and resources.

What to do next

After you configure your assignments, you can use them in assignment-based security policies to grant access based on relationships. You can edit assignment names, descriptions, relationships, and resources, or delete assignments directly from the Assignments tab. To manage relationships, see Configure relationships.