Create user campaign
Review the resources assigned to selected users, ensuring each user only retains the access they need within Okta Identity Governance.
Options
| Field | Definition | Type | Required |
|---|---|---|---|
|
Schedule Type |
Defines whether the campaign runs a single time or repeats on a defined schedule.
|
Dropdown | TRUE |
|
Scope |
Specifies how principals (users) included in the campaign are selected.
|
Dropdown | TRUE |
|
Resources |
Specifies which resource types are reviewed for the selected users.
|
Dropdown | TRUE |
|
Exclude Resources |
Choose whether specific users should be excluded from the campaign even if they otherwise match the user scope.
|
Dropdown | TRUE |
|
First Level Reviewer |
Defines who performs the initial review of access items in the campaign.
|
Dropdown | FALSE |
|
Add Another Level |
Choose whether a second-level (escalation or approval) review stage is enabled.
|
Dropdown | TRUE |
|
Second Level Reviewer |
Defines the reviewer responsible for second-level review decisions when multi-level review is enabled.
|
Dropdown | FALSE |
Input
| Field | Definition | Type | Required |
|---|---|---|---|
|
Campaign |
|||
|
Name |
The name of the campaign. |
Text | TRUE |
|
Description |
A description of the campaign. |
Text | FALSE |
|
Tier |
The minimum required SKU to manage the campaign.
|
Dropdown | FALSE |
|
Schedule Settings |
|||
|
Start Date |
The date on which the campaign is supposed to start. |
Date & Time | TRUE |
|
Time Zone |
The time zone, in IANA format, for the start date of the campaign. |
Dropdown | TRUE |
|
Duration In Days |
The duration (in days) that the campaign is active. The duration can't exceed 90 days, and must be a minimum of 7 days if the campaign is reviewed in multi-level. |
Number | TRUE |
|
Recurrence Settings |
|||
|
Interval |
The interval of the recurrence.
Interval values that conflict with the duration of the campaign result in an invalid request. For example, setting a duration of 21 days and an interval of every two weeks results in an invalid request. |
Number | TRUE |
|
Interval type |
The type of the interval.
|
Dropdown | TRUE |
|
Ends |
The date on which the resource campaign ends. |
Date & Time | FALSE |
|
Repeat on Type |
Specifies the day of the month to repeat the campaign. Applicable only if the Interval Type is Months.
|
Dropdown | FALSE |
|
Principal Scope Settings |
|||
|
User ID |
The list of Okta users included in the user campaign, up to a maximum of 100. |
List of Text | FALSE |
|
Group ID |
The list of Okta groups included in the user campaign, up to a maximum of 5. |
List of Text | FALSE |
|
Custom Search Criteria |
Include a custom search in the Okta Expression Language to include users in the campaign. A maximum of 100 users can be specified in the list. |
Text | FALSE |
|
Resource Settings - Resource specific properties |
|||
|
Individually Assigned Apps Only |
If true, only include individually assigned apps. |
True/False | FALSE |
|
Individually Assigned Groups Only |
If true, only include individually assigned groups. |
True/False | FALSE |
|
Only Include Out Of Policy Entitlements |
If true, only include out-of-policy entitlements. This is applicable when resources selected are either Apps and Groups or Apps. |
True/False | FALSE |
|
Include Admin Roles |
If true, include users assigned to admin roles in the campaign. |
True/False | FALSE |
|
Exclude Resources |
|||
|
Group ID |
The unique identifiers of groups to exclude. |
List of Text | FALSE |
|
Application ID |
The unique identifiers of Apps to exclude. |
List of Text | FALSE |
|
1st Level Reviewer |
|||
|
Reviewer ID |
The unique identifier of the reviewer. |
Text | TRUE |
|
Self Review Enabled |
If true, users can review their own review items. |
True/False | FALSE |
|
Reviewer Group ID |
The unique identifier of the reviewer group. All members of the group are reviewers for the campaign. If the group contains only one member, then that member is assigned as the reviewer for all reviews, and the reviewer type is set to User for those reviews. When the campaign launches, if the group has more than 10 members, 10 members from the group are randomly set as reviewers for the campaign. |
Text | TRUE |
|
Reviewer Scope Expression |
The expression to derive a reviewer for the campaign. This is typically used when the manager is the reviewer. For the Manager reviewer type, the reviewer scope expression is fixed at user.profile.managerId. |
Text | TRUE |
|
FallBack Reviewer ID |
The unique identifier of the fallback reviewer. A fallback reviewer is assigned if the Reviewer Scope Expression doesn't identify any reviewers, or reviewers aren't identified through resource owners. |
Text | TRUE |
|
On Day |
The day when second-level reviews start. For the first level, this value is always 0 since the first level starts when the campaign starts. For the second level, enter a value that's greater than 0. This indicates the day when the reviews move to the second level. |
Number | TRUE |
|
2nd Level Reviewer |
|||
|
Reviewer ID |
The unique identifier of the reviewer. |
Text | TRUE |
|
Self Review Enabled |
If true, users can review their own review items. |
True/False | FALSE |
|
Reviewer Group ID |
The unique identifier of the reviewer group. All members of the group are reviewers for the campaign. If the group contains only one member, then that member is assigned as the reviewer for all reviews, and the reviewer type is set to User for those reviews. When the campaign launches, if the group has more than 10 members, 10 members from the group are randomly set as reviewers for the campaign. |
Text | TRUE |
|
Reviewer Scope Expression |
The expression to derive a reviewer for the campaign. This is typically used when the manager is the reviewer. For the Manager reviewer type, the reviewer scope expression is fixed at user.profile.managerId. |
Text | TRUE |
|
FallBack Reviewer ID |
The unique identifier of the fallback reviewer. A fallback reviewer is assigned if the Reviewer Scope Expression doesn't identify any reviewers, or reviewers aren't identified through resource owners. |
Text | TRUE |
|
On Day |
The day when second-level reviews start. For the first level, this value is always 0 since the first level starts when the campaign starts. For the second level, enter a value that's greater than 0. This indicates the day when the reviews move to the second level. |
Number | TRUE |
|
When |
The condition for reviews to move from the first to the second-level reviewer.
|
Dropdown | FALSE |
|
Reviewer Settings |
|||
|
Justification Required |
If true, a justification is required when review items are approved or revoked. This property must be true for user-centric campaigns that have the Okta Admin Console as one of the resources. |
True/False | FALSE |
|
Reassignment Enabled |
If true, reassignment is enabled for reviewers. |
True/False | FALSE |
|
Bulk Decision Enabled |
If true, bulk actions are enabled for approving or revoking review items. |
True/False | FALSE |
|
Notify Reviewer |
|||
|
Period End |
If true, a notification is sent to the reviewer when a given reviewer level period is about to end. This property is only applicable for multi-level campaigns. |
True/False | FALSE |
|
During Midpoint Of Review |
If true, a notification is sent to the reviewer during the midpoint of the review process. |
True/False | FALSE |
|
When Overdue |
If true, a notification is sent to the reviewer when reviews are overdue. |
True/False | FALSE |
|
When Review Assigned |
If true, a notification is sent to the reviewer when actionable reviews are assigned. |
True/False | FALSE |
|
At Campaign End |
If true, a notification is sent to the reviewers when the campaign ends. |
True/False | FALSE |
|
Closing Reminders In Seconds |
Specifies, in seconds, the time a reminder is sent to reviewers before the campaign closes. You can send up to three notifications. For example, the array [86400, 172800, 604800] sends reminder notifications at 7 days, 2 days, and 1 day before the campaign closes. By default, reminders are sent 2 days and 1 day before the campaign closes. |
List of Numbers | FALSE |
|
Remediation Settings |
|||
|
Remove Access |
If true, the user has their access revoked as long as they aren't assigned to a group. |
True/False | TRUE |
|
Remove Access on No Response |
If true, the user's access is revoked when the campaign ends as long as they aren't assigned to a group. |
True/False | TRUE |
Output
| Field | Definition | Type |
|---|---|---|
|
Campaign |
||
|
ID |
The unique identifier of the user campaign created. |
Text |
|
Name |
The name of the user campaign created. |
Text |
|
Description |
A description of the user campaign created. |
Text |
|
Created |
The date and time when the user campaign was created. |
Date & Time |
|
Created By |
The unique identifier of the Okta user who created the user campaign. |
Text |
|
Last Updated |
The date and time when the user campaign was last updated. |
Date & Time |
|
Last Updated By |
The unique identifier of the Okta user who last updated the user campaign. |
Text |
|
Status |
The status of the resource campaign created.
|
Text |
|
Raw Output |
The raw object response for the resource campaign created. |
Object |
