<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>roles &#8211; JMartinez.tech</title>
	<atom:link href="https://jmartinez.tech/tag/roles/feed/" rel="self" type="application/rss+xml" />
	<link>https://jmartinez.tech</link>
	<description>Tech stuff, but chill.</description>
	<lastBuildDate>Thu, 12 Jun 2025 17:50:10 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://jmartinez.tech/wp-content/uploads/2025/04/T027K0ZC9-U03JL4E79KM-bbe3a34946fe-512-150x150.png</url>
	<title>roles &#8211; JMartinez.tech</title>
	<link>https://jmartinez.tech</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Before You Use Okta, Do This: An Essential Guide for Admins</title>
		<link>https://jmartinez.tech/before-you-use-okta-do-this-an-essential-guide-for-admins/</link>
					<comments>https://jmartinez.tech/before-you-use-okta-do-this-an-essential-guide-for-admins/#comments</comments>
		
		<dc:creator><![CDATA[Jordi Martinez-Hidalgo]]></dc:creator>
		<pubDate>Thu, 12 Jun 2025 17:50:10 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Access]]></category>
		<category><![CDATA[amateur]]></category>
		<category><![CDATA[groups]]></category>
		<category><![CDATA[guide]]></category>
		<category><![CDATA[okta]]></category>
		<category><![CDATA[policies]]></category>
		<category><![CDATA[profile]]></category>
		<category><![CDATA[roles]]></category>
		<category><![CDATA[source]]></category>
		<category><![CDATA[SSO]]></category>
		<category><![CDATA[steps]]></category>
		<guid isPermaLink="false">https://jmartinez.tech/?p=337</guid>

					<description><![CDATA[You&#8217;ve just acquired Okta and have no idea where to start. You&#8217;re ready to roll up your sleeves and start integrating applications, but wait! Your tenant is empty. If you don’t lay down solid foundations, you might regret it later. Here’s what I would do if I had to start ... <div><a class="more-link bs-book_btn" href="https://jmartinez.tech/before-you-use-okta-do-this-an-essential-guide-for-admins/">Read More</a></div>]]></description>
										<content:encoded><![CDATA[
<div class="posts-view">



<p style="font-size:16px">You&#8217;ve just acquired Okta and have no idea where to start.</p>



<p style="font-size:16px">You&#8217;re ready to roll up your sleeves and start integrating applications, but wait! Your tenant is empty. If you don’t lay down solid foundations, you might regret it later.</p>



<p style="font-size:16px">Here’s what I would do if I had to start from scratch today:</p>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>



<p style="font-size:24px"><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f9d1-200d-1f9d1-200d-1f9d2-200d-1f9d2.png" alt="🧑‍🧑‍🧒‍🧒" class="wp-smiley" style="height: 1em; max-height: 1em;" /><strong>Make Sure You Have a Profile Source</strong></strong></p>



<p style="font-size:16px">Okta is a powerful tool, but it’s useless without users.</p>



<p style="font-size:16px">There are many ways to create users in Okta, but in my opinion, the most powerful one is connecting a <strong>Profile Source</strong>.</p>



<p style="font-size:16px">There are tons of available options: <strong>Workday</strong>, <strong>BambooHR</strong>, <strong>Active Directory</strong>, <strong>LDAP</strong>, <strong>UKG</strong>, and more.</p>



<p style="font-size:16px">Connecting a source of truth from your HR systems allows you to sync valuable information automatically. This data can be leveraged later for workflows, group assignments, and more.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p style="font-size:16px"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f9e0.png" alt="🧠" class="wp-smiley" style="height: 1em; max-height: 1em;" /><strong>Tip for smaller companies</strong>: You can also use <em>Okta Direct Input</em>. While it’s not ideal and I wouldn’t recommend it, it can work if you don’t have other options — but treat it as a last resort.</p>
</blockquote>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>



<p style="font-size:24px"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4cd.png" alt="📍" class="wp-smiley" style="height: 1em; max-height: 1em;" /><strong><strong><strong>Map Every Attribute You Can</strong></strong></strong></p>



<p style="font-size:16px">Once your source is connected, it’s time to take full advantage of the incoming data.</p>



<p style="font-size:16px">Map <strong>every attribute you can</strong>, even if some seem irrelevant now. Trust me, you never know when you’ll need them.</p>



<p style="font-size:16px">Start with the essentials:</p>



<ul class="wp-block-list">
<li style="font-size:16px"><code>team</code></li>



<li style="font-size:16px"><code>department</code></li>



<li style="font-size:16px"><code>location</code></li>



<li style="font-size:16px"><code>division</code></li>



<li style="font-size:16px"><code>manager</code></li>



<li style="font-size:16px"><code>office</code></li>
</ul>



<p style="font-size:16px">The more metadata you collect, the more powerful your automations and policies will be.</p>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>



<p style="font-size:24px"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f3d8.png" alt="🏘" class="wp-smiley" style="height: 1em; max-height: 1em;" /><strong><strong><strong>Create Dynamic Groups</strong></strong></strong></p>



<p style="font-size:16px">Now that you have user data, it’s time to put it to use.</p>



<p style="font-size:16px"><strong>Dynamic groups</strong> let you assign users automatically based on attribute-based rules. For example:</p>



<ul class="wp-block-list">
<li style="font-size:16px"><code>HR Department</code></li>



<li style="font-size:16px"><code>Finance Team</code></li>



<li style="font-size:16px"><code>Barcelona Office</code></li>



<li style="font-size:16px"><code>US Employees</code></li>



<li style="font-size:16px"><code>IT Support</code></li>
</ul>



<p style="font-size:16px">You don’t need to manually manage membership. Any changes in your source of truth will be reflected in Okta, and users will move in and out of groups automatically based on the defined logic.</p>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>



<p style="font-size:24px"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f46e-1f3fb.png" alt="👮🏻" class="wp-smiley" style="height: 1em; max-height: 1em;" /><strong>Define Access Roles</strong></p>



<p style="font-size:16px">You won’t be the only one managing Okta.</p>



<p style="font-size:16px">Set up access roles based on each person’s responsibilities:</p>



<ul class="wp-block-list">
<li style="font-size:16px"><strong>Read-only Admin</strong></li>



<li style="font-size:16px"><strong>Group Membership Admin</strong></li>



<li style="font-size:16px"><strong>Application Admin</strong></li>



<li style="font-size:16px"><strong>Super Admin</strong> (only if absolutely necessary)</li>
</ul>



<p style="font-size:16px">This step takes a bit of time, but it&#8217;s worth it. Delegating access properly reduces risk and improves operational efficiency.</p>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>



<p style="font-size:24px"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6aa.png" alt="🚪" class="wp-smiley" style="height: 1em; max-height: 1em;" /><strong>Define Authentication Policies</strong></p>



<p style="font-size:16px">Security should always be a top priority.</p>



<p style="font-size:16px">Set up <strong>authentication policies</strong> tailored to your applications. Not all apps are created equal, accessing <strong>Salesforce</strong> is not the same as accessing <strong>Udemy</strong>.</p>



<p style="font-size:16px">I recommend:</p>



<ul class="wp-block-list">
<li style="font-size:16px">Enforcing <strong>2FA</strong></li>



<li style="font-size:16px">Applying <strong>IP restrictions</strong></li>



<li style="font-size:16px">Restricting access by <strong>device</strong> (if capable)</li>
</ul>



<p style="font-size:16px">Be <strong>strict</strong>, especially with critical systems. Better safe than sorry.</p>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>



<p style="font-size:24px"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4d7.png" alt="📗" class="wp-smiley" style="height: 1em; max-height: 1em;" /><strong>In Summary</strong></p>



<p style="font-size:16px">These five steps will help you build a strong, reliable tenant, ready for growth, app integration, and secure daily operations.</p>



<p style="font-size:16px">As for app integration… we’ll save that for another post. <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>



</div>



<p></p>
]]></content:encoded>
					
					<wfw:commentRss>https://jmartinez.tech/before-you-use-okta-do-this-an-essential-guide-for-admins/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
	</channel>
</rss>
