06 - Configure Groups Flashcards

1
Q

Demo 5:

Demonstrate knowledge of the various methods for activating and deactivating users

A

Reprovisioning a Deactivated Active Directory Account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Demo 5A:

Demonstrate knowledge of the various methods for activating and deactivating users

A

Activate and Deactivate Users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Demo 5B:

Demonstrate knowledge of the various methods for activating and deactivating users

A

Okta Essentials Module 2: Define Your Users in Okta

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Demo 5C:

Demonstrate knowledge of the various methods for activating and deactivating users

A

Okta Technical Consultant Boot Camp: Defining Users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the 3 types of groups:

A

a. Okta
b. Directory
c. Application

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q
  1. What is the difference between Oka group and the other 2 groups:
A

a. Okta group are created and memberships is managed in Okta

b. The members of Okta groups can be Okta, Directory, or Application-mastered users.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the difference between Directory group and the other 2 groups:

A

a. Directory group are created and membership is managed in the external directory service.
b. Only directory-mastered users can be members of directory groups; this is established in the external directory service.
c. Directory groups are copied into Okta
d. If the external directory instance is deactivated or deleted, the associated groups no longer appear in Okta.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the difference between Application group and the other 2 groups:

A

a. Application groups are created and membership is managed in the application.
b. Members of application groups are pulled into Okta during application creation.
c. Application groups are copied into Okta.
d. If the application connector is deactivate or deleted, the group no longer appears in Okta.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Can you have a duplicate group name from different directories?’

A

a. Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Can you have duplicate group names on the same directory?

A

a. No, For example, you can have an Okta Sales group and an Active Directory Sales group, but you cannot have two Okta Sales groups. Notice that groups can have the same name but a different source. What makes the group unique is the source plus the group name.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Can you delete or modify groups in Okta?

A

a. No, Directory groups are completely managed on the directory service. You cannot delete or modify the group within Okta.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What should you do if you need to delete a group in AD?

A

a. If a group is to be deleted, perform the deletion in Active Directory and run a full import to have the agent push the update to Okta.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Do all Applications support groups?

A

a. No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the best practice for working with diverse groups of okta and AD groups.

A

a. For example, if your contractor Sales team is not part of your Active Directory domain, but they require access through Okta to Salesforce, you can create Okta-mastered users and groups for the contractor Sales people.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What does Group allow administrators to do?

A

i. Divide the user base into smaller segments and refine application access and security policies.
ii. People and applications can be members of a group.
iii. People are automatically assigned any applications that are members of a group.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the 3 types of groups?

A

i. Okta groups
ii. Directory Groups
iii. Application groups

17
Q

What is entailed in Okta group?

A

i. OG is created and membership is managed in Okta

ii. The members of OG can be Okta, directory or App-mastered users.

18
Q

What is entailed in Directory Group (DG)

A

i. DG are created and membrerships is managed in the external services
ii. Only DMU can be members of DG. This is established in the external Directory Service.
iii. DG is copied into Okta
iv. If the external directory instance is deactivated or deleted, the associated group no longer appear in Okta.

19
Q

What is entailed in application group (AG)

A

i. AG are created and membership is managed in the app.
ii. Members of AG are pulled into Okta during app creation.
iii. AG are copied into Okta
iv. If app connectors is deactivated or deleted, the group no longer appears in Okta.

20
Q

Is creating groups mandatory?

A

i. No, but you can use groups to segments users in similar job roles or functions

21
Q

Can you associated any user with an Okta Group?

A

i. Yes– but only DMU can be associated with group defined on the same directory server and application-mastered users can only be associated w groups defined in the application.

22
Q

How are directory groups created?

A

Directory groups are created on the directory instance and copied into Okta. All directory group changes must be performed on the directory server and pulled into Okta.

23
Q

Okta directory agents are able to copy the directory group information because of

A

i. The permissions granted to the Okta service account.

24
Q

What happens when you delete or deactivate a directory instance?

A

If you deactivate or delete a directory instance, these groups no longer appear and the associations to applications are removed.

25
Q

How are application groups created?

A

a. Application groups are created in the application and copied into Okta, after you have enabled provisioning.

26
Q
  1. True/FalseAll application group changes must be performed in the application and pulled into Okta.
A

i. True

27
Q

True/False. While you can have duplicate group names from different directories, you cannot have duplicate group names on the same directory.

A

i. True. For example, you can have an Okta Sales group and an Active Directory Sales group, but you cannot have two Okta Sales groups. Notice that groups can have the same name but a different source. What makes the group unique is the source plus the group name.

28
Q

True/False. Okta groups are identified by the Okta icon – you name the groups and (optionally) provide a description.

A

i. Yes, By default, Okta has an Everyone group which contains all Okta, directory, and application users; regardless of status. Okta groups can be helpful when associating applications with people performing similar roles. For example, you can place all Okta-mastered administrator accounts into a distinct group.

29
Q

What’s the process to creating a group rule to opt someone in or out of an application.

A

a. Directory > Group
b. See both Okta groups and AD Groups
c. Create “Sales Staff”
d. Create “Marketing Staff”
e. Add people to groups
f. Assoicate apps to this group
g. “Manage Group”
h. Manually add people to groups.
i. Manage my app so I can decide everybody in sales needs access to a certain application therefore assign the app.

30
Q

How to automate so add people to groups and apps.

A

a. Groups ==> Rules
b. “Add Rule”
c. User attribute or Group membership
d. Expression Builder > Department = Sales assign to “Sales Staff”
e. Activate the rule
f. Anyone in the org qualifies, then they are automatically assigned to this group.
g. Go back and select “Jack” and edit his department to “Sales Staff” so he can qualify (for this example).

31
Q

Oliver has deleted the AD sales group in AD because he is now using rules in Okta to populate the Okta Sales group. When Oli is reviewing the group, he notices that the AD Sales Group is still appearing in Okta. Why is it still appearing in Okta?

A

a. An import an AD was not processed to reflect this change.