Skip to content
English
  • There are no suggestions because the search field is empty.

How to Enable Automatic Group and Role Sync for Okta SSO Provisioning

Automatic group and role sync for Okta SSO Provisioning

When SSO Provisioning is enabled, you can have Okta automatically place users in the right Consensus Group and assign the right Role based on their Okta group membership. Once configured, adding a new user in Okta with the appropriate groups creates a fully-configured Consensus user with no manual work.

Where to find these settings

Settings → Integrations → SSO → SSO Provisioning → Group and Role Sync section.

Group and Role Sync settings.

Configure group sync

  • Toggle "Sync Groups from Okta" ON.
  • Map each Okta group to a Consensus Group. The mapping is one-to-one — a single Okta group can't represent multiple Consensus Groups.
  • Decide what happens for unmapped Okta groups: ignore (default), or assign users to a Default Group if no specific mapping matches.

Configure role sync

  • Toggle "Sync Roles from Okta" ON.
  • Map each Okta group to a Consensus Role.
  • Decide a Default Role for users whose Okta groups don't match any role mapping.

How sync runs

Sync runs whenever Okta pushes a user update to Consensus — on user creation, on group membership change, and on Okta-side deactivation. There's no scheduled bulk sync; updates are event-driven.

When to use manual instead

If your Okta group structure doesn't cleanly map to Consensus Groups / Roles, or if you need finer-grained control, see "Manual Groups management for SSO Provisioning" and "Manual Roles Management for Okta SSO Provisioning."