Manual Groups management for SSO Provisioning
Manage Groups manually when SSO Provisioning is on
If automatic Group sync from Okta doesn't fit your structure, SSO Provisioning still works — Okta creates and deactivates the user record, but you manage Group placement in Consensus directly. This article covers that pattern.
When to use manual Groups
- Your Okta groups don't map cleanly to Consensus Groups.
- You want approval before users land in a specific Group.
- Group structure differs between regions or teams in ways Okta doesn't represent.
How it works
With group sync disabled, every new SSO-provisioned user lands in your account's Default Group (or unassigned, depending on configuration). An admin then moves them into the correct Group via Manage Users.
Configure
- Settings → Integrations → SSO → SSO Provisioning → toggle "Sync Groups from Okta" OFF.
- Optionally set a Default Group for new SSO-provisioned users.
- Save.

SSO Provisioning page — Group sync toggle.
Assigning users to Groups
When a new user appears (created by Okta), open Settings → Manage Users & Access → Users tab, find the user, and move them into the right Group via their Edit User page or the inline Group dropdown. See "How to filter your Manage Users Page for Easy Management" for tips on bulk operations.