Role of Okta

Okta is the identity provider and assignment source for SAML access and SCIM lifecycle events.

Authority model

Okta owns human identity intent; FreeIPA / LDAP owns Linux directory enforcement; FreeSCIM owns mapping, guardrails, audit evidence, and recoverability.

Supported operations

Authentication model

SAML protects operator access. SCIM endpoints should use scoped integration tokens with rotation, revocation, and redacted event logging.

Rollout guidance

  1. Validate metadata, ACS URL, certificate fingerprint, and group claims.
  2. Run read-only or dry-run reconciliation.
  3. Enable low-risk assignment groups first.
  4. Add approval gates for privileged groups and deprovisioning.

Known limits

Do not claim Okta owns downstream Linux enforcement. FreeIPA, SSSD, Kerberos, HBAC, and sudo policy remain separate operational boundaries.