2 ms·
Syncing passwords is a bad idea and is really a legacy case for applications that don't support SSO. The correct way to do provisioning + auth is to use SCIM ju
by monster_group 4y ago
Syncing passwords is a bad idea and is really a legacy case for applications that don't support SSO. The correct way to do provisioning + auth is to use SCIM just for provisioning users and groups (with password based auth disabled in the downstream app) and use SSO (SAML / OIDC) from Okta to actually do the auth for the user. Also configure your SCIM API to never taken in the password if Okta sends it and never return it in case some user decides to set the password on the downstream app anyway.