<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Key Differences Between Universal Sync and Other Okta Office 365 Provisioning Types

Okta Integration Network

Overview

The Okta Office 365 integration offers multiple provisioning types, including Universal Sync, which calculate the StsRefreshTokensValidFrom attribute differently. This attribute invalidates existing login sessions and refreshes tokens when a user changes their password. The selected provisioning type determines how Okta populates this attribute and impacts compatibility with other Active Directory synchronization tools.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Office 365
  • Provisioning
  • Universal Sync

Solution

    How does the provisioning type affect the StsRefreshTokensValidFrom attribute?

    Okta provisions each user for Office 365 with an attribute, StsRefreshTokensValidFrom, which acts as a date that invalidates existing login sessions and refreshes tokens when the user changes their password, requiring the user to authenticate into the applications again. Okta automatically calculates and populates this attribute based on the Provisioning Type.

     

    Determine how Okta populates the StsRefreshTokensValidFrom attribute based on the selected provisioning type by reviewing the following conditions.

    • License Only or Profile Sync: Okta sets the StsRefreshTokensValidFrom attribute to the current date and time when the user changes their password in Okta.
    • User Sync or Universal Sync: If Active Directory (AD) links to the user, Okta sets the StsRefreshTokensValidFrom attribute to the pwdLastSet attribute in AD. For all other users, Okta sets the StsRefreshTokensValidFrom attribute to the current date and time when the user changes their password in Okta.

     

    What are the limitations and behaviors of User Sync and Universal Sync?

     

    When selecting the User Sync or Universal Sync provisioning type, all users appear as Synced with AD in the Office 365 tenant, irrespective of the profile source. However, the source directory still acts as the source for the user.

    Understand the limitations and behaviors of the User Sync and Universal Sync provisioning types by reviewing the following requirements and restrictions.

    • User Sync and Universal Sync do not support integration with Directory Synchronization, Azure Active Directory (AAD) Sync, or Azure Active Directory Connect.
    • Universal Sync does not support Just-In-Time (JIT) enabled AD instances.
    • After configuring Universal Sync, Azure AD no longer accepts direct user updates. Updates must occur at the source of truth and synchronize across the integration. In this scenario, the configuration requires selecting the On-Premises AD domain during the Universal Sync provisioning setup.
    • Environments utilizing or planning to utilize Hybrid AAD Domain Joined devices or access do not support User Sync or Universal Sync.


    Related References

    Loading
    Okta Support - Key Differences Between Universal Sync and Other Okta Office 365 Provisioning Types