Okta LDAP Configuration

Workspace ONE can integrate with Okta LDAP, VMware have a KB for it ( https://kb.vmware.com/s/article/2961230 ) however it is outdated this article detail the Workspace ONE configuration required for it to work.

To configure the Okta side follow Okta documentation available here : https://help.okta.com/oie/en-us/Content/Topics/Directory/LDAP-interface-main.htm

These parameters are in All Settings > System > Enterprise Integration > Directory Services

You need to change the value in red to match your tenant configuration.

LDAP

Directory TypeLDAP – Other LDAP
Server oktatenant.ldap.okta.com
Encryption TypeSSL
Port636
Protocol Version3
Use Service Account CredentialsDisabled
Bind Authentication TypeBasic
Bind Usernameuid=username,ou=users,dc=oktatenant,dc=okta,dc=com
DomainOkta
Serveroktatenant.ldap.okta.com

Advanced

Search SubdomainsDisabled
Connection Timeout30
Request Timeout300
Search Without Base DNDisabled
Use Recursive OID At EnrollmentDisabled
Use Recursive OID For Group SyncDisabled
Object Identifier Data TypeString
Sort ControlDisabled

User

DomainBase DN
Oktadc=oktatenant,dc=okta,dc=com
User Object ClassinetOrgPerson
User Search Filter(&(objectClass=inetOrgPerson)(uid={EnrollmentUser}))

Advanced

Auto MergeEnabled
Automatically Sync Enabled Or Disabled User StatusEnabled
Value For Disabled StatusDEPROVISIONED / Value Exact Match
AttributeMapping Value
Object IdentifieruniqueIdentifier
Usernameuid
Member OfmemberOf
Full Namecn
Display Namecn
First NamegivenName
Middle NamemiddleName
Last Namesn
Email addressmail
Email UsernameEmpty
Mobile PhoneEmpty
Phone NumberEmpty
Distinguished NameentryDN
User Principal Namemail
DepartmentEmpty
StatusorganizationalStatus
Lockout TimeEmpty
Object ClassobjectClass
Last ModifiedmodifyTimestamp
Binding AttributeEmpty
Employee IDemployeeID
Cost CenterEmpty
Manager Distinguished NameEmpty

Groups

DomainBase DN
Oktadc=OKTATeantName,dc=okta,dc=com
Group Object ClassgroupofUniqueNames
Organizational Unit Object ClassorganizationalUnit

Advanced

Group Search Filter(&(objectClass=groupofUniqueNames))
Membership AttributeUser Attribute(“Member of”)
Auto Sync DefaultEnabled
Auto Merge DefaultEnabled
Maximum Allowable Changes10
Auto-Update Friendly NameEnabled
AttributeMapping Value
Object Identifieruniqueldentifier
Namecn
MemberuniqueMember
Common Namecn
Member OfEmpty
Distinguished NamedistinguishedName
Group Object ClassobjectCIass
Organizational Unitou
Organizational Unit Object ClassobjectClass
Written by
Website | + posts

vExpert, blogger and VMware champion. Worked as a Microsoft consultant for a partner before joining VMware via Airwatch in 2015.

Leave a Reply

Your email address will not be published. Required fields are marked *.

*
*
You may use these <abbr title="HyperText Markup Language">HTML</abbr> tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>

This site uses Akismet to reduce spam. Learn how your comment data is processed.

BCF Shop Theme By aThemeArt.
BACK TO TOP