(Optional) Add an objectGUID Attribute and Create the User Profile Mapping
If you need to import the objectGUID
attribute for users, add a new attribute and map the attributes in the profile mapping.
Note: Before setting up the import of the objectGUID
, review and meet the prerequisites. For more information, see Prerequisites.
The on-premises Secure Access AD Connector and the Cisco Secure Client rely on the objectGUID
attribute for user and group identification. Ensure that the objectGUID
attribute of users is synchronized from Okta to Secure Access only if either of the following conditions are true:
- You have previously imported AD users to Secure Access using the on-premises Secure Access AD connector, are now importing the same user identities from Okta, and want the previously imported identities to be persisted for policy or reporting purposes.
- You have endpoints that authenticate against on-premises AD and run the Cisco Secure Client.
Note: The Okta Active Directory agent does not synchronize the objectGUID
attribute of users from on-premises AD to Okta by default.