Provisioning action for the IdP user's group memberships | Enum | Description | Existing OKTA_GROUP Memberships | Existing APP_GROUP Memberships | Existing BUILT_IN Memberships | | - -- -- -- - | - -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- | - -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- | - -- -- -- -- -- -- -- -- -- -- -- -- -- -- - | - -- -- -- -- -- -- -- -- -- -- -- -- -- -- | | APPEND | Adds a user to any group defined by the IdP as a value of the sourceAttributeName array that matches the name of the allow listed group defined in the filter | Unchanged | Unchanged | Unchanged | | ASSIGN | Assigns a user to groups defined in the assignments array | Unchanged | Unchanged | Unchanged | | NONE | Skips processing of group memberships | Unchanged | Unchanged | Unchanged | | SYNC | Group memberships are sourced by the IdP as a value of the sourceAttributeName array that matches the name of the group defined in the filter | Removed if not defined by the IdP in sourceAttributeName and matching name of the group in filter | Unchanged | Unchanged | > Note: Group provisioning action is processed independently from profile sourcing. You can sync group memberships through SAML with profile sourcing disabled.
| Name | Type | Description | Notes |
|---|