Prerequisites
- An Okta tenant with Okta Identity Governance and Access Requests enabled
- The Okta integration connected with either setup method
- Okta applications and groups already synced into Ravenna. Ravenna maps catalog entries to them, so entries for unsynced apps or groups are skipped until they sync.
Required scopes and role
OIG sync needs three scopes beyond the standard set, plus the Access Requests Administrator admin role on the app.- Client Secret: the Ravenna app from the Okta OIN marketplace sets up the scopes and the role for you, so there’s nothing to configure.
- Private Key: grant the scopes on your Okta API service app alongside the standard scopes, then assign the role. In Okta, open the app under Applications > Applications, grant the scopes on the Okta API Scopes tab, and assign the role on the Admin Roles tab. The role also includes app assignment management.
All three are required. Ravenna requests them together for every OIG call, so a missing scope blocks the sync and requests alike.
OIG uses the v2 Access Requests API, which rejects the older
okta.governance.accessRequests.* scope names. Grant the okta.accessRequests.* scopes listed above.Turn on OIG sync
1
Grant the scopes and role
With Private Key, grant the three
okta.accessRequests.* scopes and assign the Access Requests Administrator role to your Okta API service app. With Client Secret, skip this step.2
Enable the setting
Go to Settings > Integrations, open the ⋯ menu on the Okta integration, and choose Configure. Turn on Sync OIG requestable access as access levels.
3
Run a sync
Choose Resync from the same ⋯ menu, or wait for the next scheduled sync (every 6 hours by default). If Ravenna can’t read the OIG catalog, the integration status turns yellow and its tooltip shows a Missing Okta Identity Governance access warning.
How the sync works
On each Okta sync, after groups sync, Ravenna reads the OIG catalog and turns every requestable entry into an access level. If the group sync fails, Ravenna skips the catalog for that run.- Application entries: an entry under an Okta application becomes an access level on the matching Ravenna application.
- Group entries: an entry tied to an Okta group becomes an access level on each Ravenna application that group grants. Ravenna also maps the access level to that group. Entries for groups that grant no application are skipped.
Turning the setting off stops the catalog sync, but access levels it already created stay active. Requests for them are still filed in OIG.
Learn more about external access levels
How requests work
1
The user requests access in Ravenna
The user picks an external access level, and the request goes through the level’s access policy.
2
Ravenna files the request in OIG
After the request is approved in Ravenna, Ravenna files an OIG access request for the requester against the matching catalog entry.
3
OIG approves and provisions
OIG runs its own approval and provisioning. Ravenna marks the entitlement Skipped Provisioning with the reason “Filed with OIG; approval and provisioning are owned by the external system”, and tells the requester their request was forwarded. For group-based levels, the new group membership appears in Ravenna on the next Okta sync.
Ravenna files each request as a self-request for the requester. If provisioning retries, Ravenna reuses the request it already filed instead of filing a new one.
Troubleshooting
Missing Okta Identity Governance access warning
Missing Okta Identity Governance access warning
Cause: Ravenna’s connection check couldn’t read the OIG catalog. Usually a scope or the role is missing on the app.Solution:
- With Private Key, grant
okta.accessRequests.catalog.read,okta.accessRequests.request.read, andokta.accessRequests.request.manageon the app, and assign the Access Requests Administrator role - With Client Secret, confirm OIG and Access Requests are enabled in your Okta tenant. The app includes the scopes and role, so contact Ravenna support if the warning persists.
- Choose Resync from the ⋯ menu on the Okta integration
okta.accessRequests.request.manage and the role.A catalog entry has no access level in Ravenna
A catalog entry has no access level in Ravenna
Cause: Ravenna couldn’t match the entry to a synced application or group, or the entry isn’t requestable.Solution:
- Confirm the entry is requestable in OIG
- Confirm the Okta application or group behind it has synced into Ravenna
- For group entries, confirm the group grants at least one application
- Run another sync after the application or group appears in Ravenna
A request shows Failed Provisioning
A request shows Failed Provisioning
Cause: Ravenna couldn’t file the request in OIG. Most often the requester has no Okta user linked in Ravenna, or the app is missing
okta.accessRequests.request.manage.Solution:- Confirm the requester has an Okta user and that it has synced into Ravenna
- With Private Key, confirm the app has all three
okta.accessRequests.*scopes and the Access Requests Administrator role - Submit the request again once both are in place
A request is approved in Ravenna but the user has no access
A request is approved in Ravenna but the user has no access
Cause: Ravenna filed the request, and OIG still owns approval and provisioning. Ravenna doesn’t reflect OIG approvals, denials, or expirations.Solution:
- Find the request in OIG Access Requests and check its status
- For group-based levels, run a sync after OIG grants access so the membership shows in Ravenna