← Course Home
Okta Certified Administrator · Part I

User Lifecycle Management

29% of the exam — the second-largest domain.

User Lifecycle Management

Module 1: Profile Sourcing & Write-Back Concepts

6 sub-topics · this deck covers sub-topic 1 of 6

↑ Module 1 Overview

The Exam Bullet

"Demonstrate knowledge of HR as a source including the benefits of groups and group rules when using an external source"

When an HR system like Workday becomes the source of truth for user data, group membership shouldn't need a human to keep updating it by hand. This sub-topic is about the automation that makes that possible: group rules.

The Mechanism

Group rules automatically populate groups based on user attributes. They simplify group administration and are used to manage application access, application roles, and security policies — without an admin manually adding or removing anyone.

Rules work both directions: when a user's attributes match the rule's conditions, they're added to the group; when their attributes stop matching, they're automatically removed. No manual cleanup required.

The Real Example — Workday + AD Groups

This is the textbook use case for HR-sourced group rules: use the cost center attribute from Workday to determine AD group memberships.

As an employee's cost center changes in Workday (a transfer, a reorg), their AD group membership updates automatically through Okta — no ticket, no manual re-assignment.

The Gotcha — Limits

Maximum 2,000 group rules per org. Only Super Admins and Org Admins can edit rules.

Both are easy exam traps: assuming any admin role can edit rules, or assuming rule count is unlimited.

The Exam Angle

Watch for scenario questions built around this trap:

→ "A help desk admin needs to edit a group rule and can't." = expected — only Super/Org Admins can edit rules.

One Line To Remember

Group rules auto-add and auto-remove group members based on attribute matches — no manual maintenance. Classic use case: Workday cost center → AD group membership. Limits: 2,000 rules per org, editable only by Super/Org Admins.

Sources: help.okta.com — usgp-user-profiles-main.htm · usgp-about-group-rules.htm