29% of the exam — the second-largest domain.
6 sub-topics · this deck covers sub-topic 3 of 6
↑ Module 1 OverviewData doesn't only need to flow into Okta. Sometimes Okta itself becomes the source of truth for something — and other systems need to catch up to what Okta already knows.
Group Push is the write-back tool for groups: it pushes existing Okta groups and their memberships out to provisioning-enabled third-party apps.
The value is directional: instead of maintaining group membership separately in Okta and in every downstream app, Okta becomes the one place group membership is managed — and it propagates outward from there.
This sub-topic is deliberately kept at the "why it matters" level — the full mechanics of how Group Push actually works (push-by-name vs. push-by-rule, reconciliation behavior, Group Linking) get their own deep-dive later, in Module 2: Provisioning.
Watch for scenario questions built around this framing:
→ "Okta manages group membership, but a third-party app's own groups keep drifting out of sync." = the value case for Group Push — write back instead of maintaining membership twice.
Sources: help.okta.com — usgp-group-push-main.htm
Next: Sub 4 →