29% of the exam — the second-largest domain.
4 sub-topics · this deck covers sub-topic 1 of 4
↑ Module 2 OverviewThis bullet names 5 methods — but you've already learned 3 of them in depth elsewhere in this course. This deck is a map back to each one, not a re-lecture.
APIs — direct, programmatic account management against Okta's own API surface.
SCIM — Okta's standard provisioning protocol, covered in Module 1 Sub 5: configure which attributes sync, then profiles update automatically.
SAML JIT — a brand-new user's Okta profile gets created the moment delegated auth succeeds against AD, no import needed.
↳ Full deck: IAM Module 1, Sub 1 (Delegated Authentication)Password sync — the reverse of delegated auth: Okta pushes ITS password to AD, making Okta the source of truth.
↳ Full deck: IAM Module 4, Sub 2 (Agent High Availability)Org2Org — connects a source (spoke) Okta org to a target (hub) org for shared authentication and provisioning.
↳ Full deck: IAM Module 2, Sub 4 (Org2Org Use Cases)This bullet tests recognition more than depth — given a scenario, can you name which of the 5 methods fits?
→ "A new AD user logs in for the first time and their Okta profile appears immediately." = SAML JIT, not SCIM.
→ "Okta needs to be the password source of truth, pushing changes to AD." = password sync, not delegated auth.
Sources: help.okta.com — org2org-integrate.htm · Provisioning_Deprovisioning_Overview.htm (cross-referencing prior modules for JIT/password sync/Org2Org)
Next: Sub 2 →