App launcher integration with Okta
Using OOTB integration with Okta, you can automatically sync the registered applications from Okta and give your employees one–click access to a personalized list of assigned applications. Your employees can easily access all the active apps with valid entitlement in Okta without specifying the login credentials.
Before you begin
- The app launcher sync of applications from Okta is only compatible with the latest Okta Spoke version. Ensure you upgrade the existing Okta spoke to sync the apps on to your web applications.
- Integrate Okta spoke with ServiceNow, Inc., create credential records, and create connection records as explained in Okta spoke setup
Role required: sp_admin, taxonomy admin, or taxonomy manager
About this task
After the spoke setup, Okta applications are synced on daily basis to a web application table from the Okta account. To sync the latest applications, you can do the following:
- As sn_hr_sp.esc_admin, navigate to to sync the updates instantly.
When you update applications, you can track the flow execution status from the related link on the page.
- As an admin, sync the updates automatically on need-basis or once everyday by running the Fetch applications schedule job from .
Procedure
Result
What to do next
For upgrades: When you have an existing Okta spoke and connection and if upgrade to the employee center pro with the App launcher feature, the apps get synced through a job automatically and are updated nightly. To disable the fetch applications job,
you must mark the job to the inactive state from .
Scheduled Job: Fetch applications
table: sysauto_script
sys_id: 48b46a8a4744c1109dcae052846d43cfBased on the user permissions and the applications mapped with the Okta, the applications are displayed on the App launcher.
- When user access permissions change on the Okta side, the updates are synced real-time on the applications widget. To see the changes, re-login to your Employee Center account.
- Changes to the app metadata such as Deletion, status change, or selecting Do not display application icon to users reflect only after the next sync. After sync, the apps are marked inactive and hidden from users.
Note:
When an application is hidden, users still have permissions to the application until the next sync.