> For the complete documentation index, see [llms.txt](https://docs.lithnet.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lithnet.io/okta-ma/configuration/creating-the-management-agent.md).

# Creating the management agent

Create the Okta management agent in MIM and work through its configuration pages.

Complete the guide for your [authentication method](/okta-ma/authentication/choosing-an-authentication-method.md) first. Before you start, you should have your Okta org URL, and either an API token or a client ID and the key details.

## Step 1: Create the management agent

1. Open MIM Synchronization Service Manager.
2. Select **Management Agents**, then **Create**.
3. Select **Okta (Lithnet)**.
4. Enter a name and description.

![Creating an Okta management agent in Synchronization Service Manager.](https://2206708376-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0u5rDWCokdBire3bUPyS%2Fuploads%2Fgit-blob-5987e31c9f43b207e5b7cae34f0f6ef7b560af2a%2Fmim-create-management-agent.png?alt=media)

If the management agent type is not listed, close and reopen Synchronization Service Manager. If it is still missing, restart the MIM Synchronization Service. This is usually because the product was installed or upgraded while the service was running.

## Step 2: Configure connectivity

The fields you need depend on the authentication method:

* [API token](/okta-ma/authentication/api-token.md#step-3-configure-mim)
* [Private JWK](/okta-ma/authentication/oauth-with-a-private-jwk.md#step-3-configure-mim)
* [X.509 certificate](/okta-ma/authentication/oauth-with-an-x509-certificate.md#step-5-configure-mim)

There are two common mistakes on this page. The **Tenant URL** is the Okta org URL, such as `https://example.okta.com`, not the `-admin` hostname or an authorization server path. The log file path must also point somewhere the MIM Synchronization Service account can write to.

See [Connectivity settings](/okta-ma/configuration/connectivity-settings.md) for the full field reference.

## Step 3: Configure global parameters

There are three decisions to make on this page:

* Whether to import `BUILT_IN` and `APP_GROUP` groups. Both are read-only.
* Whether deprovisioning a user deactivates it or permanently deletes it.
* Whether new users are activated on creation, and whether Okta sends them an activation email.

![The Global Parameters page.](https://2206708376-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0u5rDWCokdBire3bUPyS%2Fuploads%2Fgit-blob-17707e3eb3ac8502c0e0ad30f1cd546fd4e63440%2Fmim-global-parameters.png?alt=media)

The deprovisioning choice also changes what a full import returns, so read [Global settings](/okta-ma/configuration/global-settings.md) before you decide.

## Step 4: Select object types

Select `user`, `group`, or both.

With OAuth, only the object types allowed by your granted scopes are shown. If one you expected is missing, grant the matching read or manage scope in Okta and retrieve the schema again.

![Selecting the user and group object types.](https://2206708376-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0u5rDWCokdBire3bUPyS%2Fuploads%2Fgit-blob-a14530e61b189a1336f704e84608b3ef01f9737d%2Fmim-select-object-types.png?alt=media)

## Step 5: Select attributes

`id` is mandatory. Beyond that, select only the attributes that your joins, flows, filters, and reporting actually use.

Attribute directions come from the mutability set on the Okta profile and, with OAuth, from whether the app holds the read or manage scope.

`availableFactors`, `enrolledFactors`, and group `member` each cost an extra API call per object during import. Select them only if you need them. See [Schema and attributes](/okta-ma/configuration/schema-and-attributes.md) for the details.

![Selecting user profile and factor attributes.](https://2206708376-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0u5rDWCokdBire3bUPyS%2Fuploads%2Fgit-blob-a39b985ae253e8490d2de4ba6663519d734acabc%2Fmim-select-user-attributes.png?alt=media)

## Step 6: Configure anchors

`id` is the anchor for both object types. The connector declares it in the schema, so there's nothing to configure here.

The connector also uses the Okta `id` as the distinguished name on import. When MIM provisions a new object it has to supply a DN itself, so use any unique value, such as a GUID. The export returns the Okta `id` as the anchor, and the confirming import replaces the temporary DN with it. Run that confirming import before exporting any further changes to newly provisioned objects.

## Step 7: Configure synchronization rules

Build the connector filters, joins, projections, and attribute flows your solution needs. Two connector-specific rules apply:

* Flow `suspended` to suspend and unsuspend a user. Never flow `status`. It is import-only, and activation and deprovisioning are driven by the global settings instead.
* Never flow anything to `BUILT_IN` or `APP_GROUP` groups. Only `OKTA_GROUP` groups are writable.

The object-specific guides cover the rest:

* [Users](/okta-ma/operations/setting-up-user-management.md)
* [Groups and membership](/okta-ma/operations/setting-up-groups-and-membership.md)
* [Password management](/okta-ma/operations/setting-up-password-management.md)

## Step 8: Configure deprovisioning

To deactivate or delete an Okta object, configure MIM to **Stage a delete of the object for the next export run**.

For users, the **User deprovisioning action** global setting decides whether that delete deactivates the user or permanently deletes it. Group deletes are always permanent.

## Step 9: Create the run profiles

Finish the wizard and create the run profiles.

Then return to [Getting started](/okta-ma/installation/getting-started.md#step-7-import-review-then-export) for the first controlled import and synchronization. Make sure your ongoing schedule includes a periodic Full Import: Okta can't return an object it no longer holds, so a delta import will never detect a deletion.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lithnet.io/okta-ma/configuration/creating-the-management-agent.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
