> For the complete documentation index, see [llms.txt](https://docs.lithnet.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lithnet.io/okta-ma/configuration/schema-and-attributes.md).

# Schema and attributes

What the management agent presents to MIM, and what controls it.

When MIM retrieves the schema, the management agent reads the default Okta user profile and builds the `user` object type from its base and custom attributes. The `group` object type is fixed.

## OAuth scopes

With OAuth, the scopes Okta granted determine what MIM is shown. The connector reads them from the access token, so the schema reflects the real grant rather than anything typed into the MIM configuration. If the schema isn't what you expected, it's the grant in Okta that needs changing.

![The user and group object types available after schema retrieval.](https://2206708376-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0u5rDWCokdBire3bUPyS%2Fuploads%2Fgit-blob-a14530e61b189a1336f704e84608b3ef01f9737d%2Fmim-select-object-types.png?alt=media)

| Granted scope        | MIM schema                                                                           |
| -------------------- | ------------------------------------------------------------------------------------ |
| No user scope        | The `user` object type is not shown at all.                                          |
| `okta.users.read`    | `user` is shown with import-only attributes. Write-only Okta attributes are omitted. |
| `okta.users.manage`  | `user` is shown with its supported import and export attributes.                     |
| No group scope       | The `group` object type is not shown at all.                                         |
| `okta.groups.read`   | `group` is shown with import-only attributes.                                        |
| `okta.groups.manage` | `group` is shown with its supported import and export attributes.                    |

`okta.schemas.read` is required in every case, because the connector reads the Okta user profile to build the user schema. If both a read and a manage scope are granted for an object type, the manage result applies.

An API token shows the full `user` and `group` schema, with everything the connector supports, regardless of what the token's account can do.

{% hint style="info" %}
Scopes and admin roles control different things. Scopes determine what the connector presents to MIM, while the app's admin role and resource set determine what Okta permits at run time. Okta doesn't reveal the role's boundaries during schema retrieval, so a schema can retrieve cleanly and an import or export can still return `403 Forbidden`.
{% endhint %}

## User attributes

These attributes are added by the management agent, on top of whatever the Okta user profile returns.

| Attribute          | Type               | Direction                                                            |
| ------------------ | ------------------ | -------------------------------------------------------------------- |
| `id`               | String             | Import-only anchor                                                   |
| `status`           | String             | Import only                                                          |
| `created`          | String             | Import only                                                          |
| `activated`        | String             | Import only                                                          |
| `statusChanged`    | String             | Import only                                                          |
| `lastLogin`        | String             | Import only                                                          |
| `lastUpdated`      | String             | Import only                                                          |
| `passwordChanged`  | String             | Import only                                                          |
| `provider.type`    | String             | Import only                                                          |
| `provider.name`    | String             | Import only                                                          |
| `enrolledFactors`  | Multivalued string | Import only                                                          |
| `availableFactors` | Multivalued string | Import only                                                          |
| `suspended`        | Boolean            | Import and export with user management access, otherwise import only |

`suspended` is how you suspend and unsuspend a user. `status` is import-only, so there is nothing to flow to it, and activation and deprovisioning are driven by the global settings instead.

![Selecting user lifecycle attributes, including suspended.](https://2206708376-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0u5rDWCokdBire3bUPyS%2Fuploads%2Fgit-blob-8d0d8928f53ed018ea55097405c74290b67a2bda%2Fmim-select-user-lifecycle-attributes.png?alt=media)

## Custom user attributes

Add custom attributes to the default Okta user profile before retrieving the MIM schema. Their direction in MIM follows the mutability set in Okta:

| Okta mutability            | MIM direction                                     |
| -------------------------- | ------------------------------------------------- |
| `READ_WRITE`               | Import and export                                 |
| `WRITE_ONLY`               | Export only, and only with user management access |
| `READ_ONLY` or `IMMUTABLE` | Import only                                       |

Okta data types map to MIM types as follows:

| Okta type | MIM type                               |
| --------- | -------------------------------------- |
| `string`  | String                                 |
| `boolean` | Boolean                                |
| `integer` | Integer                                |
| `number`  | String                                 |
| `array`   | Multivalued attribute of the item type |

`managerId` is the exception: it is presented as a reference to another Okta user rather than as a string.

![Custom Okta profile attributes on the MIM Select Attributes page.](https://2206708376-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0u5rDWCokdBire3bUPyS%2Fuploads%2Fgit-blob-3a85b2fdfc2edb0fd5af3184f39d85a648cab69c%2Fmim-select-user-custom-attribute.png?alt=media)

## Group attributes

| Attribute               | Type                  | Direction                                                             |
| ----------------------- | --------------------- | --------------------------------------------------------------------- |
| `id`                    | String                | Import-only anchor                                                    |
| `created`               | String                | Import only                                                           |
| `lastUpdated`           | String                | Import only                                                           |
| `lastMembershipUpdated` | String                | Import only                                                           |
| `type`                  | String                | Import only                                                           |
| `name`                  | String                | Import and export with group management access, otherwise import only |
| `description`           | String                | Import and export with group management access, otherwise import only |
| `member`                | Multivalued reference | Import and export with group management access, otherwise import only |

Only `OKTA_GROUP` groups are writable, regardless of what the schema shows. Scope your outbound flows so that `BUILT_IN` and `APP_GROUP` groups never receive one.

MIM lists the attributes of every selected object type together on one page, so the group `member` attribute appears in the same list as the user attributes.

![The combined attribute list, including the group member attribute.](https://2206708376-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F0u5rDWCokdBire3bUPyS%2Fuploads%2Fgit-blob-3a85b2fdfc2edb0fd5af3184f39d85a648cab69c%2Fmim-select-group-attributes.png?alt=media)

## Import cost of factor and membership attributes

Three attributes are more expensive to import than the rest, because each one requires a separate API call:

* `enrolledFactors` costs one call per imported user
* `availableFactors` costs one call per imported user
* group `member` costs one call per imported group

Selecting all three on a large tenant will dominate the import time, so select them only if your solution uses them.

## When to retrieve the schema again

MIM schemas don't refresh by themselves. Retrieve the schema again after:

* Adding, removing, or changing a custom Okta user attribute
* Changing the OAuth scope grants
* Installing a release whose notes say the schema changed

Then review the object types and attribute directions, update the affected attribute flows, and run a Full Import and Full Synchronization before you resume exporting.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lithnet.io/okta-ma/configuration/schema-and-attributes.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
