> For the complete documentation index, see [llms.txt](https://docs.lithnet.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lithnet.io/okta-ma/okta-management-agent/installation/create-the-management-agent.md).

# Installing the OKTA management agent

Download the latest version from the [releases](https://github.com/lithnet/okta-managementagent/releases/) and run the installer on the server that has the FIM synchronization service installed.ls

### Create Management Agent

Once the management agent has been installed, you may need to restart the FIM Synchronization Service Client application if you do not see the `Okta (Lithnet)` management agent type listed.

![](https://1193289288-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FCjWXH2lcMZCS29etu3JK%2Fuploads%2Fgit-blob-8f9e14df6f356f1f60c91ffb6b435e6e6253a377%2Fsetup-1.png?alt=media)

### Connectivity

| Setting    | Description                                                                                                                                             |
| ---------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Tenant URL | This is the URL of your Okta domain. Be sure that you DO NOT include the -admin suffix that appears when visiting the admin console of your tenant      |
| API key    | Create an API key using the [guide provided by Okta](https://developer.okta.com/docs/api/getting_started/getting_a_token)                               |
| Log file   | Specify the path to a location where the log file will be created. Ensure that the FIM sync engine service account has access to write to this location |

![](https://1193289288-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FCjWXH2lcMZCS29etu3JK%2Fuploads%2Fgit-blob-45d249eba13114630f6cbc7cb4c3414107948325%2Fsetup-2.png?alt=media)

### Global Parameters

These settings control the behavior of the management agent.

![](https://1193289288-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FCjWXH2lcMZCS29etu3JK%2Fuploads%2Fgit-blob-9e55f0d7c95754b45239d426fc604d78c56ffd87%2Fsetup-3.png?alt=media)

#### Include built-in groups

This will include groups that are built into Okta itself. These groups have a type of `BUILT_IN` within Okta itself.

#### Include app groups

Allows the management agent to import groups with a type of `APP_GROUP`. These are typically created by external applications, such as the Active Directory agent.

The management agent will always import groups of type `OKTA_GROUP` when the `group` object class is selected in the `Select Object Types` page of the management agent configuration.

#### User deprovisioning action

If the management agent is with a deprovisioning action of 'Stage a delete of the object on the next run', you can configure the specific way that objects are deleted.

* *Deactivate* - Users are deactivated, but not deleted. Deactivated users will not be seen by FIM. Deletes will be confirmed on a delta import. Users must be deleted manually from Okta.
* *Delete* - Users will be deactivated and then automatically deleted. Deletes will only be confirmed on the next full import.

#### Activate new users

Instructs the management agent to automatically activate the users when they are created in Okta. If this option is not selected, the users are place in a `STAGED` status.

#### Send activation email to new users

When the management agent is configured to activate new users, this setting allows you to specify if Okta should send an activation email to new users.

### Select Object Types

Select the object types that you wish to manage. As API calls are expensive, don't select any object types that you don't need.

Do note, that the group object type is currently read-only.

![](https://1193289288-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FCjWXH2lcMZCS29etu3JK%2Fuploads%2Fgit-blob-5043f0ff2a11b2e34d6ca8d1ceed9b293b33378c%2Fsetup-4.png?alt=media)

### Select Attributes

Select the attributes that you wish to manage. It is important to note that

* The `id` attribute is mandatory
* Selecting the `availableFactors` and `enrolledFactors` attributes will slow down your import process. These attributes each require a separate API call, and therefore can add significantly to the total time an import process will take. Consider the use of these attributes carefully.

### Complete the configuration

Configure your attribute flows, filters and join rules as needed.

### Provisioning rules

When provisioning new users, use any unique value as the DN, such as a GUID. The actual value does not matter. This will be replaced by the objectId during the confirming import.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lithnet.io/okta-ma/okta-management-agent/installation/create-the-management-agent.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
