# Pritunl VPN with Okta groups

**URL:** https://forum.pritunl.com/t/pritunl-vpn-with-okta-groups/488
**Category:** Pritunl VPN
**Created:** [October 23, 2022, 6:24am UTC](https://forum.pritunl.com/t/pritunl-vpn-with-okta-groups/488 "2022-10-23T06:24:16Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![liranmenashe](https://forum.pritunl.com/user_avatar/forum.pritunl.com/liranmenashe/32/161_2.png) [@liranmenashe](https://forum.pritunl.com/u/liranmenashe)
#### Post date: [October 23, 2022, 6:24am UTC](https://forum.pritunl.com/t/pritunl-vpn-with-okta-groups/488/1 "2022-10-23T06:24:16Z")

</div>

Hey, is there an option to use Okta groups to access control in Pritunl VPN?  
If the answer is no - is there an option to attach multiple users to a static group from CLI instead of one by one in GUI ?

Thanks.

---

<div class="post-metadata">

### Author: ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)
#### Post date: [October 23, 2022, 8:18pm UTC](https://forum.pritunl.com/t/pritunl-vpn-with-okta-groups/488/2 "2022-10-23T20:18:58Z")

</div>

The [**Okta documentation**](https://docs.pritunl.com/docs/okta#setting-user-organization) explains how to configure setting the Pritunl organization from Okta.

Pritunl user groups can also be used by setting the `groups` SAML attribute with a comma separated list. When using user groups the groups option in the server settings must also be configured. Once user groups are configured a user must have a matching organization and group when connecting to a server.

---

<div class="post-metadata">

### Author: ![alexz](https://forum.pritunl.com/letter_avatar_proxy/v4/letter/a/5daacb/32.png) [@alexz](https://forum.pritunl.com/u/alexz)
#### Post date: [November 6, 2022, 8:55am UTC](https://forum.pritunl.com/t/pritunl-vpn-with-okta-groups/488/3 "2022-11-06T08:55:50Z")

</div>

Do you have an example on how to add a comma separated list of groups in Okta?  
I’ve been trying and it always sends only 1 group.

---

<div class="post-metadata">

### Author: ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)
#### Post date: [November 7, 2022, 12:39pm UTC](https://forum.pritunl.com/t/pritunl-vpn-with-okta-groups/488/4 "2022-11-07T12:39:13Z")

</div>

The [**Okta Expression Language documentation**](https://developer.okta.com/docs/reference/okta-expression-language/) has more information.

---

<div class="post-metadata">

### Author: ![liranmenashe](https://forum.pritunl.com/user_avatar/forum.pritunl.com/liranmenashe/32/161_2.png) [@liranmenashe](https://forum.pritunl.com/u/liranmenashe)
#### Post date: [November 14, 2022, 6:57am UTC](https://forum.pritunl.com/t/pritunl-vpn-with-okta-groups/488/5 "2022-11-14T06:57:47Z")

</div>

Hey this solution provide to me by Okta support and it works:

1. Firstly, you will need to create a custom attribute under Directory → Profile Editor → Profile (The one next to your application) → Add Attribute --\>type:string array, name: groups, scope: user personal

2. You will need to create a mapping between Okta and the application. So go to the mappings of the app, select Okta to App and use the following expression:

String.join(“,”, isMemberOfGroupName(“Group1”) ? ‘Group1’ : ‘’, isMemberOfGroupName(“Group2”) ? ‘Group2’ : ‘’, isMemberOfGroupName(“Group3”) ? ‘Group3’ : ‘’)

You will need to adapt the expression based on your groups.

1. Under the Sign On tab of the application, under “Attribute Statements”, you will need to add a new attribute and for Value, you will need to enter the same expression that you used at step 2

Good luck.
