Delta Aggregation

Note
The Okta SaaS connector supports delta aggregation for accounts only.

The time stamp for account aggregation is stored in the application object and is used by the delta aggregation feature to aggregate updated data into Identity Security Cloud. This time stamp is updated after every account delta aggregation.

The delta for Okta user profile attributes is populated from the users API by comparing the time stamp of the last successful account aggregation against the last updated attribute.

To detect entitlement changes and deleted users, the data is populated from the logs API by comparing the time stamp of the last successful account aggregation against the published attribute.

Note
Log data older than 90 days is not returned by Okta's Data Retention Policy. This implies that any data changes that happened before 90 days from the last successful account aggregation will not be captured and hence a full account aggregation will be required.