To enable groups within Okta Identity Provider, you have to configure groups to the application's Sign On settings.


  1. Log in to your Okta's Administrator Console

  2. Go to Applications > Applications

  3. Click on your Cameyo SSO application

  4. Change tab to Sign On

  5. Scroll down to OpenID Connect ID Token

  6. Click Edit

  7. Set Groups claim filter to groups, select Matches regex and enter .*
    (this needs to be called exactly like this)
  8. Go to the Cameyo admin console

  9. Go to your company page

  10. Make sure you set the SSO claim for groups to groups under AUTHENTICATION
  11. Scroll down to your PowerTags and add the following tag (important!):
    !SSO_MEMBEROF_SCOPE=1
  12. Click the [SAVE] button