jump to content

Okta

Connect Okta as access review source using an API token and an org domain so the platform can list users, status, last login, and date of creation.

Show as Markdown

The platform reads your Okta org users through Okta UsersAPI so you can check who has access.

  • the platform organization administrator access
  • A Okta administrator function that can create tokens. Okta allows superadministrators, organ administrators, group administrators, group members administrators, and read-only administrators to create them
  • An admin that can view Usersbecause the token inherits administrator permissions
  • Your Okta DomainOkta does not have a centralAPIport, so each org authenticates against its own host, such as acme.okta.com, acme.oktapreview.com, acme.okta-emea.com, or a custom domain.
the platform field Okta field Notes
Name profile.displayName Returns to profile.firstName and profile.lastName united with a space
Email profile.email Returns to profile.login. A user with none is omitted
Role Not supported
Admin Not supported
Status status SUSPENDED and STAGED are listed as inactive. ACTIVE, PROVISIONED, STAGED, RECOVERY, PASSWORD_EXPIRED, and LOCKED_OUT are listed as active.
MFA Not supported
Last login lastLogin Last user login to Okta. left empty when Okta returns null
External ID id Stable ID used to track your account through reviews
Created at created When the user was created in Okta org

The user endpoint does not return role assignments, so the platform does not register any roles and does not register any accounts as administrators.

  1. In the Okta Admin Console, logged in as an administrator that can view Users, go to Security > API > Tokens.
  2. Click Create token The name he carries in What do you want your token to be called? (e.g. Probo Access Review).
  3. For ZebraByte Cloud, set Calls made with this token must come from to Any IPFor a self-hosted implementation with fixed egress addresses, you can instead allow listing these addresses in an Okta network area. Create token, then copy the token value and store it securely. Okta displays it only once.

Step 2: Connect in the platform

“Step 2: Connect in the platform”
  1. On the platform, go to Access Reviews > Sources > Add Source.
  2. Find Okta, click API KeyPut yourself in the box, enter Okta Domain (org host, for example acme.okta.com), and click on Connect.

The platform names the source after Okta org and attracts its users to your campaigns.

  • Token rejected. Confirm that it is an OktaAPI tokenCreated under Security > API > Tokens rather than an OAuth 2.0 access token and that Okta Domain is the host of the bodies that issued it. a token only authenticates against its own body.
  • A token that normally worked stops working. An OktaAPI token is valid for 30 days after creation or last use, so an unused token for 30 days expires. Okta also rejects a token once the administrator who created it is disabled.
  • No users appear. The token carries the permissions of the administrator who created it, so it must come from an administrator who can view Users. Any IPFor a self-hosted implementation, on the other hand, it may allow the list addressing the fixed egress of the implementation.
  • Deactivated users are missing. The Okta user endpoint omits users whose status is DEPROVISIONED unless the request carries a filter or a search query, and the platform does not send any, so the accounts you have disabled in Okta do not reach the campaign.

Ultima actualizare: