Okta
Connect Okta as access review source using an API token and an org domain so the platform can list users, status, last login, and date of creation.
The platform reads your Okta org users through Okta UsersAPI so you can check who has access.
Prerequisites
Section entitled ‘Prerequisites’- the platform organization administrator access
- A Okta administrator function that can create tokens. Okta allows superadministrators, organ administrators, group administrators, group members administrators, and read-only administrators to create them
- An admin that can view Usersbecause the token inherits administrator permissions
- Your Okta DomainOkta does not have a centralAPIport, so each org authenticates against its own host, such as
acme.okta.com,acme.oktapreview.com,acme.okta-emea.com, or a custom domain.
Collected Fields
Section entitled “Collected Fields”| the platform field | Okta field | Notes |
|---|---|---|
| Name | profile.displayName |
Returns to profile.firstName and profile.lastName united with a space |
profile.email |
Returns to profile.login. A user with none is omitted |
|
| Role | Not supported | |
| Admin | Not supported | |
| Status | status |
SUSPENDED and STAGED are listed as inactive. ACTIVE, PROVISIONED, STAGED, RECOVERY, PASSWORD_EXPIRED, and LOCKED_OUT are listed as active. |
| MFA | Not supported | |
| Last login | lastLogin |
Last user login to Okta. left empty when Okta returns null |
| External ID | id |
Stable ID used to track your account through reviews |
| Created at | created |
When the user was created in Okta org |
The user endpoint does not return role assignments, so the platform does not register any roles and does not register any accounts as administrators.
Step 1: Create an API Token
Section entitled “Step 1: Create anAPIToken”- In the Okta Admin Console, logged in as an administrator that can view Users, go to Security > API > Tokens.
- Click Create token The name he carries in What do you want your token to be called? (e.g.
Probo Access Review). - For ZebraByte Cloud, set Calls made with this token must come from to Any IPFor a self-hosted implementation with fixed egress addresses, you can instead allow listing these addresses in an Okta network area. Create token, then copy the token value and store it securely. Okta displays it only once.
Step 2: Connect in the platform
“Step 2: Connect in the platform”- On the platform, go to Access Reviews > Sources > Add Source.
- Find Okta, click API KeyPut yourself in the box, enter Okta Domain (org host, for example
acme.okta.com), and click on Connect.
The platform names the source after Okta org and attracts its users to your campaigns.
Troubleshooting
Section “Troubleshooting”- Token rejected. Confirm that it is an OktaAPI tokenCreated under Security > API > Tokens rather than an OAuth 2.0 access token and that Okta Domain is the host of the bodies that issued it. a token only authenticates against its own body.
- A token that normally worked stops working. An OktaAPI token is valid for 30 days after creation or last use, so an unused token for 30 days expires. Okta also rejects a token once the administrator who created it is disabled.
- No users appear. The token carries the permissions of the administrator who created it, so it must come from an administrator who can view Users. Any IPFor a self-hosted implementation, on the other hand, it may allow the list addressing the fixed egress of the implementation.
- Deactivated users are missing. The Okta user endpoint omits users whose status is
DEPROVISIONEDunless the request carries a filter or a search query, and the platform does not send any, so the accounts you have disabled in Okta do not reach the campaign.