Okta
Visualize Okta users, groups, devices, applications, and services, map users to employees, and monitor changes through queries and alerts.
- Installation
- Authorization
- Data Model
- Types
- Release Notes
Installation
For this integration, you will need to create an API Token on Okta from an Okta account with admin permissions. Ensure that you are in admin-mode when creating the token by selecting the Admin button in the top right prior to creating the API Token.
An Okta API token carries the admin role of the user who created it. The integration only reads from Okta, so create the token from a Read-Only Administrator account. That covers users, groups, group rules, applications, devices and the System Log.
Two things need a token created by a Super Administrator, per Okta's admin role comparison:
- Admin role assignments (the Okta User Roles data source). With a lower role, those steps are skipped and every other step still runs.
- The Okta Support access setting. With a lower role,
okta_account.supportEnabledis left empty.
The Authorization tab lists every Okta API endpoint the integration calls and the admin role each one needs.
Per the Okta documentation: API tokens are valid for 30 days and automatically renew every time they are used with an API request. When a token has been inactive for more than 30 days it is revoked and cannot be used again. Tokens are also only valid if the user who created the token is also active.
For additional information regarding Okta API tokens, see their documentation for more information.
Configuration in JupiterOne
To install the Okta integration in JupiterOne, navigate to the Integrations tab in JupiterOne and select Okta. Click New Instance to begin configuring your integration.
Creating an instance requires the following:
-
The Account Name used to identify the Okta account in JupiterOne. Ingested entities will have this value stored in
tag.AccountNamewhen theAccountNametoggle is enabled. -
Description to assist in identifying the integration instance, if desired.
-
Polling Interval that you feel is sufficient for your monitoring needs. You may leave this as
DISABLEDand manually execute the integration. -
Enter the Organization URL unique to your Okta organization and your Okta API Key.
These settings are optional:
-
Additional user profile attributes: a comma-separated list of Okta user profile attributes to add to
okta_userentities, such as custom attributes your admins created (for example:badgeNumber, building). Use the variable names shown in Okta's Profile Editor. Each attribute is added under its camelCased name (team_codebecomesteamCode). Okta's standard profile attributes, such astitle,departmentandemployeeNumber, are ingested without being listed. -
Ingest Admin Notes: adds each application's admin notes to
okta_application.adminNotes.
The data sources section lets you turn off what you don't need: Okta Apps, User Groups, MFA Devices, User Roles and Group Rules are on by default. Okta Devices is off by default and requires the org to be on Okta Identity Engine. Turning a data source off stops its API calls and removes its entities from JupiterOne on the next run.
Click Create once all values are provided to finalize the integration.
Next steps
Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.
Roles
RBAC roles that must be assigned to the integration principal.
Show Roles (2)
Read-Only AdministratorSuper Administrator
Endpoints
API endpoints that the integration makes requests to.
Show Endpoints (14)
https://{yourOktaDomain}/api/v1/appshttps://{yourOktaDomain}/api/v1/apps/{appId}/groupshttps://{yourOktaDomain}/api/v1/apps/{appId}/usershttps://{yourOktaDomain}/api/v1/deviceshttps://{yourOktaDomain}/api/v1/groupshttps://{yourOktaDomain}/api/v1/groups/ruleshttps://{yourOktaDomain}/api/v1/groups/{groupId}/roleshttps://{yourOktaDomain}/api/v1/groups/{groupId}/usershttps://{yourOktaDomain}/api/v1/iam/assignees/usershttps://{yourOktaDomain}/api/v1/logshttps://{yourOktaDomain}/api/v1/org/privacy/oktaSupporthttps://{yourOktaDomain}/api/v1/usershttps://{yourOktaDomain}/api/v1/users/{userId}/factorshttps://{yourOktaDomain}/api/v1/users/{userId}/roles
Documentation Links
Links to provider documentation relevant to setup and configuration.
Show Documentation Links (13)
- https://developer.okta.com/docs/api/openapi/okta-management/management/tags/application
- https://developer.okta.com/docs/api/openapi/okta-management/management/tags/applicationgroups
- https://developer.okta.com/docs/api/openapi/okta-management/management/tags/applicationusers
- https://developer.okta.com/docs/api/openapi/okta-management/management/tags/device
- https://developer.okta.com/docs/api/openapi/okta-management/management/tags/group
- https://developer.okta.com/docs/api/openapi/okta-management/management/tags/grouprule
- https://developer.okta.com/docs/api/openapi/okta-management/management/tags/orgsettingsupport
- https://developer.okta.com/docs/api/openapi/okta-management/management/tags/roleassignmentauser
- https://developer.okta.com/docs/api/openapi/okta-management/management/tags/roleassignmentbgroup
- https://developer.okta.com/docs/api/openapi/okta-management/management/tags/systemlog
- https://developer.okta.com/docs/api/openapi/okta-management/management/tags/user
- https://developer.okta.com/docs/api/openapi/okta-management/management/tags/userfactor
- https://help.okta.com/en-us/content/topics/security/administrators-admin-comparison.htm
Per-Step Breakdown
Detailed authorization requirements for each ingestion step.
Show all steps (7)
| Step | Roles | Endpoints |
|---|---|---|
| Build User Created Application Relationship | Read-Only Administrator | https://{yourOktaDomain}/api/v1/logs |
| Create app user group to user relationships | Read-Only Administrator | https://{yourOktaDomain}/api/v1/groups/{groupId}/users |
| Create group to app relationships | Read-Only Administrator | https://{yourOktaDomain}/api/v1/apps/{appId}/groups |
| Create user group to user relationships | Read-Only Administrator | https://{yourOktaDomain}/api/v1/groups/{groupId}/users |
| Create user to app relationships | Read-Only Administrator | https://{yourOktaDomain}/api/v1/apps/{appId}/users |
| Fetch Group Roles | Super Administrator | https://{yourOktaDomain}/api/v1/groups/{groupId}/roles |
| Fetch Rules | Read-Only Administrator | https://{yourOktaDomain}/api/v1/groups/rules |
Entities
The following entities are created:
| Resources | Entity _type | Entity _class |
|---|---|---|
| Okta Account | okta_account | Account |
| Okta App UserGroup | okta_app_user_group | UserGroup |
| Okta Application | okta_application | Application, NHI |
| Okta Device | okta_device | Device |
| Okta Factor Device | mfa_device | Key, AccessKey |
| Okta Role | okta_role | AccessRole |
| Okta Rule | okta_rule | Configuration |
| Okta Service | okta_service | Service, Control |
| Okta User | okta_user | User |
| Okta UserGroup | okta_user_group | UserGroup |
Relationships
The following relationships are created:
Source Entity _type | Relationship _class | Target Entity _type |
|---|---|---|
okta_account | MANAGES | okta_service |
okta_account | HAS | okta_service |
okta_account | HAS | okta_user |
okta_account | HAS | okta_user_group |
okta_account | HAS | okta_app_user_group |
okta_account | HAS | okta_application |
okta_account | HAS | okta_rule |
okta_account | MANAGES | okta_device |
okta_app_user_group | HAS | okta_user |
okta_rule | MANAGES | okta_user_group |
okta_user | ASSIGNED | mfa_device |
okta_user | MANAGES | okta_user |
okta_user | ASSIGNED | okta_application |
okta_user | ASSIGNED | aws_iam_role |
okta_user | ASSIGNED | okta_role |
okta_user | CREATED | okta_application |
okta_user | OWNS | okta_device |
okta_user_group | HAS | okta_user |
okta_user_group | ASSIGNED | aws_iam_role |
okta_user_group | ASSIGNED | okta_role |
okta_user_group, okta_app_user_group | ASSIGNED | okta_application |
Mfa Device
mfa_device inherits from Key, AccessKey
| Property | Type | Description | Specifications |
|---|---|---|---|
authenticatorName | string | Authenticator name for WebAuthn factors, e.g. YubiKey 5. | |
created | number | Please use createdOn instead | deprecated: true |
device | string | Device reported for the factor, if any. | |
deviceType | string | Device type for Okta Verify factors, e.g. SmartPhone_IPhone. | |
factorType | string | Okta factor type, e.g. push, sms, token:software:totp or webauthn. | |
lastUpdated | number | Please use updatedOn instead | deprecated: true |
lastVerifiedOn | number | When the factor was last used to verify the user. | |
platform | string | Device platform for Okta Verify factors, e.g. IOS. | |
profileName | string | Device name for Okta Verify factors. | |
provider | string | Factor provider, e.g. OKTA, GOOGLE, FIDO or YUBICO. | |
vendorName | string | Factor vendor name reported by Okta. |
Okta Account
okta_account inherits from Account
| Property | Type | Description | Specifications |
|---|---|---|---|
accountId * | string | Okta org domain, e.g. acme.okta.com. | |
supportEnabled * | boolean | null | Whether Okta Support currently has temporary access to the org. Null when the API token cannot read the setting (it requires a Super Administrator token). | |
supportExpiresOn | number | When Okta Support access to the org expires. |
Okta App User Group
okta_app_user_group inherits from UserGroup
| Property | Type | Description | Specifications |
|---|---|---|---|
created | number | Please use createdOn instead | deprecated: true |
lastMembershipUpdated | number | Please use lastMembershipUpdatedOn instead | deprecated: true |
lastMembershipUpdatedOn | number | When the group's membership last changed. | |
lastUpdated | number | Please use updatedOn instead | deprecated: true |
lastUpdatedOn | number | Please use updatedOn instead | deprecated: true |
objectClass | array of strings | Okta object classes of the group, e.g. okta:user_group. | |
type | string | Okta group type: OKTA_GROUP, APP_GROUP (imported from an app such as Active Directory) or BUILT_IN. |
Okta Application
okta_application inherits from Application, NHI
| Property | Type | Description | Specifications |
|---|---|---|---|
adminNotes * | string | null | Admin notes on the app. Only populated when the Ingest Admin Notes setting is on. | |
appAccountType | string | array | Kind of vendor account the app grants access to, for known vendors. | |
appVendorName | string | Human readable, capitalized vendor name Examples: Atlassian, Snyk | |
created | number | Please use createdOn instead | deprecated: true |
endUserNotes * | string | null | Notes shown to end users for the app. | |
features | array of strings | Provisioning features enabled for the app, e.g. PUSH_NEW_USERS. | |
imageUrl | string | URL of the app logo in Okta. | |
isMultiInstanceApp | boolean | True if one of: aws, githubcloud, gcp, google, office365 | |
isSAMLApp | boolean | True if the application is a SAML application | |
label | string | App label as shown in the Okta admin console. | |
lastUpdated | number | Please use updatedOn instead | deprecated: true |
loginUrl | string | URL users open to sign in to the app from Okta. | |
oauthApplicationType | string | OAuth client application type: web, native, browser, or service | |
oauthClientUri | string | Publisher-supplied landing page URL for the OAuth client | |
oauthConsentMethod | string | OAuth consent flow: REQUIRED (end-user consent) or TRUSTED (admin pre-approved — risk signal for third-party access) | |
oauthGrantTypes | array of strings | OAuth grant types the client is configured for (e.g. authorization_code, client_credentials, refresh_token) | |
oauthLogoUri | string | Publisher-supplied URL of the client's logo | |
oauthPolicyUri | string | Publisher-supplied privacy policy URL | |
oauthPostLogoutRedirectUris | array of strings | OAuth post-logout redirect URIs the client is allowed to use | |
oauthRedirectUris | array of strings | OAuth redirect URIs the client is allowed to use after authorization | |
oauthTosUri | string | Publisher-supplied terms of service URL | |
shortName | string | Short app name derived from the Okta app name. Examples: aws, gcp | |
signOnAttribute | array of strings | Filter values of the app's SAML attribute statements. | |
signOnMode | string | Sign-on mode: AUTO_LOGIN, BASIC_AUTH, BOOKMARK, BROWSER_PLUGIN, OPENID_CONNECT, SAML_1_1, SAML_2_0, SECURE_PASSWORD_STORE or WS_FEDERATION. |
Okta Device
okta_device inherits from Device
| Property | Type | Description | Specifications |
|---|---|---|---|
deviceStatus | string | Okta device status: active, created, deactivated or suspended. | |
isRegistered | boolean | Whether the device is registered with Okta. | |
platform | string | Device platform reported by Okta, lowercased, e.g. macos. | |
registered | boolean | Please use isRegistered instead | deprecated: true |
Okta Role
okta_role inherits from AccessRole
| Property | Type | Description | Specifications |
|---|---|---|---|
lastUpdatedOn | number | Please use updatedOn instead | deprecated: true |
roleType | string | Okta admin role type, e.g. SUPER_ADMIN, ORG_ADMIN or READ_ONLY_ADMIN. |
Okta Rule
okta_rule inherits from Configuration
| Property | Type | Description | Specifications |
|---|---|---|---|
actions | string | JSON stringified object of actions | |
conditions | string | JSON stringified object of conditions | |
created | number | Please use createdOn instead | deprecated: true |
lastUpdated | number | Please use updatedOn instead | deprecated: true |
lastUpdatedOn | number | Please use updatedOn instead | deprecated: true |
ruleType | string | Okta rule type. Examples: group_rule, policy_rule |
Okta Service
okta_service inherits from Service, Control
| Property | Type | Description | Specifications |
|---|---|---|---|
controlDomain * | string | Security control domain of the service: identity-access. |
Okta User
okta_user inherits from User
| Property | Type | Description | Specifications |
|---|---|---|---|
activated | number | Please use activatedOn instead | deprecated: true |
activatedOn | number | When the user was activated in Okta. | |
city | string | null | City from the Okta user profile. | |
costCenter | string | null | Cost center from the Okta user profile. | |
countryCode | string | Country code from the Okta user profile, e.g. US. | |
created | number | Please use createdOn instead | deprecated: true |
credentialProvider | string | The type of authentication provider backing the user (e.g. OKTA for native credentials, FEDERATION for SSO-bound). | Any of: ACTIVE_DIRECTORYFEDERATIONIMPORTLDAPOKTASOCIAL |
credentialProviderName | string | null | The display name of the authentication provider (e.g. an AD domain or federated IdP label). | |
department | string | null | Department from the Okta user profile. | |
division | string | null | Division from the Okta user profile. | |
employeeNumber | string | null | Employee number from the Okta user profile. | |
employeeType | string | Employment classification from Okta user profile (e.g. "Full-time", "Contractor"). Custom attribute configured per-organization. | |
hiredOn | number | Hire date from the Okta profile hireDate attribute. | |
isSsoBound | boolean | True when the user authenticates through a federated SSO provider (credentialProvider === FEDERATION). | |
lastLogin | number | Please use lastLoginOn instead | deprecated: true |
lastLoginOn | number | When the user last signed in to Okta. | |
lastUpdated | number | Please use lastUpdatedOn instead | deprecated: true |
lastUpdatedOn | number | Please use updatedOn instead | deprecated: true |
locale | string | null | Locale from the Okta user profile, e.g. en_US. | |
login * | string | null | The user's Okta login. | |
manager | string | null | Manager's display name from the Okta user profile. | |
managerId | string | The manager's identifier from the Okta profile managerId attribute. | |
organization | string | null | Organization from the Okta user profile. | |
passwordChanged | number | Please use passwordChangedOn instead | deprecated: true |
state | string | null | State or region from the Okta user profile. | |
statusChanged | number | Please use statusChangedOn instead | deprecated: true |
statusChangedOn | number | When the user's status last changed. | |
terminatedOn | number | Termination date from the Okta profile terminationDate attribute. | |
timezone | string | null | Time zone from the Okta user profile, e.g. America/New_York. | |
title | string | null | Job title from the Okta user profile. | |
unverifiedEmails | array of strings | Email addresses on the user's Okta credentials that are not verified. | Format: email |
userType | string | null | User type from the Okta user profile, e.g. Employee or Contractor. | |
verifiedEmails | array of strings | Email addresses on the user's Okta credentials that Okta reports as verified. | Format: email |
Okta User Group
okta_user_group inherits from UserGroup
| Property | Type | Description | Specifications |
|---|---|---|---|
created | number | Please use createdOn instead | deprecated: true |
lastMembershipUpdated | number | Please use lastMembershipUpdatedOn instead | deprecated: true |
lastMembershipUpdatedOn | number | When the group's membership last changed. | |
lastUpdated | number | Please use updatedOn instead | deprecated: true |
lastUpdatedOn | number | Please use updatedOn instead | deprecated: true |
objectClass | array of strings | Okta object classes of the group, e.g. okta:user_group. | |
type | string | Okta group type: OKTA_GROUP, APP_GROUP (imported from an app such as Active Directory) or BUILT_IN. |
Release Notes
- 2026-04-08 — Improved OS name display for Okta device entities, providing human-readable names for all supported platforms.
- 2026-03-05 — Added MFA enabled status property to Okta user entities, indicating whether a user has active MFA configured.
- 2025-10-09 — Added management hierarchy relationships linking Okta users to the users who manage them.
- 2025-06-16 — Added notes field and configuration option to Okta user entities for storing user notes.
- 2025-05-12 — Added device management status property to Okta user-to-device relationships.