Skip to main content

Okta

Visualize Okta users, groups, devices, applications, and services, map users to employees, and monitor changes through queries and alerts.

Installation​

For this integration, you will need to create an API Token on Okta from an Okta account with admin permissions. Ensure that you are in admin-mode when creating the token by selecting the Admin button in the top right prior to creating the API Token.

An Okta API token carries the admin role of the user who created it. The integration only reads from Okta, so create the token from a Read-Only Administrator account. That covers users, groups, group rules, applications, devices and the System Log.

note

Two things need a token created by a Super Administrator, per Okta's admin role comparison:

  • Admin role assignments (the Okta User Roles data source). With a lower role, those steps are skipped and every other step still runs.
  • The Okta Support access setting. With a lower role, okta_account.supportEnabled is left empty.

The Authorization tab lists every Okta API endpoint the integration calls and the admin role each one needs.

Per the Okta documentation: API tokens are valid for 30 days and automatically renew every time they are used with an API request. When a token has been inactive for more than 30 days it is revoked and cannot be used again. Tokens are also only valid if the user who created the token is also active.

info

For additional information regarding Okta API tokens, see their documentation for more information.

Configuration in JupiterOne​

To install the Okta integration in JupiterOne, navigate to the Integrations tab in JupiterOne and select Okta. Click New Instance to begin configuring your integration.

Creating an instance requires the following:

  • The Account Name used to identify the Okta account in JupiterOne. Ingested entities will have this value stored in tag.AccountName when the AccountName toggle is enabled.

  • Description to assist in identifying the integration instance, if desired.

  • Polling Interval that you feel is sufficient for your monitoring needs. You may leave this as DISABLED and manually execute the integration.

  • Enter the Organization URL unique to your Okta organization and your Okta API Key.

These settings are optional:

  • Additional user profile attributes: a comma-separated list of Okta user profile attributes to add to okta_user entities, such as custom attributes your admins created (for example: badgeNumber, building). Use the variable names shown in Okta's Profile Editor. Each attribute is added under its camelCased name (team_code becomes teamCode). Okta's standard profile attributes, such as title, department and employeeNumber, are ingested without being listed.

  • Ingest Admin Notes: adds each application's admin notes to okta_application.adminNotes.

The data sources section lets you turn off what you don't need: Okta Apps, User Groups, MFA Devices, User Roles and Group Rules are on by default. Okta Devices is off by default and requires the org to be on Okta Identity Engine. Turning a data source off stops its API calls and removes its entities from JupiterOne on the next run.

Click Create once all values are provided to finalize the integration.

Next steps​

Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.