Skip to content
All integrations
Okta

Compare Okta assignments with the apps people use.

Synchronize your Okta directory and see, read-only, which Okta applications each person is assigned. Compare them with the applications people use outside Okta, then make changes in Okta.

Read-only Okta connection · Okta identity provider or API Services app

Product illustration · Example data and workflow.

Capabilities

What this integration covers.

01

Synchronize eligible employees.

Import active users assigned to the Elba SSO application, plus groups and memberships.

02

See who is assigned which app.

Show Okta assignments, direct or through a group, as access in Third-Party Apps without opening issues.

03

Find apps used outside Okta.

Filter the applications at least five people use without an Okta assignment. Not being managed in Okta is not a risk verdict on its own.

Example workflow

Review an application used outside Okta.

How the integration supports a specific security task.

  1. 01

    Synchronize Okta

    Elba synchronizes the directory and reads which Okta applications each person is assigned.

  2. 02

    Review usage outside Okta

    The reviewer filters the inventory on Not managed in Okta to see applications at least five people use without an Okta assignment.

  3. Update Okta if needed

    The identity administrator makes any assignment change in the Okta Admin Console.

Related capability

Explore this part of the platform.

Explore apps & access

Before you connect

Coverage, permissions, and requirements.

Available when Okta is your elba identity provider, and for Third-Party Apps through an Okta API Services application when it is not. With Okta as your identity provider, setup uses two application configurations: an SSO application for administrator sign-in and a service integration with read scopes for directory and assignment synchronization.

Explore security & privacy
Why does elba need two Okta applications?

One application handles administrator SSO. The separate service integration provides read-only access for directory synchronization, application assignments and the administrator role check during sign-in.

Can elba disable an Okta user or remove an assignment?

No. elba only reads Okta. Use the evidence in elba to investigate, then change the account or assignment in the Okta Admin Console.

Do Okta assignments open Third-Party Apps issues?

No. Each assignment counts as access for that person and application, but it never opens an issue, receives a tag or changes the application’s usage policy.

Which Okta scopes are requested for synchronization?

The service integration uses okta.apps.read, okta.users.read, okta.roles.read and okta.groups.read. Application assignments use these existing scopes and need no new consent. Sign-in dates need okta.logs.read, which is optional and requested on a token of its own.

Which administrator role is required?

Complete setup with an active Super Administrator or Application Administrator account. To show app assignments, the service integration needs a Super Administrator, Organization Administrator or Read-only Administrator role, or an Application Administrator role not limited to specific applications.

Coverage and requirements
  • When your elba identity provider is Google Workspace or Microsoft 365, application assignments come from an Okta API Services application you connect for Third-Party Apps. It matches Okta users to elba users by email.
  • Sign-in dates need the okta.logs.read scope. elba then reads successful Okta sign-ins and keeps only each person’s latest sign-in to each application it records as an assignment.
  • Only Okta applications that elba can match with confidence to its catalog appear; others are skipped. An application without an Okta assignment is not managed in Okta, which does not make it unsanctioned or risky by itself.
  • The service integration needs a Super Administrator, Organization Administrator or Read-only Administrator role, or an Application Administrator role not limited to specific applications. Without one, elba skips the assignment synchronization and adds or removes nothing.
  • elba never writes to Okta: it does not suspend users, change assignments or change roles. The administrator role check at sign-in authorizes access to elba; it is not a role inventory.
  • SSO and directory synchronization use separate application credentials and must both remain correctly configured.
  • Client secrets are production credentials and must not be placed in tickets, screenshots or source control.
  • If the Okta application types or console labels differ from the in-product setup, stop and confirm the configuration before creating another production application.

Other applications

Review more integrations.

All integrations

Discuss your requirements

Evaluate Elba for Okta.

Review the available capabilities, required permissions, and setup for your environment with our team.

Request a demo