elba
Demo
All integrations

Okta integration

Okta

See who has access to what in Okta—without granting write access

Synchronize the users, groups, application assignments and administrator roles needed to investigate access—without granting elba write scopes to Okta.

Okta setup uses two application configurations: an SSO application for administrator sign-in and a service integration with read scopes for directory synchronization.

Why connect

Identity reviews need more than a list of users

Understanding access requires the relationship between people, groups, assigned applications and elevated roles. The Okta integration brings that connected context into elba while leaving account and entitlement changes under administrator control in Okta.

What elba finds

Read-only identity and assignment evidence

The service integration reads the supported Okta objects covered by its explicit scopes.

  • Users and their current status

    Synchronize supported Okta user profiles and status for identity reconciliation.

    From the connected application

  • Groups and memberships

    Read supported Okta groups and their member relationships to preserve identity context.

    From the connected application

  • Assigned applications and administrator roles

    Read supported application assignments and administrative roles used by security findings.

    From the connected application

What elba can change

Keep Okta changes with the identity administrator

The documented service integration requests read scopes, so elba does not present it as a direct account or assignment-remediation connector.

  • Investigate an unexpected application assignment

    Use the connected user, group and application context in elba, then remove or change access in Okta when required.

    Administrator step

  • Correct group membership or an administrator role

    Validate the identity relationship in elba and complete the authoritative change in the Okta administration console.

    Administrator step

Setup

Separate sign-in from directory synchronization

Use an active Okta Super Administrator or Application Administrator account.

  1. 1

    Open the Okta setup flow supplied by elba and enter the Okta domain and administrator email.

  2. 2

    Create or select the SSO application and the service integration using the in-product instructions.

  3. 3

    Grant the service integration okta.apps.read, okta.users.read, okta.roles.read and okta.groups.read.

  4. 4

    Enter each application’s credentials in the matching elba fields, sign in through Okta and allow the initial synchronization to finish.

Validate both applications and the first synchronization

Check sign-in and data coverage independently because they use different Okta configurations.

  • Administrator sign-in completes through the configured Okta SSO application.
  • The service integration synchronizes the expected users and groups.
  • Representative application assignments and administrator roles appear with the expected identities.
  • The service application has only the four documented read scopes unless the live setup explicitly states otherwise.

Important boundaries

  • The documented Okta service integration is read-only and does not directly suspend users, remove assignments or change roles.
  • SSO and directory synchronization use separate application credentials and must both remain correctly configured.
  • Client secrets are production credentials and must not be placed in tickets, screenshots or source control.
  • If the Okta application types or console labels differ from the in-product setup, stop and confirm the configuration before creating another production application.

FAQ

Okta integration questions

Why does elba need two Okta applications?

One application handles administrator SSO. The separate service integration provides the read-only scopes used for directory, assignment and role synchronization.

Can elba disable an Okta user or remove an assignment?

Not through the documented read-only service integration. Use the evidence in elba to investigate and complete the authoritative change in Okta.

Which Okta scopes are requested for synchronization?

The documented service integration uses okta.apps.read, okta.users.read, okta.roles.read and okta.groups.read.

Which administrator role is required?

Complete setup with an active Super Administrator or Application Administrator account, following the application instructions shown in your elba workspace.

Bring Okta identity context into every access decision

See how read-only assignments, memberships and roles can support a more accountable review workflow.

Book a demo