Skip to content
All integrations
Okta

Review Okta identities and app assignments.

Review users, groups, application assignments, and admin roles through a read-only connection. Use the findings to investigate access and make changes in Okta.

Read-only Okta connection

Product illustration · Example data and workflow.

Capabilities

What this integration covers.

01

Review users and group memberships.

Connect people to their group memberships and applications, in one place.

02

Investigate application and admin access.

Review application assignments and administrator roles with the context needed to investigate.

03

Make access changes in Okta.

Use Elba to guide the decision, then make account, role, or assignment changes in Okta.

Example workflow

Investigate an unexpected app assignment.

How the integration supports a specific security task.

  1. 01

    Synchronize Okta records

    Elba synchronizes the user’s Okta groups, roles, and application assignments.

  2. 02

    Review the assignment

    The reviewer investigates whether an unexpected assignment is still needed.

  3. Update access in Okta

    The identity administrator makes the required change in the Okta console.

Related capability

Explore this part of the platform.

Explore apps & access

Before you connect

Coverage, permissions, and requirements.

Okta setup uses two application configurations: an SSO application for administrator sign-in and a service integration with read scopes for directory synchronization.

Explore security & privacy
Why does elba need two Okta applications?

One application handles administrator SSO. The separate service integration provides the read-only scopes used for directory, assignment and role synchronization.

Can elba disable an Okta user or remove an assignment?

Not through the documented read-only service integration. Use the evidence in elba to investigate and complete the authoritative change in Okta.

Which Okta scopes are requested for synchronization?

The documented service integration uses okta.apps.read, okta.users.read, okta.roles.read and okta.groups.read.

Which administrator role is required?

Complete setup with an active Super Administrator or Application Administrator account, following the application instructions shown in your elba workspace.

Coverage and requirements
  • The documented Okta service integration is read-only and does not directly suspend users, remove assignments or change roles.
  • SSO and directory synchronization use separate application credentials and must both remain correctly configured.
  • Client secrets are production credentials and must not be placed in tickets, screenshots or source control.
  • If the Okta application types or console labels differ from the in-product setup, stop and confirm the configuration before creating another production application.

Other applications

Review more integrations.

All integrations

Discuss your requirements

Evaluate Elba for Okta.

Review the available capabilities, required permissions, and setup for your environment with our team.

Request a demo