Synchronize eligible employees.
Import active users assigned to the Elba SSO application, plus groups and memberships.
Synchronize your Okta directory and see, read-only, which Okta applications each person is assigned. Compare them with the applications people use outside Okta, then make changes in Okta.
Read-only Okta connection · Okta identity provider or API Services app
Product illustration · Example data and workflow.
Capabilities
Import active users assigned to the Elba SSO application, plus groups and memberships.
Show Okta assignments, direct or through a group, as access in Third-Party Apps without opening issues.
Filter the applications at least five people use without an Okta assignment. Not being managed in Okta is not a risk verdict on its own.
Example workflow
How the integration supports a specific security task.
Elba synchronizes the directory and reads which Okta applications each person is assigned.
The reviewer filters the inventory on Not managed in Okta to see applications at least five people use without an Okta assignment.
The identity administrator makes any assignment change in the Okta Admin Console.
Related capability
Before you connect
Available when Okta is your elba identity provider, and for Third-Party Apps through an Okta API Services application when it is not. With Okta as your identity provider, setup uses two application configurations: an SSO application for administrator sign-in and a service integration with read scopes for directory and assignment synchronization.
Explore security & privacyOne application handles administrator SSO. The separate service integration provides read-only access for directory synchronization, application assignments and the administrator role check during sign-in.
No. elba only reads Okta. Use the evidence in elba to investigate, then change the account or assignment in the Okta Admin Console.
No. Each assignment counts as access for that person and application, but it never opens an issue, receives a tag or changes the application’s usage policy.
The service integration uses okta.apps.read, okta.users.read, okta.roles.read and okta.groups.read. Application assignments use these existing scopes and need no new consent. Sign-in dates need okta.logs.read, which is optional and requested on a token of its own.
Complete setup with an active Super Administrator or Application Administrator account. To show app assignments, the service integration needs a Super Administrator, Organization Administrator or Read-only Administrator role, or an Application Administrator role not limited to specific applications.
Discuss your requirements
Review the available capabilities, required permissions, and setup for your environment with our team.