Review users and group memberships.
Connect people to their group memberships and applications, in one place.
Review users, groups, application assignments, and admin roles through a read-only connection. Use the findings to investigate access and make changes in Okta.
Read-only Okta connection
Product illustration · Example data and workflow.
Capabilities
Connect people to their group memberships and applications, in one place.
Review application assignments and administrator roles with the context needed to investigate.
Use Elba to guide the decision, then make account, role, or assignment changes in Okta.
Example workflow
How the integration supports a specific security task.
Elba synchronizes the user’s Okta groups, roles, and application assignments.
The reviewer investigates whether an unexpected assignment is still needed.
The identity administrator makes the required change in the Okta console.
Related capability
Before you connect
Okta setup uses two application configurations: an SSO application for administrator sign-in and a service integration with read scopes for directory synchronization.
Explore security & privacyOne application handles administrator SSO. The separate service integration provides the read-only scopes used for directory, assignment and role synchronization.
Not through the documented read-only service integration. Use the evidence in elba to investigate and complete the authoritative change in Okta.
The documented service integration uses okta.apps.read, okta.users.read, okta.roles.read and okta.groups.read.
Complete setup with an active Super Administrator or Application Administrator account, following the application instructions shown in your elba workspace.
Discuss your requirements
Review the available capabilities, required permissions, and setup for your environment with our team.