Overview
Okta is a leading identity and access management (IAM) platform. Organizations use it to protect workforce access to applications. The Persona Okta marketplace integration connects to your Okta tenant. You can then get detailed user profile data and do account actions directly in Persona Workflows.
This integration helps Compliance, IT, and People Ops teams work faster. It syncs important attributes, including custom profile fields. It also automates account lifecycle actions, for example resetting MFA factors or suspending and unsuspending users. Teams do not have to change tools.
Benefits
Unified Employee Context: Show Okta profile attributes in Persona, including custom fields such as legal name or date of birth. This decreases manual searches and mismatches.
Reduced Manual Work: Replace repetitive admin tasks with workflows that you can use again. These workflows run the same way every time, at large volume.
Fewer Verification Hurdles: Automatically use the correct identity information from Okta, for example the legal name and not the preferred name. This increases verification success and decreases manual fixes.
Integration Features
The Persona Okta integration gets data in real time and does direct account actions. These features give secure, two-way workflows between Persona and Okta.
- Retrieve User Profile: Finds an Okta user and returns standard and custom attributes. These attributes add data to Persona Workflows and Cases.
- Update User: Updates the profile or credentials of a user.
- Expire Password and Generate a Temporary Password: Expires the current password of a user. Returns a temporary password from Okta for the next sign-in of the user.
- Reset All MFA Factors: Removes all enrolled authenticators for a user. The user must enroll again at the next sign-in. This is useful after high-risk events.
- Suspend User: Temporarily stops access for an Okta user during an investigation.
- Unsuspend User: Gives access again to a suspended user after the investigation clears them.
Setting up the Okta integration
Prerequisites
Make sure that you have:
- Admin access to your Okta account.
- The necessary API permissions to access Okta credentials.
You can use an Okta API Service or an Okta API key to connect Okta to Persona. To select an authentication method, read the FAQs.
Option A: Connect via API Service
Do these steps to configure the Private Key JWT Authentication method.
-
In Okta Admin, create an API Services app. Go to Applications and Resources > Applications. Click
Create App Integrationand select theAPI Servicesoption.- Give the application a name and save it. Copy the Client ID that Okta generates to your clipboard.
-
In the Persona Dashboard, go to Integrations > Marketplace > Okta.
- Click
+ Add Credential. SelectOkta API Service. - Enter your Okta tenant information. Paste the Client ID from the API Service that you created.
- When you save, you get a JWKS URL. You give this URL to Okta in the next step.
- Click
-
In Okta Admin, go back to the API Service that you created in Step 1. On the General tab, make these edits:
Section Edits to make Client Credentials • Set Client authentication to Public key / Private keyPublic Keys • Select the Use a URL to fetch keys dynamicallyconfiguration option
• Paste in the JWKS URL from the Persona dashboard in the Url fieldGeneral Settings • Uncheck the Require Demonstrating Proof of Possession (DPoP) header in token requestscheckbox -
Go to the Okta API Scopes tab. Grant the scopes that your integration needs. At a minimum, grant
okta.users.readto get user information. The table below shows scopes that customers frequently grant. Grant only the scopes that you need.Okta API Scope Affected Okta API Endpoints okta.users.read: Read User’s Info List all users; Retrieve a user; List all groups for a user okta.users.manage: Manage User’s Info Update a user; Activate a user; Deactivate a user; Reactivate a user; Expire a password and generate a temporary password; Reset all factors for a user; Suspend a user; Unlock a user account; Unsuspend a user; Generate a temporary access code for a user okta.authenticators.read: Read Authenticators List all authenticators; Retrieve an authenticator -
Next, assign an admin role and a resource set to your service app. These define which actions the app can do and which Okta resources it can access. At a minimum, your admin role must have the permission to
Retrieve a user. Your resource set must includeAll users, or all users that you plan to access through Persona. Other permissions and resources change with your use case.If you already have a role and a resource set, assign them in the Admin roles tab of your service app. Then go to the next step.
To create a new role and resource set:
-
Go to Security > Administrators.
-
Click the Roles tab. Click
Create new role. -
Set Role name to
Persona Okta Integration Roleor a similar title. -
Grant permissions for the endpoints that you use. Grant only the permissions that your integration use case requires. For help, use the table below or Okta’s permissions catalog.
Role permissions by Okta API endpoint
Okta API Endpoint Required Role Permissions List all users User > View users and their details or Edit users’ profile attributes Retrieve a user User > View users and their details or Edit users’ profile attributes Update a user User > Edit users’ profile attributes Activate a user User > Edit users’ lifecycle states > Activate user Deactivate a user User > Edit users’ lifecycle states > Deactivate users Reactivate a user User > Edit users’ lifecycle states > Activate users Expire a password and generate a temporary password User > Set users’ temporary password Reset all factors for a user User > Reset users’ authenticator Suspend a user User > Edit users’ lifecycle states > Suspend users Unlock a user account User > Edit users’ lifecycle states > Unlock users Unsuspend a user User > Edit users’ lifecycle states > Unsuspend users List groups for a user User > View users and their details; Group > View groups and their details List all authenticators None Retrieve an authenticator None Generate a temporary access code for a user User > Edit users’ authenticator operations > Manage user’s temporary access code -
Click the Resources tab. Click
Create new resource set. -
Set Name to
Persona Okta Integration Resource Setor a similar title. -
Click
+ Add resource. Search forUsersand selectAll users. -
Go back to your application at Applications > Applications. Click the Admin roles tab. Click
Edit assignments. Select your newPersona Okta Integration Rolerole and your newPersona Okta Integration Resource Setresource set. Save your changes.
-
-
After you connect, click
Testin the Persona dashboard. Make sure that the credential works.
Option B: Connect via API key
- Create an API token in Okta Admin.
- Go to Security > API > Tokens >
Create Token. - Copy the API token.
- Note: In this article, “API key” and “API token” have the same meaning.
- Go to Security > API > Tokens >
- Add the API token as a credential in Persona.
- Go to Persona Dashboard > Integrations > Marketplace > Okta > Add Credential >
Okta API Key Credential. - Enter your Okta subdomain. Give the credential a nickname. Paste the token.
- Go to Persona Dashboard > Integrations > Marketplace > Okta > Add Credential >
- After you connect, click
Test. Make sure that the credential works.
Persona does not support OAuth 2.0 for our Okta integration. Okta OAuth 2.0 credentials have a maximum lifetime of 90 days, and you cannot extend it. Thus, they are not applicable for long-lived integrations. This authorization scheme is not for machine-to-machine communication. It causes integration errors.
Using the Okta integration in a workflow
- Create a new workflow, or open an existing workflow that you want to update.
- Add a new Action step > Integrations.
- Select the Okta integration. Select your Okta credential.
- Configure the inputs, for example the user identifier and the action. Map outputs to Persona fields as necessary.
- Save and publish the workflow.
Okta Operations Overview
Persona can sync field values. Persona can also use the Okta API to do these actions:
- Get user profiles.
- Issue temporary passwords.
- Reset MFA factors.
- Suspend or unsuspend users.
These actions give two-way workflows. Teams can manage investigations and not change platforms. Below is a full list of the Workflow Action steps and configurations for the Okta integration:
Retrieve a user
Gets the profile of an Okta user and puts the values in Workflow variables in Persona.
Configuration Steps:
- Provide values for required fields:
- ID of the user to retrieve.
- Provide values for optional fields:
- Fields to include: limits the result to the listed properties, for example
status,profile:(login,email). Use commas to separate properties. Profile attributes use the formatprofile:(firstName,lastName). You can select custom profile attributes in the same way. The result always includes theidof the user. Persona sends the selection to Okta, so fields that you do not select never leave Okta. Persona also applies the same selection to the response. Thus, Persona does not return fields that you do not select, and does not keep them in the Workflow integration log. If you leave this field empty, the result includes all fields.
- Fields to include: limits the result to the listed properties, for example
Update a user
Updates the profile or credentials of an Okta user. You can use this action to reset the password of the user.
Configuration Steps:
- Provide values for required fields:
- ID of the user to reset.
- Request body that includes the attributes to update. For the request body schema, read Okta’s documentation.
Activate a user
Configuration Steps:
- Provide values for required fields:
- ID of the user to activate.
Deactivate a user
Configuration Steps:
- Provide values for required fields:
- ID of the user to deactivate.
Reactivate a user
Configuration Steps:
- Provide values for required fields:
- ID of the user to reactivate.
Reset all factors for a user
Removes all enrolled MFA authenticators for the specified user. The user must enroll again at the next sign-in. Teams frequently use this action after a high-risk event, or when they think that devices are compromised.
Configuration Steps:
- Provide values for required fields:
- ID of the user to reset.
Suspend a user
Temporarily stops the access of a user during an investigation. A suspended user cannot access apps that Okta protects until you unsuspend the user.
Configuration Steps:
- Provide values for required fields:
- ID of the user to suspend.
Unlock a user account
Unlocks a user who is locked out. Also unlocks an active user that Okta blocks from unknown devices. Unlocked users have an ACTIVE status and can sign in with their current password.
Configuration Steps:
- Provide values for required fields:
- ID of the user to unlock.
Unsuspend a user
Gives access again to a suspended user. Enter the user identifier to put the user back in an active state. Access then starts again as your Okta policies specify. Teams usually use this action after an investigation ends or after they resolve false positives. This keeps the effect on legitimate users small.
Configuration Steps:
- Provide values for required fields:
- ID of the user to unsuspend.
List groups for a user
Lists all groups that the user is a member of.
Configuration Steps:
- Provide values for required fields:
- ID of the user.
FAQs
When should I use an API service vs. an API key?
An API service is a service account for service-to-service communication. API service credentials use Private Key JWT authentication. This gives more security than API keys. You configure the capabilities on the service. They are not connected to a specific Okta user.
An API key is a unique, secret code. Applications use it to access an API. An API key is like a master key that you generate in Okta and give to Persona. An API key has the same capabilities as the Okta user who issued it. If someone deactivates that user, the API key stops working.
Persona recommends API services for our Okta integration. Persona recommends API keys only for tests. Okta API services give durable credentials. Their capabilities are not connected to a specific user account. Thus, the integration is more reliable, more secure, and easier to manage. API keys are less secure. A person who has the key can send requests to Okta for you, usually with broad permissions.
What happens when I reset all factors?
Okta clears all MFA enrollments for the user. At the next sign-in, Okta tells the user to enroll factors again, as your Okta policies specify.
Plans Explained
Okta Integration by plan
| Startup Program | Essential Plan | Growth Plan | Enterprise Plan | |
|---|---|---|---|---|
| Okta Integration | Not Available | Not Available | Limited | Available |