# Okta integration overview

> Three ways to use Persona with Okta: trigger verification in Okta policies, call the Okta API from Workflows, or use Persona as an OIDC identity provider.

Source: https://help.withpersona.com/articles/4w8cDQLPuaPAadq4LzhO40/
Section: Marketplace and 3rd-Party Integrations > Authentication > Okta

## Overview

[Okta](https://www.okta.com/) is an Identity and access management (IAM) platform that centralizes and secures user access to applications and services. It acts as a central, secure hub that allows users to log in to multiple apps with a single set of credentials (SSO) while giving IT teams centralized control over access and security.

With Persona’s Okta integration, you can seamlessly embed identity verification throughout the employee lifecycle — from onboarding to account recovery — to protect against phishing, social engineering, and deepfake attacks.

Organizations can:

- Trigger identity verification during critical moments (e.g., onboarding, password resets, authenticator enrollments)
- Pull user profile data from Okta to enrich verification workflows
- Automate account actions like resetting MFA factors or suspending users— without leaving Okta

This integration helps IT and InfoSec teams reduce account takeover risk, streamline account recovery, and deliver faster, more secure access for employees — while maintaining data compliance and supporting distributed teams.

## Integration Options

Persona offers three ways to integrate with Okta:

1.  [Persona for Identity Verification (IDV) in Okta](https://help.withpersona.com/articles/x7vPGY4te68wp1T0Ce5eFi/)
2.  [Persona's Okta API marketplace integration](https://help.withpersona.com/articles/2MTecveKOnadYlNqOY4BFr/)
3.  [Persona as an Identity Provider (IdP) authenticator](https://help.withpersona.com/articles/3ZFkLLXBFVACuqlwQbUcFG/)

Only options 1 and 3 trigger identity verification. The Okta API marketplace integration is a Workflows integration for reading Okta profile data and taking account actions, and it layers on top of either identity verification method above; see "Choosing your integration method" below to decide between options 1 and 3.

Note: For Okta SCIM and SSO provisioning, please refer to the following articles:

1.  [Setting up Okta SCIM](https://help.withpersona.com/articles/SJ40Iy2cK2nuY40JthHqS/)
2.  [Enabling SAML-based single sign-on (SSO) with Okta for Persona Dashboard](https://help.withpersona.com/articles/3A0ZoW5ozu1k17n7bOrVuE/)

## Choosing your integration method

Before you set up either integration, decide which Okta policies you need Persona to protect.

### Okta policy types

Okta has two kinds of authentication policies where Persona can be used:

- **[Account Management Policies](https://help.okta.com/oie/en-us/content/topics/identity-engine/policies/oamp.htm) (OAMP)**: authentication requirements for enrolling or unenrolling authenticators, resetting a password, or unlocking an account. Example triggers: clicking "Forgot password," activating a new account, or enrolling a new authenticator.
- **[App sign-in policies](https://help.okta.com/oie/en-us/content/topics/identity-engine/policies/about-app-sign-on-policies.htm)**: how a user must authenticate to access an app. Example trigger: signing in to Jira via SSO.

### Identity Verification vs. IdP authenticator

[Persona for Identity Verification (IDV) in Okta](https://help.withpersona.com/articles/x7vPGY4te68wp1T0Ce5eFi/) triggers identity proofing just-in-time, only when an employee takes an action a policy protects. An employee who never takes a protected action never sees Persona, and there's no enrollment step. This method only works with OAMP.

[Persona as an Identity Provider (IdP) authenticator](https://help.withpersona.com/articles/3ZFkLLXBFVACuqlwQbUcFG/) requires an employee to enroll in Persona (complete an inquiry) before an authentication policy can use it as a factor. Okta admins can require enrollment, in which case an employee enrolls the next time they sign in. This method works with both OAMP and app sign-in policies.

The tradeoff: an employee who hasn't enrolled in the IdP authenticator can't use it as a factor. If password reset is gated behind the IdP authenticator and an employee never enrolled, they can't self-serve a reset from the "Forgot password" link.

⚠️

Don't gate authenticator enrollment behind an Account Management Policy that requires Persona as the IdP authenticator. An employee who hasn't enrolled yet would have no way to complete the enrollment that policy is protecting.

### Feature comparison

| Feature             | Persona IDV                             | Persona as an IdP authenticator                      |
| ------------------- | --------------------------------------- | ---------------------------------------------------- |
| Supported policies  | Account Management Policies (OAMP) only | Account Management Policies and app sign-in policies |
| Enrollment required | No                                      | Yes                                                  |

### Which method should I use?

| If you want to protect                                                                      | Use                                                                                                                                                                                                                                                                                     |
| ------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Only Account Management Policies (password reset, authenticator enrollment, account unlock) | Persona for Identity Verification (IDV). No authenticator enrollment needed.                                                                                                                                                                                                            |
| App sign-in policies (for example, requiring verification to sign in to an app)             | Persona as an IdP authenticator. Only authenticators are eligible for app sign-in policies.                                                                                                                                                                                             |
| Both                                                                                        | Either. Many customers start with Persona IDV for Account Management Policies and add the IdP authenticator later, since the two are compatible. A customer who wants both from the start can use the IdP authenticator alone, but must require enrollment for every employee up front. |

If you plan to use both integration methods, talk to your Persona account team before turning on the second one, so your Persona accounts stay linked to the right employee instead of creating duplicates.

## Plans Explained

### Okta Integration by plan

|                  | Startup Program | Essential Plan | Growth Plan | Enterprise Plan |
| ---------------- | --------------- | -------------- | ----------- | --------------- |
| Okta Integration | Not Available   | Not Available  | Limited     | Available       |

[Learn more about pricing and plans](https://withpersona.com/pricing?utm_source=product&utm_medium=referral&utm_audience=a&utm_campaign=cm_gen_ds_hc-plan-table).

_Last updated on August 20, 2026._
