Okta
Okta connects your directory, user accounts (including MFA enrollment) and managed devices, into Navigator.
Beta. This connector was built from Okta’s documentation and hasn’t been verified against a live account yet. It may return incomplete data or fail in ways we haven’t seen. If something looks wrong, contact support@chartingcyber.com.
At a glance
| Data provided | Users, Devices |
|---|---|
| Authentication | API token |
| Where to configure | Connectors → Add a Connector → Okta |
Required permissions
| Credential | Required access |
|---|---|
| API Token | Generated by an Okta admin account. Navigator never writes to Okta; it only reads users, devices, and factor (MFA) enrollment data. Use a custom admin role scoped to just that read access — see below. |
Prefer a custom admin role over Read-Only Administrator. Okta’s built-in Read-Only Administrator grants visibility into your entire org — every application, policy, log and configuration object — which is far more than Navigator reads. Okta supports custom admin roles with per-permission granularity, so the least-privilege setup is a dedicated role granting only:
okta.users.read— user profilesokta.devices.read— device/endpoint recordsokta.userFactors.read— MFA factor enrollment (what powers the “users without MFA” exposure metric)
scoped, if your Okta edition supports resource sets, to only the user/group resources you actually want Navigator to inventory. Read-Only Administrator still works if custom roles aren’t available on your plan — it’s just a wider grant than this integration needs, so it shouldn’t be the default recommendation.
Setup
- In the Okta Admin Console, create the custom admin role described above (Security → Administrators → Roles → Create new role), granting only the three read permissions listed, and assign it to a dedicated service account — not a personal admin account. An Okta API token inherits the permissions of the account that created it, so the token is only as least-privilege as that account is.
- As that service account, go to Security → API → Tokens and create a new token.
- Note your Okta domain (e.g.
your-org.okta.com) and the token value. - In Navigator, go to Connectors → Add a Connector → Okta.
- Enter your Okta Domain and API Token.
- Save. Navigator validates the credentials and enqueues a first sync immediately.
Vendor documentation
Okta’s own instructions: Create an API token (Okta Developer).
What data this connector provides
- Users: including real per-user MFA enrollment status and factor types, via Okta’s Factors API (filtered to active factors only).
- Devices: including a genuine per-device “managed” signal used directly as agent/MDM coverage.
- Disk encryption status is derived from Okta’s own
diskEncryptionTypefield using Okta’s documented rule (full or all-internal-volumes encryption counts as encrypted).
Known limitations
- Okta devices don’t share a common identifier with Microsoft-connector devices, so cross-connector matching for the same physical device falls back to hostname/serial/MAC overlap rather than an exact directory ID match.