Skip to main content

Okta

Okta connects your directory, user accounts (including MFA enrollment) and managed devices, into Navigator.

Beta. This connector was built from Okta’s documentation and hasn’t been verified against a live account yet. It may return incomplete data or fail in ways we haven’t seen. If something looks wrong, contact support@chartingcyber.com.

At a glance

Data providedUsers, Devices
AuthenticationAPI token
Where to configureConnectors → Add a Connector → Okta

Required permissions

CredentialRequired access
API TokenGenerated by an Okta admin account. Navigator never writes to Okta; it only reads users, devices, and factor (MFA) enrollment data. Use a custom admin role scoped to just that read access — see below.

Prefer a custom admin role over Read-Only Administrator. Okta’s built-in Read-Only Administrator grants visibility into your entire org — every application, policy, log and configuration object — which is far more than Navigator reads. Okta supports custom admin roles with per-permission granularity, so the least-privilege setup is a dedicated role granting only:

  • okta.users.read — user profiles
  • okta.devices.read — device/endpoint records
  • okta.userFactors.read — MFA factor enrollment (what powers the “users without MFA” exposure metric)

scoped, if your Okta edition supports resource sets, to only the user/group resources you actually want Navigator to inventory. Read-Only Administrator still works if custom roles aren’t available on your plan — it’s just a wider grant than this integration needs, so it shouldn’t be the default recommendation.

Setup

  1. In the Okta Admin Console, create the custom admin role described above (Security → Administrators → Roles → Create new role), granting only the three read permissions listed, and assign it to a dedicated service account — not a personal admin account. An Okta API token inherits the permissions of the account that created it, so the token is only as least-privilege as that account is.
  2. As that service account, go to Security → API → Tokens and create a new token.
  3. Note your Okta domain (e.g. your-org.okta.com) and the token value.
  4. In Navigator, go to Connectors → Add a Connector → Okta.
  5. Enter your Okta Domain and API Token.
  6. Save. Navigator validates the credentials and enqueues a first sync immediately.

Vendor documentation

Okta’s own instructions: Create an API token (Okta Developer).

What data this connector provides

  • Users: including real per-user MFA enrollment status and factor types, via Okta’s Factors API (filtered to active factors only).
  • Devices: including a genuine per-device “managed” signal used directly as agent/MDM coverage.
  • Disk encryption status is derived from Okta’s own diskEncryptionType field using Okta’s documented rule (full or all-internal-volumes encryption counts as encrypted).

Known limitations

  • Okta devices don’t share a common identifier with Microsoft-connector devices, so cross-connector matching for the same physical device falls back to hostname/serial/MAC overlap rather than an exact directory ID match.