Okta connector
This connector can be run in the cloud or using an on-premises connector server.
The Okta connector gathers data about users from the Okta Identity Cloud.
Required Permissions for the Okta Connector
To import data from Okta, the connector requires an Okta API token generated by an account that has read access to the following Okta objects:
-
Users
-
Applications
-
System Logs, including sign-in and single sign-on (SSO) events used for usage reporting.
An account assigned the Read-Only Administrator role provides sufficient permissions for standard connector operations. The connector only reads data from Okta and does not require the Super Admin role.
Certain Okta-managed applications can be accessed only by accounts assigned the Super Admin role. These applications include:
-
Okta Dashboard
-
Okta Browser Plugin
-
Okta Admin Console
When the connector uses an API token generated by a Read-Only Administrator account, the connector logs might contain access-denied errors for these applications. These errors are expected and can be safely ignored because the restricted applications are not used for SaaS discovery or license usage tracking.
For information about what data is imported and how it is mapped, see Mapping (below).
Options
An Okta connector has the following options:
- Connector name: A name for the connector.
- Connector server name: The name of the connector server that this connector is associated with. When running the connector in the cloud, this server needs to be the Cloud option in the list.
Each connector can only be associated with one connector server. If you added this connector to a specific connector server (on the Connectors > Connector Servers page), this field will be populated for you. Otherwise, you can select the server from the list. - Okta URL: Your company's custom Okta URL.
- Okta API token: An API token associated with your Okta instance. For information about creating an API token, see Create an API token in the Okta documentation.
- User status: The types of users to import. If a user's status changes to a type that isn't selected, they will be removed the next time the connector runs.
- Repeats: How often the connector should gather data.
- Start time: The time of day the connector should start running. To minimize the impact on your network and applications, we recommend that connectors generally run at night or on weekends.
- Active: Whether the connector is active or not. While the connector is active, it runs according to the schedule you create. If you clear the check box, the connector is inactive and will not gather data until the check box is enabled again and the connector is saved.
For details on configuring or using connectors, see Connectors.
Mapping
The data that this connector imports is mapped to target attributes in the Neurons database.
For an overview of how the data imported by this connector is mapped to the Neurons target attributes, please download the CSV file using the button below.
For an overview of the Neurons target attributes per data type and the connector source attributes that are mapped to them, see Connector data mapping.