Okta Common Questions
How does your software help address vulnerability at the password level? - answer With
Okta, you can eliminate password re-use across all of your enterprises cloud
applications. You can also strengthen the security of your users by adding 2 factor
authentication (MFA).
What does Okta do? (Internal) – answer Okta is enterprise grade identity and access
management. We enable seamless and secure access for all of your users into every
application, on any device, in every location. Okta provides single sign on into all of your
web-facing applications, provisions and de-provisons users to and from applications,
provides an extra layer of security with strong authentication offered in our own MFA
solution as well as 3rd party integrations, and extends your desktop applications to
mobile devices safely and securely.
What does Okta do? (External) – answer Okta can be used for externally facing sites
such as B2B portals, supplier portals, eCommerce sites, distributor portals, etc. to
enable self-registration of users, store these users in a homegrown user store in the
cloud, and federate that identity across all of your sites/apps.
How do you integrate with AD? - answerOkta uses a lightweight agent to connect to
your active directory. From there, Okta is able to provision applications to users. Also,
because the Okta service syncs with your AD, your users can authenticate into Okta
using their AD credentials. Furthermore, if your security personell allows it - your users
can even reset their AD password from Okta.
How do you work with my VPN? - answerVirtual Private Network. Integrate directly with
a SAML so that the user can access their apps with a single sign on.
How are you different from One Login? - answerWe are able to integrate AD groups
automatically while use one login this process has to be done manually. One login tends
to have more downtime. Okta has on premise automatic provisioning and de-
provisioning. Okta has more advanced integrations than one login. Not only that One
log lacks the depth and number of enterprise customers when compared to Okta. Okta
is the leader in cloud identity and access management. In addition lead cloud
companies are also utilizing our service essentially validating the overall success of our
services. Okta has has a much higher up time.
How do you simplify the O365 implementation/rollout? - answerOffice 365 is one of our
most deeply integrated applications and one of our most widely utilized. Our seem-less
integration with an existing active directory or LDAP will make the transition to SSO for
O365 and other applications as simple as possible. Okta can also use existing groups
with the AD essentially removing the need to manually create groups again. Through
, this lightweight integration a user can can sign on to any of O365's wide array of
service, from anywhere and from any device.
Do I have to store my users in the cloud? - answerYes and No. Okta's service is built
out to be flexibile to match the different requirements of our customers. Some of our
customers do not want to maintain any hardware therefore they use Okta as their user
store. This is simple for them because they can manage all their users from one
platform. Then there are some other customers who prefer not storing information in the
cloud because they are not completely comfortable with storing their directory
information in the cloud. For these customers, we have a directory agent. This agent
connects to something like an Active Directory and maintains a connection with Okta
through port 443. It is important to note that this is an outbound connection therefore no
information is extracted. Imagine it as if Okta was coming to your door, knocking and
asking if John Doe was allowed access to your applications. Based on your answer of
yes or no, Okta would grant John Doe access. (AAA)N
What is Secure Web Authentication (SWA) and how does it compare to SAML? -
answerSecure Web Authentication is the most basic type of authentication. The idea is
to programmatically go to the login page of the application and submit the credentials as
if the end user is actually logging in. This is also known as "Form Submit" and "Screen
Scraping". SAML is a Federated SSO protocol. In SAML, the application does not
receive a password from the user. Instead, a trusted identity provider authenticates a
user and sends a SAML assertion to the application to "assert" the identity
of the user. IT folks like SAML because they do not need to worry about setting up
passwords for users - nor do the end users have to worry about their passwords for
these applications. (SD)
How do you work with ServiceNow (admin-mgr asking)? - answerOkta Cloud Connect
for ServiceNow is a purpose-built solution that seamlessly integrates ServiceNow with
Active Directory. Enabling automated user management for ServiceNow is equally
simple. Through the ServiceNow User Management configuration in Okta,
administrators can complete integration in minutes to enable account provisioning and
de-provisioning between AD and your ServiceNow instance.
How do you work with ServiceNow (VP, C level asking)? - answerOkta has the ability to
automate workflow within ServiceNow. When an application request is made within
ServiceNow, your ServiceNow admin will have the option to click a button that is tied
into Okta and will automatically provision the user the application. In doing so you will
not only see a higher ROI in your application usage, but also a simplified process that
will save both your end users and admins valuable time. (Kyle)
How do you work with Workday (admin-mgr asking)? - answerOkta enables your on-
boarding process to be simplified. With Okta you can create a user in Workday, use
Workday as the master for application access, org charts, group affiliations, etc., while
simultaneously having the Okta service creating the same account in AD. No longer will
your HR and IT identities be separate. (Janice)
How does your software help address vulnerability at the password level? - answer With
Okta, you can eliminate password re-use across all of your enterprises cloud
applications. You can also strengthen the security of your users by adding 2 factor
authentication (MFA).
What does Okta do? (Internal) – answer Okta is enterprise grade identity and access
management. We enable seamless and secure access for all of your users into every
application, on any device, in every location. Okta provides single sign on into all of your
web-facing applications, provisions and de-provisons users to and from applications,
provides an extra layer of security with strong authentication offered in our own MFA
solution as well as 3rd party integrations, and extends your desktop applications to
mobile devices safely and securely.
What does Okta do? (External) – answer Okta can be used for externally facing sites
such as B2B portals, supplier portals, eCommerce sites, distributor portals, etc. to
enable self-registration of users, store these users in a homegrown user store in the
cloud, and federate that identity across all of your sites/apps.
How do you integrate with AD? - answerOkta uses a lightweight agent to connect to
your active directory. From there, Okta is able to provision applications to users. Also,
because the Okta service syncs with your AD, your users can authenticate into Okta
using their AD credentials. Furthermore, if your security personell allows it - your users
can even reset their AD password from Okta.
How do you work with my VPN? - answerVirtual Private Network. Integrate directly with
a SAML so that the user can access their apps with a single sign on.
How are you different from One Login? - answerWe are able to integrate AD groups
automatically while use one login this process has to be done manually. One login tends
to have more downtime. Okta has on premise automatic provisioning and de-
provisioning. Okta has more advanced integrations than one login. Not only that One
log lacks the depth and number of enterprise customers when compared to Okta. Okta
is the leader in cloud identity and access management. In addition lead cloud
companies are also utilizing our service essentially validating the overall success of our
services. Okta has has a much higher up time.
How do you simplify the O365 implementation/rollout? - answerOffice 365 is one of our
most deeply integrated applications and one of our most widely utilized. Our seem-less
integration with an existing active directory or LDAP will make the transition to SSO for
O365 and other applications as simple as possible. Okta can also use existing groups
with the AD essentially removing the need to manually create groups again. Through
, this lightweight integration a user can can sign on to any of O365's wide array of
service, from anywhere and from any device.
Do I have to store my users in the cloud? - answerYes and No. Okta's service is built
out to be flexibile to match the different requirements of our customers. Some of our
customers do not want to maintain any hardware therefore they use Okta as their user
store. This is simple for them because they can manage all their users from one
platform. Then there are some other customers who prefer not storing information in the
cloud because they are not completely comfortable with storing their directory
information in the cloud. For these customers, we have a directory agent. This agent
connects to something like an Active Directory and maintains a connection with Okta
through port 443. It is important to note that this is an outbound connection therefore no
information is extracted. Imagine it as if Okta was coming to your door, knocking and
asking if John Doe was allowed access to your applications. Based on your answer of
yes or no, Okta would grant John Doe access. (AAA)N
What is Secure Web Authentication (SWA) and how does it compare to SAML? -
answerSecure Web Authentication is the most basic type of authentication. The idea is
to programmatically go to the login page of the application and submit the credentials as
if the end user is actually logging in. This is also known as "Form Submit" and "Screen
Scraping". SAML is a Federated SSO protocol. In SAML, the application does not
receive a password from the user. Instead, a trusted identity provider authenticates a
user and sends a SAML assertion to the application to "assert" the identity
of the user. IT folks like SAML because they do not need to worry about setting up
passwords for users - nor do the end users have to worry about their passwords for
these applications. (SD)
How do you work with ServiceNow (admin-mgr asking)? - answerOkta Cloud Connect
for ServiceNow is a purpose-built solution that seamlessly integrates ServiceNow with
Active Directory. Enabling automated user management for ServiceNow is equally
simple. Through the ServiceNow User Management configuration in Okta,
administrators can complete integration in minutes to enable account provisioning and
de-provisioning between AD and your ServiceNow instance.
How do you work with ServiceNow (VP, C level asking)? - answerOkta has the ability to
automate workflow within ServiceNow. When an application request is made within
ServiceNow, your ServiceNow admin will have the option to click a button that is tied
into Okta and will automatically provision the user the application. In doing so you will
not only see a higher ROI in your application usage, but also a simplified process that
will save both your end users and admins valuable time. (Kyle)
How do you work with Workday (admin-mgr asking)? - answerOkta enables your on-
boarding process to be simplified. With Okta you can create a user in Workday, use
Workday as the master for application access, org charts, group affiliations, etc., while
simultaneously having the Okta service creating the same account in AD. No longer will
your HR and IT identities be separate. (Janice)