Skip to main content

Okta Organizations

Integrate Okta with Cloudaware to inventory organizations, users, groups, applications, policies, and more for identity governance reporting.

info
  • Audience: Cloudaware administrators, IAM teams, SecOps teams, and identity governance teams
  • Outcome: Okta organizations, users, groups, applications, policies, and related identity configuration are available in CMDB for governance reporting, access review, and asset correlation

Capabilities

The integration supports:

  • Read-only discovery of Okta organizations, users, groups, applications, policies, and tenant configuration
  • Relationship mappings between Okta identities, applications, and assets in the CMDB
  • Search and reporting for Okta objects using CMDB Navigator, CMDB list views, and reports

Prerequisites

Before you begin, make sure you have:

  • Access to a Cloudaware account.
  • A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
  • Okta Base URL, for example https://yourOktaOrg.com.
  • Okta API token with read permissions.

Add an Okta Organization to Cloudaware

  1. In Cloudaware, go to Admin.
  2. Find Okta Organizations, then click + ADD.
  3. Enter the following values:
    • Name: Enter a display name for the Okta organization.
    • Base URL: Enter the Okta organization URL, for example https://yourOktaOrg.com.
    • API Key: Enter the Okta API token.
  4. Click Save.
  5. Confirm that the integration status indicator is green.
tip

Allow the initial discovery cycle to complete after enabling the integration.

View Okta Organizations Data in CMDB

  1. In Cloudaware, open CMDB Navigator.
  2. In the left pane, select OKTA ORGANIZATIONS.
  3. Open the Okta user, group, application, policy, or organization object list to view records.
  4. Validate users, groups, and applications against Okta.

Supported Objects

Cloudaware ingests the following Okta Organization objects:

Okta ObjectCMDB Object API Name
Okta AgentCA10OK__CaOktaAgent__c
Okta Agent PoolCA10OK__CaOktaAgentPool__c
Okta API Service IntegrationCA10OK__CaOktaApiServiceIntegration__c
Okta ApplicationCA10OK__CaOktaApplication__c
Okta Application Group LinkCA10OK__CaOktaApplicationGroupLink__c
Okta Application User LinkCA10OK__CaOktaApplicationUserLink__c
Okta AuthenticatorCA10OK__CaOktaAuthenticator__c
Okta Authorization ServerCA10OK__CaOktaAuthorizationServer__c
Okta Authorization Server ClaimCA10OK__CaOktaAuthorizationServerClaim__c
Okta Authorization Server ClientCA10OK__CaOktaAuthorizationServerClient__c
Okta Authorization Server PolicyCA10OK__CaOktaAuthorizationServerPolicy__c
Okta Authorization Server Policy RuleCA10OK__CaOktaAuthorizationServerPolicyRule__c
Okta Authorization Server ScopeCA10OK__CaOktaAuthorizationServerScope__c
Okta Behavior RuleCA10OK__CaOktaBehaviorRule__c
Okta BrandCA10OK__CaOktaBrand__c
Okta Custom DomainCA10OK__CaOktaCustomDomain__c
Okta Custom RoleCA10OK__CaOktaCustomRole__c
Okta DeviceCA10OK__CaOktaDevice__c
Okta Device User LinkCA10OK__CaOktaDeviceUserLink__c
Okta Email DomainCA10OK__CaOktaEmailDomain__c
Okta Email ServerCA10OK__CaOktaEmailServer__c
Okta Event HookCA10OK__CaOktaEventHook__c
Okta GroupCA10OK__CaOktaGroup__c
Okta Group OwnerCA10OK__CaOktaGroupOwner__c
Okta Group RuleCA10OK__CaOktaGroupRule__c
Okta Group User LinkCA10OK__CaOktaGroupUserLink__c
Okta Identity ProviderCA10OK__CaOktaIdentityProvider__c
Okta Identity Provider User LinkCA10OK__CaOktaIdentityProviderUserLink__c
Okta Log StreamCA10OK__CaOktaLogStream__c
Okta OrganizationCA10OK__CaOktaOrganization__c
Okta PolicyCA10OK__CaOktaPolicy__c
Okta Policy Resource LinkCA10OK__CaOktaPolicyResourceLink__c
Okta Policy RuleCA10OK__CaOktaPolicyRule__c
Okta Push ProviderCA10OK__CaOktaPushProvider__c
Okta Security Event ProviderCA10OK__CaOktaSecurityEventProvider__c
Okta Security Event StreamCA10OK__CaOktaSecurityEventStream__c
Okta Trusted OriginCA10OK__CaOktaTrustedOrigin__c
Okta UserCA10OK__CaOktaUser__c
Okta User TypeCA10OK__CaOktaUserType__c

Troubleshooting

note

Initial data collection may take time to complete.

Authentication Fails or Integration Shows Red Status

  • Verify that the Okta Base URL is correct and includes the protocol, for example https://yourOktaOrg.com.
  • Confirm that the API token is valid, active, and has read permissions.
  • Check whether the Okta user or service account associated with the token is active.
  • Re-enter the API token by editing the integration in Cloudaware.

Okta Objects Are Missing

  • Allow the initial discovery cycle to complete.
  • Confirm that the API token has access to the missing users, groups, applications, policies, or organization settings.
  • Review Okta admin permissions and API token scope for the affected objects.
  • In CMDB Navigator, verify that you are viewing the OKTA ORGANIZATIONS section and related resources.

Changes in Okta Are Not Yet Visible in Cloudaware

  • Synchronization is periodic. Wait for the next collection cycle.
  • If changes remain missing, confirm that the API token can still access the changed Okta objects.
  • Review the integration status and error messages in Cloudaware Admin.

Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name and a brief description of the issue.

Reconfigure or Remove the Integration

warning

To rotate API keys or update the Okta Base URL, edit the existing integration instead of deleting and re-creating it.

Update the Integration Details

  1. Go to Admin.
  2. Select Okta Organizations.
  3. Select the specific integration.
  4. Open the three-dot menu (), then click Edit.
  5. Update the required fields.
  6. Click Save.

Remove the Integration from Cloudaware

  1. Go to Admin.
  2. Select Okta Organizations.
  3. Select the specific integration.
  4. Open the three-dot menu (), then click Delete.
  5. Confirm the deletion if prompted.

Security Notes

  • Use a dedicated Okta service account or API token with the minimum read permissions required for Cloudaware discovery.
  • Avoid using a personal administrator token for long-running integrations.
  • Store Okta API tokens only in approved credential stores and avoid sharing them through tickets, chat, or documentation.
  • Rotate API tokens according to your organization's credential-rotation policy and immediately after suspected exposure.
  • Revoke unused or replaced Okta API tokens in Okta after updating the Cloudaware integration.
  • Update the Cloudaware integration immediately if the Okta Base URL changes or the token is revoked, regenerated, or replaced.