Okta Organizations
Integrate Okta with Cloudaware to inventory organizations, users, groups, applications, policies, and more for identity governance reporting.
info
- Audience: Cloudaware administrators, IAM teams, SecOps teams, and identity governance teams
- Outcome: Okta organizations, users, groups, applications, policies, and related identity configuration are available in CMDB for governance reporting, access review, and asset correlation
Capabilities
The integration supports:
- Read-only discovery of Okta organizations, users, groups, applications, policies, and tenant configuration
- Relationship mappings between Okta identities, applications, and assets in the CMDB
- Search and reporting for Okta objects using CMDB Navigator, CMDB list views, and reports
Prerequisites
Before you begin, make sure you have:
- Access to a Cloudaware account.
- A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
- Okta Base URL, for example
https://yourOktaOrg.com. - Okta API token with read permissions.
Add an Okta Organization to Cloudaware
- In Cloudaware, go to Admin.
- Find Okta Organizations, then click + ADD.
- Enter the following values:
- Name: Enter a display name for the Okta organization.
- Base URL: Enter the Okta organization URL, for example
https://yourOktaOrg.com. - API Key: Enter the Okta API token.
- Click Save.
- Confirm that the integration status indicator is green.
tip
Allow the initial discovery cycle to complete after enabling the integration.
View Okta Organizations Data in CMDB
- In Cloudaware, open CMDB Navigator.
- In the left pane, select OKTA ORGANIZATIONS.
- Open the Okta user, group, application, policy, or organization object list to view records.
- Validate users, groups, and applications against Okta.
Supported Objects
Cloudaware ingests the following Okta Organization objects:
| Okta Object | CMDB Object API Name |
|---|---|
| Okta Agent | CA10OK__CaOktaAgent__c |
| Okta Agent Pool | CA10OK__CaOktaAgentPool__c |
| Okta API Service Integration | CA10OK__CaOktaApiServiceIntegration__c |
| Okta Application | CA10OK__CaOktaApplication__c |
| Okta Application Group Link | CA10OK__CaOktaApplicationGroupLink__c |
| Okta Application User Link | CA10OK__CaOktaApplicationUserLink__c |
| Okta Authenticator | CA10OK__CaOktaAuthenticator__c |
| Okta Authorization Server | CA10OK__CaOktaAuthorizationServer__c |
| Okta Authorization Server Claim | CA10OK__CaOktaAuthorizationServerClaim__c |
| Okta Authorization Server Client | CA10OK__CaOktaAuthorizationServerClient__c |
| Okta Authorization Server Policy | CA10OK__CaOktaAuthorizationServerPolicy__c |
| Okta Authorization Server Policy Rule | CA10OK__CaOktaAuthorizationServerPolicyRule__c |
| Okta Authorization Server Scope | CA10OK__CaOktaAuthorizationServerScope__c |
| Okta Behavior Rule | CA10OK__CaOktaBehaviorRule__c |
| Okta Brand | CA10OK__CaOktaBrand__c |
| Okta Custom Domain | CA10OK__CaOktaCustomDomain__c |
| Okta Custom Role | CA10OK__CaOktaCustomRole__c |
| Okta Device | CA10OK__CaOktaDevice__c |
| Okta Device User Link | CA10OK__CaOktaDeviceUserLink__c |
| Okta Email Domain | CA10OK__CaOktaEmailDomain__c |
| Okta Email Server | CA10OK__CaOktaEmailServer__c |
| Okta Event Hook | CA10OK__CaOktaEventHook__c |
| Okta Group | CA10OK__CaOktaGroup__c |
| Okta Group Owner | CA10OK__CaOktaGroupOwner__c |
| Okta Group Rule | CA10OK__CaOktaGroupRule__c |
| Okta Group User Link | CA10OK__CaOktaGroupUserLink__c |
| Okta Identity Provider | CA10OK__CaOktaIdentityProvider__c |
| Okta Identity Provider User Link | CA10OK__CaOktaIdentityProviderUserLink__c |
| Okta Log Stream | CA10OK__CaOktaLogStream__c |
| Okta Organization | CA10OK__CaOktaOrganization__c |
| Okta Policy | CA10OK__CaOktaPolicy__c |
| Okta Policy Resource Link | CA10OK__CaOktaPolicyResourceLink__c |
| Okta Policy Rule | CA10OK__CaOktaPolicyRule__c |
| Okta Push Provider | CA10OK__CaOktaPushProvider__c |
| Okta Security Event Provider | CA10OK__CaOktaSecurityEventProvider__c |
| Okta Security Event Stream | CA10OK__CaOktaSecurityEventStream__c |
| Okta Trusted Origin | CA10OK__CaOktaTrustedOrigin__c |
| Okta User | CA10OK__CaOktaUser__c |
| Okta User Type | CA10OK__CaOktaUserType__c |
Troubleshooting
note
Initial data collection may take time to complete.
Authentication Fails or Integration Shows Red Status
- Verify that the Okta Base URL is correct and includes the protocol, for example
https://yourOktaOrg.com. - Confirm that the API token is valid, active, and has read permissions.
- Check whether the Okta user or service account associated with the token is active.
- Re-enter the API token by editing the integration in Cloudaware.
Okta Objects Are Missing
- Allow the initial discovery cycle to complete.
- Confirm that the API token has access to the missing users, groups, applications, policies, or organization settings.
- Review Okta admin permissions and API token scope for the affected objects.
- In CMDB Navigator, verify that you are viewing the OKTA ORGANIZATIONS section and related resources.
Changes in Okta Are Not Yet Visible in Cloudaware
- Synchronization is periodic. Wait for the next collection cycle.
- If changes remain missing, confirm that the API token can still access the changed Okta objects.
- Review the integration status and error messages in Cloudaware Admin.
Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name and a brief description of the issue.
Reconfigure or Remove the Integration
warning
To rotate API keys or update the Okta Base URL, edit the existing integration instead of deleting and re-creating it.
Update the Integration Details
- Go to Admin.
- Select Okta Organizations.
- Select the specific integration.
- Open the three-dot menu (⋮), then click Edit.
- Update the required fields.
- Click Save.
Remove the Integration from Cloudaware
- Go to Admin.
- Select Okta Organizations.
- Select the specific integration.
- Open the three-dot menu (⋮), then click Delete.
- Confirm the deletion if prompted.
Security Notes
- Use a dedicated Okta service account or API token with the minimum read permissions required for Cloudaware discovery.
- Avoid using a personal administrator token for long-running integrations.
- Store Okta API tokens only in approved credential stores and avoid sharing them through tickets, chat, or documentation.
- Rotate API tokens according to your organization's credential-rotation policy and immediately after suspected exposure.
- Revoke unused or replaced Okta API tokens in Okta after updating the Cloudaware integration.
- Update the Cloudaware integration immediately if the Okta Base URL changes or the token is revoked, regenerated, or replaced.