How to Configure an Okta Data Source
This article provides detailed steps to set up an Okta data source for discovery.
Prerequisites
Okta credentials are required to configure an Okta Data Source. The following guides you through the necessary steps.
Note: The token will have the same permissions as the user that created it. To enable Hydden to see all the account data correctly, we suggest that a ‘Super Admin’ creates the token.
To configure an API Token in Okta, navigate to
https://[your okta tenant name].okta.com/admin/access/api/tokens
. Alternatively, login to your Okta tenant with admin credentials, and browse using the left-hand menu to SECURITY | API. Change the API page view to TOKENS.On the TOKENS view page, press the Create Token button.
On the token creation page, enter a name for the token that Hydden will use to perform its collections.
To complete the token creation workflow, press the CREATE TOKEN button.
Copy and save the Token Value, which looks something like the following:
00AReXGuJKL9r-i3HbvUj9piQc-Quc49XMZ9VYgfrf
Note, that you will not be able to view this value again after leaving the page. This value is needed on the Data Source creation page.
Make note of the Token ID, which will look something like the following:
00D234plopklal8DS5k9
.This will be the Client ID on the Data Source Credentials configuration page.
Configure Your Hydden Okta Data Source
- Login to your Hydden tenant.
- To access the data sources page, navigate to Configuration > Discover and select Data Sources or use the data source URL:
https://portal.hydden.com/configuration/datasource
. - To add the Okta data source, click + Add Data Source.
- From the drop-down, choose Okta.
- For Name enter an easy-to-identify name for the data source.
- For tenant ID, enter your Okta tenant name, i.e. bus-33563577.okta.com.
- You may ignore Preset and Schedule for now.
- To the right of Credentials, click +.
- The Add credential modal opens and the drop-down selection should show Cloud credential. If not, change it to Cloud credential.
- Enter a name for your Okta credential.
- Enter the client ID and Secret from your Okta API Token as previously saved/vaulted.
- Click Add.
- On the Add Data Source modal, click Add to save the newly created data source.
At this point, you can run a collection from the Data Sources page and shortly after, you will see your Okta users listed on the Identity Posture dashboard, in Global Search and the Search Library.