Book Image

Okta Administration Up and Running - Second Edition

By : HenkJan de Vries, Lovisa Stenbäcken Stjernlöf
Book Image

Okta Administration Up and Running - Second Edition

By: HenkJan de Vries, Lovisa Stenbäcken Stjernlöf

Overview of this book

Identity and access management (IAM) is a set of policies and technologies used to ensure an organization’s security, by carefully assigning roles and access to users and devices. This book will get you up and running with Okta, an IAM service that can help you manage both employees and customers. The book begins by helping you understand how Okta can be used as an IAM platform, before teaching you about Universal Directory and how to integrate with other directories and apps, as well as set up groups and policies for Joiner, Mover, and Leaver flows. This updated edition helps you to explore agentless desktop single sign-on (SSO) and multifactor authentication (MFA) solutions, and showing how to utilize Okta to meet NIST requirements. The chapters also walk you through Okta Workflows, low-/no-code automation functionalities, and custom API possibilities used to improve lifecycle management. Finally, you’ll delve into API access auditing and management, where you’ll discover how to leverage Advanced Server Access (ASA) for your cloud servers. By the end of this book, you’ll have learned how to implement Okta to enhance your organization's security and be able to use the book as a reference guide for the Okta certification exam.
Table of Contents (14 chapters)
1
Part 1:Getting Started with Okta
8
Part 2: Extending Okta

Enrolling end users in MFA

Previously, we looked at how enrollment with different authenticators works, but let’s take a closer look at it from an end user perspective. We’ll learn this with the help of an example: an end user enrolling in Okta Verify. After a new MFA policy is rolled out, end users will be prompted to enroll in one or multiple authenticators on their next sign-on or when that authenticator is required. Let’s look at how it would work when the user clicks Setup for Okta Verify:

In the first step, the end user will select what device they are using, and then be informed to download the Okta Verify application from the device’s app store. Afterward, with the downloaded app, the user can scan the QR code to connect and register:

Figure 4.41 – Okta Verify download and QR scan step to enroll

Figure 4.41 – Okta Verify download and QR scan step to enroll

Once the code has been scanned, the user is asked to turn on and use biometric options if the device supports fingerprint...