Okta is workforce identity and access management software for IT and security teams, with Single Sign-On, MFA and lifecycle automation in five suites.
Okta is workforce identity and access management software for IT and security teams that manage how employees sign in to business applications. It gives each person one sign-in, then adds a second factor and access rules on top. Okta, Inc., founded in 2009 and based in San Francisco, makes and sells it, and the product carries the company's name. The Starter suite covers Single Sign-On, Multi-Factor Authentication, Universal Directory and Workflows, the no-code editor for identity automations. Adaptive MFA applies contextual policies that can block a sign-in or trigger a challenge based on device, network and location. Lifecycle Management automates onboarding, offboarding and profile updates, and provisioning connectors create, update, deactivate and delete user accounts in the connected apps. Access Governance automates access reviews, and Access Requests in Identity Governance routes app and group requests to approvers. Device Access checks managed and unmanaged devices at sign-in. Okta Privileged Access records SSH and RDP sessions through a gateway. Identity Security Posture Management reports identity-based risks and misconfigurations, and Identity Threat Protection detects identity-based threats and responds to them automatically. API Access Management handles OAuth scopes for custom APIs, and Access Gateway puts legacy on-premises web apps behind SSO through standard headers, with no change to their source code. Okta suits IT teams that begin with SSO and MFA and grow into governance and threat response. Security teams use the higher suites for device checks and identity threat response, and engineering groups use API Access Management for their own APIs. Custom admin roles limit an administrator's powers to chosen groups and apps. Okta is sold as suites from Starter to Enterprise on a per-user, per-month basis, billed annually, with add-ons for capabilities such as Device Access, Access Gateway and Identity Governance. Day to day, people sign in to workforce apps through the Okta Integration Network of pre-built integrations. It fits hybrid environments where cloud apps sit beside on-premises web apps and Active Directory, which the Okta AD agent imports into the cloud directory. Workday can act as the profile source, so a hire creates an Okta user and a termination deactivates it. Administrators stream System Log events to Splunk Cloud and use Workflows to react to identity events. The Okta for AI Agents add-on brings the AI agents that work inside an organization onto the same platform that secures its other identities.
Features
- Included: Workforce SSO and MFA in one platform
- Included: Joiner-mover-leaver lifecycle automation
- Included: HR system as the identity source
- Included: Pre-built provisioning connectors for SaaS apps
- Included: Active Directory and LDAP integration
- Included: Conditional access policies by context
- Included: Device trust and posture checks
- Included: Identity threat detection and response
- Included: Identity security posture management
- Included: Built-in privileged access module
- Included: Periodic access reviews for app assignments
- Included: Self-service app access requests
- Included: No-code identity workflow automation
- Included: API access management for OAuth scopes
- Included: Gateway for on-premises web apps
- Included: Sign-in log streaming to a SIEM
- Included: Delegated admin roles by group or app
- Not included: Sandbox tenant for testing changes
Additional Features
- Single Sign-On
- Multi-Factor Authentication (MFA)
- Adaptive MFA with contextual policies
- Universal Directory
- Lifecycle Management for onboarding and offboarding
- Workflows no-code identity automation
- Access Governance access reviews
- Okta Integration Network pre-built integrations
Best for
- IT teams starting with SSO and MFA and adding governance later
- Security teams adding device checks and identity threat response
- Companies with on-premises web apps that need to join SSO
- Organizations automating employee onboarding and offboarding
- Engineering groups securing custom APIs with OAuth
- Teams that run recurring access reviews for app assignments
Use cases
- Single sign-on to workforce cloud apps
- Requiring a second factor at sign-in
- Automating account creation and removal when people join or leave
- Provisioning accounts in SaaS apps through pre-built connectors
- Running access reviews for app assignments
- Stepping up or blocking sign-ins by network, location and device
- Putting legacy on-premises web apps behind SSO
- Issuing and validating OAuth tokens for custom APIs
- Streaming System Log events to Splunk Cloud
- Recording SSH and RDP admin sessions to servers
- Hiring and terminating people in Workday and reflecting it in user accounts
- Importing Active Directory users and groups into the cloud directory
- Letting employees request an app and routing it to approvers
- Limiting an admin's powers to chosen groups or apps
- Finding identity misconfigurations across connected apps
- Bringing AI agents under the same identity platform
Screenshots & Videos
Explore Okta in action