This document describes the approach and mechanism to authorize users to access Okta Privileged Access (OPA) and protected resources.
Introduction
This document outlines a solution for managing access for federated users, specifically from business partners, vendors, subsidiaries, or sister companies, to applications and resources protected by Okta Privileged Access.
This document focuses on addressing business use cases for authorizing partner users to access or manage protected resources. Some key scenarios include:
- Customers leveraging an Org2Org deployment but requiring centralized PAM.
- Customers in compliance-focused Okta Orgs or Okta Orgs without OPA availability.
- Organizations outsourcing infrastructure management to a third-party provider.
Below is a refined summary of the key aspects of the solution:
Objective
To enable customers to:
- Grant federated users access to applications and resources protected by Okta Privileged Access .
- Utilize Okta Identity Governance (OIG), if subscribed, to conduct certification campaigns for auditing and managing user access to the resources protected by Okta Privileged Access.
Key Features
- Federated Access Management:
- Designed to manage access for users federated from external organizations (e.g., business partners or subsidiaries).
- Leverages two Okta organizations (Okta Org) integrated through the Org2Org application available in the Okta Integration Network (OIN).
- Certification Campaigns:
- If OIG is in use, customers can run certification campaigns to audit access.
- Campaign reviewers can:
- Review access for Okta Privileged Access applications and associated groups.
- Decide whether users should retain access or have it revoked.
- Self Service Support:
- Other Articles and resources published provides guidance for:
- Self-service functionalities to request access to Okta Privileged Access and resources
- Setting up and running certification campaigns for Okta Privileged Access.
- Other Articles and resources published provides guidance for:
Use Case
This solution empowers organizations to:
- Simplify OPA access management for external federated users.
- Maintain security and compliance through regular access reviews and certification campaigns.
- Seamlessly integrate federated users using the Org2Org application to extend privileges across the Okta ecosystem.
This solution supports scalability and aligns with the needs of organizations managing diverse federated user bases while prioritizing security and compliance.
Note:- This solution is being provided AS IS and it does not imply any support from Okta. It can be used as reference and feel free to modify or customize as per your Org needs.
Overview
The Aim of the Solution
The aim of this solution is to integrate two Okta tenants (Okta Orgs) to enable the federation of users from one tenant (as Identity Provider) to another tenant (Service Provider) which hosts Okta Privileged Access (OPA). This integration facilitates granting federated users access to resources protected by Okta Privileged Access, ensuring secure and streamlined access management.
Additionally, a similar approach can be applied to provide access to users managed by third-party identity providers, further extending the solution’s versatility and scalability.
How the Solution is Built
This solution establishes integration between two Okta tenants, with one acting as the Identity Provider (IdP) and the other as the Service Provider (SP). The integration allows federated users to access Okta Privileged Access applications and protected resources seamlessly.
For this solution, it is assumed that the tenant serving as the Service Provider has Okta Privileged Access and Okta Identity Governance (OIG) application SKUs enabled and properly configured. It also assumes that the administrator or user implementing this solution has a foundational understanding of OIG and Okta Privileged Access.
The document is structured into the following sections to guide you in implementing and adopting the solution effectively:
- Setup Org2Org Application in the Identity Provider Tenant
Configure the Org2Org application in the tenant acting as the Identity Provider to enable secure federation. - Setup Identity Provider in the Tenant Hosting the Okta Privileged Access Application
Configure the Identity Provider settings in the Service Provider tenant to establish a trusted federation and enable access to protected resources.
Note: This solution does not include guidance for setting up or configuring OIG components or Okta Privileged Access (OPA). It assumes that these configurations are already in place.
This approach ensures a comprehensive and secure integration for managing federated user access.
SSO: Setup Trust between IDP and SP
This section provides a step-by-step instruction to set up the Org2Org application in the Identity Provider (IdP) tenant and Identity Provider configuration and rules to allow IDP to use Okta Privileged Access application and protected resources on Service Provider (SP) tenant. For this demonstration, the https://<<IDP>>.oktapreview.com tenant is used as the Identity Provider and https://<<SP>>.oktapreview.com tenant as service provider. By assigning users to this application in the IdP tenant, they will be able to federate into the Okta tenant acting as the Service Provider (SP), thereby gaining access to the Okta Privileged Access (OPA) application and protected resources.
Add Org2Org Application on IDP tenant:
Steps have been provided below. For details integration and to learn more about Org2Org application follow this link.
- Log in to the Identity Provider Tenant:
- Access the Okta Admin Console for the tenant https://<<IDP>>.oktapreview.com, which serves as the Identity Provider.
- Navigate to the Applications Section:
- Go to the Applications tab in the Admin Console.
- Click on Applications > Applications.
- Add a New Application:
- Click on Browse App Integration Catalog.
- Search for Okta Org2Org and click on Add Integration to proceed.
- Configure the Org2Org Application:
- Enter the required application details:
- Application label: Provide a meaningful label, “Org2Org Integration for OPA”
- Base Url: Enter the Okta tenant Url https://<<SP>>.oktapreview.com of the Service Provider tenant hosting OPA. Click Next and then Done.
- Application Visibility: Checked
- Enter the required application details:
- Map User Attributes:
- Use Profile Editor to ensure proper user attributes are mapped to the Service Provider tenant’s requirements, such as:
- FirstName
- LastName
- ManagerID etc.
- Use Profile Editor to ensure proper user attributes are mapped to the Service Provider tenant’s requirements, such as:
Note: If you are using Custom Application integration using SAML template follow the the link to map attribute statements
- Enable provisioning from source to target
- Use one of the following methods, as detailed in the Okta Help Center, to enable provisioning in the Org2Org application:
- The API token method has been used in this document for demonstration.
- Navigate to the Provisioning tab within the Org2Org application settings.
- Click the Provisioning tab, click Configure API Integration, and then select Enable API integration.
Provide following details into respective fields:
- Security Token: Generate an API token from the Service Provider tenant’s Admin Console (under Security > API > Tokens) and copy it into the required field.
- Prefer Username Over Email: Optional. Select this option if you don’t want to use an email address as the username.
- Import Groups: Optional. Clear the checkbox if you don’t want to import groups from the connected org.
- Click Test API Credentials to test the API integration
- Click Save
Change the provisioning settings to push user from Okta IDP tenant to Okta SP tenant:
- Click the Provisioning tab, and then select To App under Settings.
- Click Edit.
- Select the Create Users, Update User Attributes, Deactivate Users, or Sync Password checkboxes
- Click Save.
- Create a Bookmark application
- Navigate to the Applications Section:
- Go to the Applications tab in the Admin Console.
- Click on Applications > Applications.
- Add a New Application:
- Click on Browse App Integration Catalog.
- Search for Bookmark App and click on Add Integration to proceed.
- Configure the Bookmark App Application:
- Application label: “Okta Privileged Access (SP Access)”
- Url: Obtain the URLs from source and target
- The IdP Single Sign On URL: To obtain this URL navigate to above application (Org2Org Integration for OPA) and click on Authentication tab https://<<IDP>>.oktapreview.com/app/okta_org2org/exkjl38y46gPlmNd71d7/sso/saml
- Navigate to the Applications Section:
- ?RelayState=
- The Embed Link value for the app: To obtain this URL navigate to Okta Privileged Access application on the service provider side and click on the General tab and copy the App Embed Link. https://<<SP>>.oktapreview.com/home/okta_privileged_access_sso/0oa7l5wucrcB76RIQ1d7/aln77zldx1LJPuhdB0g7
- Concatenate the above URLs to create URL for bookmark app.
- https://<<IDP>>.oktapreview.com/app/okta_org2org/exkjl38y46gPlmNd71d7/sso/saml?RelayState=https://<<SP>>.oktapreview.com/home/okta_privileged_access_sso/0oa7l5wucrcB76RIQ1d7/aln77zldx1LJPuhdB0g7
- Group to manage Okta PA app access
- Create a Group as “Okta PA – Service Provider”
- Assign both application (Created above) to this group
- Assign Users to the Application:
- Assign the relevant users to the above group which will grant them access to both the applications created above. End users will only see Bookmark app tile on their Okta (IDP) tenant https://<<IDP>>.oktapreview.com dashboard.
- Confirm that these users have the correct permissions to federate into the SP tenant.
Setup configuration on Service Provider Tenant
Steps to configure Identity Provider configuration on SP tenant have been provided below. For detailed integration and to learn more about Identity provider configuration follow this link.
- Log in to the Service Provider Tenant:
- Access the Okta Admin Console for the tenant https://<<SP>>.oktapreview.com, which hosts Okta Privileged Access application.
- Create a Group to manage federated users
- Go to the Directory section in the Admin Console and click on Groups.
- Create a Group as “OPA_IDP_Users”.
- Assign “Okta Privileged Access” and Okta Access Request” applications to this group
- Navigate to the Security Section:
- Go to the Security section in the Admin Console.
- Click on Security > Identity Provider.
- Add a New Identity Provider:
- Click on Add Identity Provider.
- Select SAML 2.0 IDP and click Next to proceed.
- Configure the Identity Provider configuration:
- Enter the required application details:
- Name: Provide a meaningful name, e.g., “IDP OPA Users”
- IDP Usage: SSO only
- Account matching with Persistent Name ID: Checked
- IdP username: idpuser.subjectNameId
- Match against: Okta Username
- Account link policy: Automatic
- Auto-Link Restrictions: None
- If no match is found: Create new user (JIT)
- JIT Settings
- Profile Source: Update attributes for existing users
- Reactivation Settings
- Reactivate users who are deactivated in Okta: Checked
- Unsuspend users who are suspended in Okta: Checked
- Group Assignments
- Specific Groups: “OPA_IDP_Users”
- SAML Protocol Settings
- Navigate to Org2Org Integration for OPA application on IDP tenant and click on Authentication tab. Expand Show details under SAML 2.0 section. Copy Sign on URL, issuer URL and download the Signing Certificate. Change the downloaded file extension to *.crt.
- Enter the required application details:
- IdP Issuer URI: issuer URL (Copied above) http://www.okta.com/exkjl38y46gPlmNd71d7
- IdP Single Sign-On URL: Sign on URL (Copied above) https://<<IDP>>.oktapreview.com/app/okta_org2org/exkjl38y46gPlmNd71d7/sso/saml
- Upload the certificate downloaded above.
- Destination: https://<<IDP>>.oktapreview.com/app/okta_org2org/exkjl38y46gPlmNd71d7/sso/saml
- Okta Assertion Consumer Service URL: Trust-specific
- Max Clock Skew: 2 minutes (Default value)
- Click Finish to complete the Identity Provider configuration
- Expand the Identity Provider configuration and copy the Assertion Consumer Service URL and Audience URI. This will be required to update the Org2Org application advance sign-on settings to complete the configuration.
Create Identity Provider Rule:
Steps to create Identity Provider rule to redirect IDP sourced users to authenticate by IDP and assert the authentication token to SP to trust the IDP user and allow access to the application.
- Navigate to the Security Section:
- Navigate to the Identity Provider > Routing Rules in the Admin Console
- Click Add Routing Rule and provide details as shown in screenshot below.
- Navigate to the Identity Provider > Routing Rules in the Admin Console
Note: “RegEx has been used to identify the IDP users and redirect them for authentication. This is configurable and can be modified as needed.
- Click “Create Rule”
Update Org2Org Application on IDP tenant:
Steps to complete final configuration on Identity Provider’s Org2Org application to complete the SAML trust between IDP and SP.
- Log in to the Identity Provider Tenant:
- Access the Okta Admin Console for the tenant https://<<IDP>>.oktapreview.com, which serves as the Identity Provider.
- Navigate to the Applications Section:
- Navigate to the Applications > Applications in the Admin Console
- Search for Org2Org Integration for OPA application.
- Click on “Authentication” tab
- Edit the SAML 2.0 section to update the Hub ACS URL and Audience URL under Advanced Sign-on settings copied above from Identity Provider configuration in SP tenant.
Assign Okta Privileged Access Policy:
This section will demonstrate the steps to authorize IDP users to grant resources access in Okta Privileged Access. This can be automated using multiple processes. The document will detail the approach by using a push group mechanism by pushing OPA_IDP_Users groups in the Okta Privileged Access application which was created to manage IDP users.
- Log in to the Identity Provider Tenant:
- Access the Okta Admin Console of https://<<SP>>.oktapreview.com tenant.
- Navigate to the Applications Section:
- Navigate to the Applications > Applications in the Admin Console
- Search for Org2Org Integration for OPA application.
- Click on “Push Groups” tab
- Click on Push Groups button and select Find groups by name
- Search for the “OPA_IDP_Users” group and click on the Save button to push.
- Login to Okta Privileged Access application to access console as Security Administrator
- Create a policy to authorize resource access to IDP users and attach the “OPA_IDP_Users” group to the policy.
By following above steps, the Org2Org application in the Identity Provider tenant https://<<IDP>>.oktapreview.com will be configured to enable secure and efficient user federation into the Service Provider tenant, providing seamless access to Okta Privileged Access applications and protected resources.
MFA: Setup trust between IDP and SP
This section provides a step-by-step guide to setting up Multi-Factor Authentication (MFA) for an Identity Provider (IDP) on the Service Provider (SP) tenant. It ensures that MFA prompt confirmation is redirected to the IDP and relies on the Authentication Policy Response (APR) received from the IDP. Additionally, a separate SAML application is set up to establish trust between the IDP and SP, facilitating the MFA request and response.
Once a user is Just-In-Time (JIT) provisioned on the SP tenant and assigned to a group managing federated users, they will be subject to authentication and MFA policies configured specifically for federated users. These policies will redirect them to their respective IDPs for authentication and MFA verification before gaining access to the OPA console or OPA protected resources.
Add SAML Application on IDP tenant:
Steps have been provided below. For details integration and to learn more about Org2Org application follow this link.
- Log in to the Identity Provider Tenant:
- Access the Okta Admin Console for the tenant https://<<IDP>>.oktapreview.com, which serves as the Identity Provider.
- Navigate to the Applications Section:
- Go to the Applications tab in the Admin Console.
- Click on Applications > Applications.
- Add a New Application:
- Click on Create App Integration.
- Select SAML 2.0 as Sign-in method, Click Next
- Configure the SAML Application:
- Enter the required application details:
- Application Name: Provide a meaningful label, “SP MFA Challenge for OPA”
- Application Visibility: Checked
- Enter the required application details:
- Enter http://localhost as a temporary value. We will come back and replace it with the Service Providers URLs once we set up config on the SP side.
- Click Next
- Check App Type as “This is an internal app that we have created”, Click Finish
- Group to manage Okta PA app access
- Assign “SP MFA Challenge for OPA” application to “Okta PA – Service Provide” group.
Setup configuration on Service Provider Tenant for IDP MFA
Steps to configure Identity Provider configuration on SP tenant to redirect federated users for MFA to IDP have been provided below. For detailed integration and to learn more about configuration follow this link.
- Log in to the Service Provider Tenant:
- Access the Okta Admin Console for the tenant https://<<SP>>.oktapreview.com, which hosts Okta Privileged Access application.
- Navigate to the Security Section:
- Go to the Security section in the Admin Console.
- Click on Security > Identity Provider.
- Add a New Identity Provider:
- Click on Add Identity Provider.
- Select SAML 2.0 IDP and click Next to proceed.
- Configure the Identity Provider configuration:
- Enter the required application details:
- Name: Provide a meaningful name, e.g., “OPA MFA”
- IDP Usage: Factor only
- Account matching with Persistent Name ID: Unchecked
- SAML Protocol Settings
- Navigate to SAML Application “SP MFA Challenge for OPA” on IDP tenant and click on Authentication tab. Expand Show details under SAML 2.0 section. Copy Sign on URL, issuer URL and download the Signing Certificate. Change the downloaded file extension to *.crt.
- Enter the required application details:
- IdP Issuer URI: issuer URL (Copied above) http://www.okta.com/exkl5xz4einaJ0Abi1d7
- IdP Single Sign-On URL: Sign on URL (Copied above) https://<<IDP>>.oktapreview.com/app/spmfachallengeforopa_1/exkl5xz4einaJ0Abi1d7/sso/saml
- Upload the certificate downloaded above.
- Destination: https://<<IDP>>.oktapreview.com/app/spmfachallengeforopa_1/exkl5xz4einaJ0Abi1d7/sso/saml
- Okta Assertion Consumer Service URL: Trust-specific
- Max Clock Skew: 2 minutes (Default value)
- Click Finish to complete the Identity Provider configuration
- Expand the Identity Provider configuration and copy the Assertion Consumer Service URL and Audience URI. This will be required to update the “SP MFA Challenge for OPA” application advance sign-on settings to complete the configuration.
Update SAML Application on IDP tenant:
Steps to complete final configuration on Identity Provider’s “SP MFA Challenge for OPA” application to complete the SAML trust between IDP and SP.
- Log in to the Identity Provider Tenant:
- Access the Okta Admin Console for the tenant https://<<IDP>>.oktapreview.com, which serves as the Identity Provider.
- Navigate to the Applications Section:
- Navigate to the Applications > Applications in the Admin Console
- Search for “SP MFA Challenge for OPA” application.
- Click on “Authentication” tab
- Edit the SAML 2.0 section to update the Hub ACS URL and Audience URL under Advanced Sign-on settings copied above from Identity Provider configuration in SP tenant.
Configure the IdP authenticator
Steps to add an Authenticator as MFA on the Service Provider to redirect users and require them to complete the MFA challenge on the IDP.
Follow the provided link to set up the Authenticator on the IDP.
Once the Authenticator for the IDP is added, make sure to add an enrollment policy specifically for federated users only.
Testing Steps
Once the above set up and configuration is completed, then the test the OPA resource access for IDP users.
This section will guide you through how an IDP administrator assigns users to a group to provide access to an OPA application hosted by a service provider and access the OPA resources.
- Create a user with username as “dparker01092025@domain.com” in Okta IDP tenant and assign the user to “Okta PA – Service Provider” group.
- Once an IDP user is assigned to the group and login, “Okta Privileged Access (SP Access) application will be visible on the dashboard.
- Click on the application tile which will take him to Okta Privileged Access console
- All servers authorized will be visible under My Server page.
- Now users can access resources, authorized to them.
- If the OPA policy enforces MFA for server access, the user will be prompted for MFA and redirected to the IDP for verification. Once successfully verified, the user will be redirected back to the Service Provider (SP), and server access will be granted.
Appendix
Self Service for Identity Provider Users
The Org2Org application can be made visible to users in the Identity Provider (IdP) tenant if the Service Provider (SP) wants to grant access to the Okta End-User Dashboard. This visibility enables users to perform the following actions:
- Request Group Membership:
- Users can request membership to specific groups from the Okta End-User Dashboard.
- These groups can be used to manage entitlements, as explained in Reference Link #2.
- Request Policy Access as OPA Entitlements:
- Users can request policy access as part of an Okta Privileged Access (OPA) entitlement bundle to gain access to OPA-protected resources.
- The setup and functionality are detailed in Reference Link #1.
Helpful Resources
The following blogs provide additional guidance for configuring these features:
- Governance for Okta Privileged Access Server Resources
- The Combined Power of Okta Privileged Access and Okta Identity Governance
By leveraging these features and references, the Org2Org application setup not only facilitates federation but also empowers users to request and manage access to resources in a self-service manner, streamlining entitlement management and compliance processes.

IAMSE