MFA Can Now Be Applied to Secret Access Policy in Okta Privileged Access

Okta Privileged Access (OPA) has had the option to turn on Multifactor Authentication (MFA) for server access policy for some time. This has now been extended to cover secret access policy. If you have worked with OPA Policy Rules for Secrets you will be familiar with the following that shows the permissions that can be … Continue reading MFA Can Now Be Applied to Secret Access Policy in Okta Privileged Access

Managing Access in Okta Privileged Access with the new OIG Resource Catalog

Okta has released into Early Access a new feature called the Access Request Conditions and Resource Catalog, or more simply the Resource Catalog. This is a new way to configure and use access requests in Okta Identity Governance. This article shows how this can be applied to access within Okta Privileged Access. IntroductionA Quick Revision … Continue reading Managing Access in Okta Privileged Access with the new OIG Resource Catalog

Privileged Access Management for AWS using Okta Workforce Solutions

This article is a summary of a presentation I recently gave looking at Okta Workforce Identity Cloud and Amazon Web Services (AWS). It is focused on how privileged access management can be applied to AWS users and access, leveraging the different Identity and Access Management (IAM) capabilities in Okta. IntroductionAccess Management and AWS PrivilegesIdentity Administration, … Continue reading Privileged Access Management for AWS using Okta Workforce Solutions

Advanced Server Access PLUS step-up MFA for sudo with RADIUS

Okta’s Advanced Server Access (ASA) eliminates password and SSH-key challenges with just-in-time, ephemeral certificates, improving security and user experience. While ASA doesn’t support transactional MFA, Okta’s RADIUS agent with the libpam_radius module enables sudo step-up MFA. The guide details RADIUS agent setup, server configuration, and sudo entitlement adjustments for enhanced security.

Okta Privileged Access : User Identity Creation alert

This article is to send a notification to the security team if a new user id is being created on any Okta PA protected resources. This will help the security team to identify new identities directly created on protected servers which are not discovered and being managed by the vault in Okta Privileged Access - … Continue reading Okta Privileged Access : User Identity Creation alert

Okta Privileged Access – Determining and Highlighting Risk in Roles and Policies

Okta Privileged Access provides a flexible framework for controlling who can access what privileged resources and how. This includes resource groups for managing resources, security policies for controlling access, administrative roles to manage them, and principals to use them. Invariably configuring the PAM solution will introduce risk. But how to monitor and manage the risk … Continue reading Okta Privileged Access – Determining and Highlighting Risk in Roles and Policies

Okta Privileged Access and Access Certification – Getting Roles into the Group Description

As with many SaaS applications in Okta, application entitlement can be managed via Okta Groups pushed to Okta Privileged Access (OPA). This means membership in OPA policies and roles is based on Okta Group membership and thus can be governed by access requests and access certification for those groups. In this article we look at … Continue reading Okta Privileged Access and Access Certification – Getting Roles into the Group Description

Okta Privileged Access and the Reports API – Who has Access to What and How?

With the release of Okta Privileged Access, an API has also been released to provide programmatic access into objects managed by it, such as servers, secrets and gateways. There is a set of Access Reports APIs to allow for external reporting on who has access to what and how. This article explores the APIs, the … Continue reading Okta Privileged Access and the Reports API – Who has Access to What and How?

Leveraging Zero Standing Privileges and Shared Account Access with Okta Privileged Access

We all appreciate that a Zero Standing Privileges model is the best approach when it comes to privileged access - if a compromised account doesn't have standing privileges, then the attacker is limited in what they can do. But the reality for many organisations is that there are still shared accounts with elevated privileges that … Continue reading Leveraging Zero Standing Privileges and Shared Account Access with Okta Privileged Access

Introducing Secrets Management in Okta Privileged Access

This article explores the new secrets management capability within Okta Privileged Access. Introduction to Secrets ManagementThe Vault, Secrets and FoldersResource Administration and Security PolicyAn Example of Generic Secrets ManagementThe configuration in Okta and Okta Privileged AccessOkta Users and GroupsResource Groups and ProjectsDefining Top-Level Folders as the SecretAdminDefine Secrets PoliciesManaging Folders and SecretsUser (Linux Sysadmin) ViewConclusion … Continue reading Introducing Secrets Management in Okta Privileged Access