Secure Partner Access

This page is for articles relating to the Okta Secure Partner Access product.

Okta Secure Partner Access Overview

The aim of Okta Secure Partner Access (SPA) is to simplify the administration of parter users in an Okta org. Prior to SPA, you would need to use groups or a multi-tenant approach to control administrative access.

The following figure shows the major components and integrations with the wider Okta Workforce Identity Cloud platform and external systems.

The solution leverages the new Realms feature in Okta Universal Directory (realms are also provided with Okta Identity Governance). Realms are discrete containers of users (a user can only be in one realm) and administrative roles can be applied to one or more realms – so you could have different Okta admins for different partner realms. The admin roles, applications and groups reside outside the realms, so groups and apps can be applied for users across different realms.

The other key capability in SPA is the Secure Partner Access Portal. This is a cut-down Okta Admin Console with rights restricted to administering users in one or more realms.

More information can be found in an introduction article (also listed below).

Okta Secure Partner Access Posts

The following articles are specific to Okta Secure Partner Access.

Privileged Access Management for Federated Users

This document describes the approach and mechanism to authorize users to access Okta Privileged Access (OPA) and protected resources. Introduction This document outlines a solution for managing access for federated users, specifically from business partners, vendors, subsidiaries, or sister companies, to applications and resources protected by Okta Privileged Access.  This document focuses on addressing business…

Automating Realm Creation in Okta with Workflows

The new Realms feature in the Okta Workforce platform and the Secure Partner Access (SPA) product built on top of it are designed to make management of discrete user populations simpler. Realms can be managed via the Okta Admin Console. But what about when you want to automate the process, such as onboarding a large…

Assigning Administrators to Realms in Okta

Realms were introduced into Okta to provide an alternative mechanism for delegated administration with discrete user populations. A key aspect of this is the administration – you may need to have different types of administrator roles for the users in the realm, but also allow cross-realm roles. In this article we explore configuring administrators for…

An Introduction to Realms in Okta

Okta recently added a new feature to the Universal Directory called Realms. This article provides an overview of the new feature. Note that Realms is only available with the Okta Identity Governance and Secure Partner Access products. At the time of writing this article, Realms is in Early Access. Background – Why do we need…

Okta Secure Partner Access Solution

Description: In this document we will go over the high-level overview of the Secure Partner Access (SPA)  solution in Okta. Also, we will go over the setup of Realms and Partner Admin Portal. Prerequisite: Use case: The Partner Admin Portal is a delegated admin portal designed to manage partner user access. The Partner Admin Portal…

Realms for Workforce Management – A New Flexible Way to Manage your Organization

Introduction  Okta’s vision with Universal Directory is to provide a centralized approach to identity management, where customers can integrate any technology stack into a comprehensive, central cloud directory for unified management. In today’s world, unified identity management is becoming increasingly challenging. Organizations rely on a workforce composed of employees, contractors, seasonal workers, and business partners,…