Collects paginated user inventory and verifies required authenticator enrollment settings in Okta.
AvailableRead-only collection
What vCISO.ai observes
Paginated user inventory
Required authenticator enrollment settings
Authorization and permissions
Okta organization domain and read-only API token
Read users through Okta API GET requests
Read authenticator-enrollment policies
No write endpoint is called
Setup path
Setup remains administrator-controlled inside the authenticated workspace.
Create a read-only Okta API token
Provide the Okta organization domain and token
Run the first read-only collection
Review the checks
Collection limitations
A limited or failed read stays visible and never becomes a passing result.
User inventory follows supported pagination limits
Current checks cover user inventory and required authenticator enrollment
The connection cannot change Okta policies
Disconnect and deletion behavior
An administrator can disconnect the integration. The encrypted token and configuration are removed locally and connector-derived evidence is expired. The customer should also revoke the Okta token.
Existing historical records remain available as review history
Connector-derived evidence is marked expired when the source is disconnected
Disconnect is organization-scoped and audit logged
A provider observation can support a control only after the right relationship and evidence are reviewed. Connecting Okta does not automatically verify a control, complete a framework, or produce an audit conclusion.
Start with the roadmap
Put Okta into a prioritized readiness plan.
Build the free roadmap first, then activate the AI vCISO when you are ready to connect the provider.