.ai
All integrations

Available integration

Okta

Collects paginated user inventory and verifies required authenticator enrollment settings in Okta.

AvailableRead-only collection

What vCISO.ai observes

  • Paginated user inventory
  • Required authenticator enrollment settings

Authorization and permissions

Okta organization domain and read-only API token

  • Read users through Okta API GET requests
  • Read authenticator-enrollment policies
  • No write endpoint is called

Setup path

Setup remains administrator-controlled inside the authenticated workspace.

  1. Create a read-only Okta API token
  2. Provide the Okta organization domain and token
  3. Run the first read-only collection
  4. Review the checks

Collection limitations

A limited or failed read stays visible and never becomes a passing result.

  • User inventory follows supported pagination limits
  • Current checks cover user inventory and required authenticator enrollment
  • The connection cannot change Okta policies

Disconnect and deletion behavior

An administrator can disconnect the integration. The encrypted token and configuration are removed locally and connector-derived evidence is expired. The customer should also revoke the Okta token.

  • Existing historical records remain available as review history
  • Connector-derived evidence is marked expired when the source is disconnected
  • Disconnect is organization-scoped and audit logged
A provider observation can support a control only after the right relationship and evidence are reviewed. Connecting Okta does not automatically verify a control, complete a framework, or produce an audit conclusion.

Start with the roadmap

Put Okta into a prioritized readiness plan.

Build the free roadmap first, then activate the AI vCISO when you are ready to connect the provider.