Integrate Okta
You can integrate Okta with Sophos XDR so that it sends authentication and authorization data to Sophos for analysis.
Key steps
The key steps in an Okta integration are as follows:
- Get details of your Okta service.
- Generate an API token in Okta.
- Configure the integration in Sophos XDR.
Requirements
The following is required for Okta configuration:
- An administrator account in the Okta console.
Add an Okta integration
To integrate Okta, you must first gather certain details from Okta, then provide them in Sophos XDR.
Find your base URL
To find your Okta URL, also called an Okta domain, do as follows:
- Sign in to the Okta administrator console for your Okta organization.
-
Look for the Okta domain in the global header, in the upper-right corner of the dashboard.
Example Okta domains are as follows:
example.oktapreview.comexample.okta.comexample.okta-emea.com
-
Copy the URL to use later in Sophos XDR.
Next, you generate an API token in Okta.
Generate an API token
To integrate Okta, you'll need an API token. This is also sometimes called a key or secret.
To generate the API token, do as follows:
-
Sign in to Okta as an administrator with the same rights that are needed to perform the API's actions.
The API token inherits its user role and permissions from the signed-in administrator.
-
In the Okta administrator console, go to Security > API.
- Click Create Token.
-
Enter a name for your token.
Copy the token value immediately. You can't retrieve it.
Next, you configure an integration in Sophos XDR.
Configure the integration in Sophos XDR
To integrate Okta with Sophos XDR, do as follows:
- In Sophos Fusion, go to Security Operations > Integrations > Marketplace.
-
Click Okta.
The Okta page opens. You can configure integrations here and see a list of any you've already configured.
-
In Configured Integrations, click Add new.
-
In Add an integration, do as follows:
- Enter a name for the integration.
- Enter the Base URL and API token.
-
Click Save.
The new integration appears under Configured integrations. If its status icon is a green tick, your data should appear in the Sophos Data Lake after validation.
Configuration notes
Keep the following in mind during Okta configuration:
- If you're using a trial Okta account, make sure that the URL hasn't expired.
Additional resources
For more information on configuring Okta, see the following documents: