Add a database integration to Okta Privileged Access

Adding database integrations at the database instance level, or at a specific database or container in that instance, lets you manage database accounts in Okta Privileged Access.

Database type Database target
MariaDB, Microsoft SQL Server, MySQL, PostgreSQL The database instances themselves.
MongoDB A specific database on a database instance (authentication database).
Oracle Database A specific container: the CDB root, an application root, or a PDB.

Before you begin

  • Ensure that you have the Okta Privileged Access resource admin role.

  • Ensure that you or another admin has the Okta Privileged Access security admin role. Your end users can't use this integration until security policies are configured.
  • Complete the steps in Set up your first database integration.

  • Ensure that a gateway enrolled with the Infrastructure orchestrator role is running and can reach the database instance. See Configure the gateway to support database integrations.

  • Know the connection details for the database instance, namely the host, and port. Some database types need more, such as a service name for Oracle database, an instance name for Microsoft SQL server, or a default authentication database for MongoDB.

  • Ensure that you have a dedicated user on the database instance with the necessary privileges to manage the integration. See Database integration user privileges.

Create the integration

  1. Go to Resource Administration > Integrations.

  2. From the Resource type dropdown list, select Databases.

  3. Select Add Integration in the top right.

  4. Select the database type.

  5. Complete the following database integration details:

    1. Enter an Integration name. This is the alias for this database instance. You can't change the integration name after the integration is created.

    2. Optional. Add a Description.

    3. Select an Orchestration group.

    4. Enter the Host and Port that the gateway uses to access the target database instance. For an Oracle Real Application Cluster (RAC) deployment, enter the RAC cluster's SCAN hostname.

    5. For a Microsoft SQL server integration, you can enter a Instance name or Port, but not both.

    6. For an Oracle database integration, enter the Service name.

    7. For a MongoDB integration, enter the Default authentication database.

  6. Under Integration user, enter the username and password.

  7. Select Test and Save integration.

If the test fails, examine the error message returned in the Admin Console. For specific error messages and remedies, see Troubleshooting database integrations.

After the integration is created, its ongoing health is visible in the integrations list. See Database integration health status.

When an integration is created successfully, Okta Privileged Access prompts you to set up account rules and offers to take you there. You can skip that prompt and add account rules later by opening the integration and selecting the Account rules tab.

Add account rules

Account rules allow you to choose which user accounts in the integrated database instance become managed resources in Okta Privileged Access. Don't onboard a database user account that is used by any type of automation. The automation breaks when the account's password is auto-rotated by Okta Privileged Access.

  1. Enter a Rule name.

  2. Select the Operator and enter a Value. The value you enter is case-sensitive. Okta Privileged Access matches accounts using the exact case that you enter.

  3. Optional. Select Add a condition to define another condition by which to onboard database accounts.

  4. Select the Project that matching accounts will be assigned to. To find the project, first select its Resource group.

  5. Select Save rule.

  6. Go back to the Accounts tab to confirm that the accounts appear.

Discovery and onboarding start automatically when you save an account rule, so you don't need to start them yourself. Onboarded accounts can take a few minutes to appear. If no accounts appear, the account rule may not match any users in the database. Review the operator and value in the rule.

Run discovery and onboarding

Okta Privileged Access runs discovery and onboarding automatically every time you create or change an account rule, so you don't need to start them yourself. To run it before the next automatic run, complete these steps:

  1. Go to Resource Administration > Integrations.

  2. From the Resource type dropdown menu, select Databases.

  3. Select the Actions menu on the integration, and then select Sync now.

  4. Open the integration and select the Accounts tab to confirm the discovered accounts appear.

What to do next

Now that accounts are onboarded, grant your users access to them by creating a security policy and adding rules to it. Create the policy after your account rules, because a policy can only grant access to accounts that are already onboarded. You can wait to do this, but until you do, no end user has access to any of these database accounts.