Connect a database to Okta Privileged Access to discover, onboard, and manage its user accounts.
About this task
You do part of this setup in Okta Privileged Access and part in your own
environment.
Table 1. What you integrate
| What |
Where |
| Create integration user |
Your database instance |
| Deploy the gateway machine and configure networking |
Your infrastructure |
| Configure integration, onboarding rules, and a security policy rule |
Okta Privileged Access |
Before you begin
-
You have the Okta Privileged Access resource admin role. The final step also requires the security admin role.
-
You have a supported database instance running. See Supported database types, versions, and deployment options.
-
You have a server or virtual machine to use exclusively as the gateway machine. See Okta Privileged Access gateway capacity planning.
-
The gateway machine has outbound network access to each database instance that it services, and to
Okta Privileged Access on port 443 at
your-opa-team-name.pam.okta.com and
your-opa-team-name.pam.oktapreview.com. See Network access by
environment.
-
You have your database connection details ready, such as hostname and port.
Procedure
Create the gateway setup token
-
In Okta Privileged Access, identify the resource group and project where you want to manage the onboarded database accounts.
A dedicated project for your databases is often a good idea.
-
Create a gateway setup
token.
Choose the Infrastructure orchestrator role, and provide a unique
Orchestration group name.
CAUTION:
Launching and using a gateway that was set up with a setup token configured for Server
access proxy, or using an existing non-orchestrator token, causes the database
integration creation to fail.
Deploy the gateway machine and create the integration user
-
In your infrastructure, allocate a server or virtual machine to use exclusively as the Okta Privileged Access gateway machine.
Configure it to have outbound network access to each database instance that it services, and to
Okta Privileged Access. See Network access by
environment.
Note:
A single gateway can service multiple integrations, but most often a group of gateways will
together service multiple integrations providing both high-availability and efficiency.
-
Ensure the database that you intend to integrate with is up and running, and is supported.
You need this database instance's address for creating the integration. For most database types this
is just the host and port. For Oracle Database you need the service name. For Microsoft SQL Server you
may prefer to use the Named Instance value instead of the port.
-
Create the database integration
user on your database instance.
Okta Privileged Access connects as this user to discover accounts and rotate
passwords.
-
Set up the gateway machine to act as the Okta Privileged Access database
orchestrator.
Configure the integration and rules
-
In Okta Privileged Access, add an integration.
If the integration creation fails, you're presented with a clear error name and short descriptions.
Use the Troubleshooting database
integrations guide to learn more about how to remediate the issue.
-
Define account
rules to select which database user accounts Okta Privileged Access takes
over and manages.
-
Create a security policy, and then add rules to grant user groups access to the managed database accounts.
You can do this now or later.