Set up your first database integration

Connect a database to Okta Privileged Access to discover, onboard, and manage its user accounts.

About this task

You do part of this setup in Okta Privileged Access and part in your own environment.

Table 1. What you integrate
What Where
Create integration user Your database instance
Deploy the gateway machine and configure networking Your infrastructure
Configure integration, onboarding rules, and a security policy rule Okta Privileged Access

Before you begin

  • You have the Okta Privileged Access resource admin role. The final step also requires the security admin role.

  • You have a supported database instance running. See Supported database types, versions, and deployment options.

  • You have a server or virtual machine to use exclusively as the gateway machine. See Okta Privileged Access gateway capacity planning.

  • The gateway machine has outbound network access to each database instance that it services, and to Okta Privileged Access on port 443 at your-opa-team-name.pam.okta.com and your-opa-team-name.pam.oktapreview.com. See Network access by environment.

  • You have your database connection details ready, such as hostname and port.

Procedure

  • Create the gateway setup token

    1. In Okta Privileged Access, identify the resource group and project where you want to manage the onboarded database accounts.

      A dedicated project for your databases is often a good idea.

    2. Create a gateway setup token.

      Choose the Infrastructure orchestrator role, and provide a unique Orchestration group name.

  • Deploy the gateway machine and create the integration user

    1. In your infrastructure, allocate a server or virtual machine to use exclusively as the Okta Privileged Access gateway machine.

      Configure it to have outbound network access to each database instance that it services, and to Okta Privileged Access. See Network access by environment.

    2. Ensure the database that you intend to integrate with is up and running, and is supported.

      You need this database instance's address for creating the integration. For most database types this is just the host and port. For Oracle Database you need the service name. For Microsoft SQL Server you may prefer to use the Named Instance value instead of the port.

    3. Create the database integration user on your database instance.

      Okta Privileged Access connects as this user to discover accounts and rotate passwords.

    4. Set up the gateway machine to act as the Okta Privileged Access database orchestrator.
      1. Install the Okta Privileged Access gateway.

        Follow the instructions for your operating system.

      2. Configure the gateway to support database integrations.

        This creates the gateway configuration file, applies the setup token, and starts the gateway service.

  • Configure the integration and rules

    1. In Okta Privileged Access, add an integration.

      If the integration creation fails, you're presented with a clear error name and short descriptions. Use the Troubleshooting database integrations guide to learn more about how to remediate the issue.

    2. Define account rules to select which database user accounts Okta Privileged Access takes over and manages.
    3. Create a security policy, and then add rules to grant user groups access to the managed database accounts.

      You can do this now or later.