Set up Okta Privileged Access
Okta automatically provisions the Okta Privileged Access app for orgs with an active Okta Privileged Access subscription. Orgs that haven't migrated to automated provisioning must add and configure the app manually.
To determine which setup applies to your org, in the Admin Console go to :
- If the Okta Privileged Access app is listed, follow Automated setup.
- If the Okta Privileged Access app isn't listed, follow Manual setup.
Prerequisites
You must have an admin role in your Okta org.
Automated setup
When your org's Okta Privileged Access subscription becomes active, Okta automatically provisions the Okta Privileged Access app, creates your team, and enables SCIM provisioning. Your team name is generated automatically, so you don't need to add the app or configure provisioning manually. Okta also automatically syncs the super admins in your org to Okta Privileged Access and adds them to the owners group, granting them the PAM admin role.
While automated provisioning is active, you can't deactivate or delete the Okta Privileged Access app from the Applications page.
Complete the following steps to finish setting up Okta Privileged Access:
- Assign an admin to Okta Privileged Access
- Verify SSO and user configuration
- Assign users and groups
- Push groups to Okta Privileged Access
Assign an admin to Okta Privileged Access
Super admins are added to the owners group automatically. To grant PAM admin access to another user, assign them to the app.
- From the Applications page, select Okta Privileged Access .
- Go to the Assignments tab and select .
- Identify your account in the list and select Assign.
- Select Save and Go Back, then select Done.
Verify SSO and user configuration
After your subscription is activated, the Okta Privileged Access app appears on your End-User Dashboard under My Apps with SSO already configured. You can sign in to the app.
- From your dashboard, select the Okta Privileged Access app.
- In the Okta Privileged Access Admin Console, you can view assigned users and groups. At this stage, one user is registered, and admins aren't configured. Okta will add more users and groups in the next steps.
Assign users and groups
You can assign users and groups to the Okta Privileged Access app in your Okta org. You can create groups that reflect the admin structure in Okta Privileged Access. For example, create a PAM admin group, a security admin group, and a resource admin group. Assign these groups to the app, and then push the groups to your Okta Privileged Access team.
-
Go to the Assignments tab.
-
The users assigned to the Okta Privileged Access app appear.
To assign users or groups to an app, see Assign an app integration to a user and Assign an app integration to a group.
Push groups to Okta Privileged Access
You can use Group Push to push existing Okta groups and their memberships to Okta Privileged Access. See Configure group sync.
After the Group Push operation completes, user groups pushed from the Okta org to Okta Privileged Access are visible under Okta Privileged Access. Check and .
This confirms that the integration is working, and you can now start configuring Okta Privileged Access.
Manual setup
If your org isn't yet using automated provisioning, you must add the Okta Privileged Access OIN app to your Okta org, add an admin user, enable provisioning, and assign users and groups.
Complete the following steps to set up Okta Privileged Access:
- Add the Okta Privileged Access app to your Okta org
- Assign an admin to Okta Privileged Access
- Verify SSO and user configuration
- Enable provisioning
- Assign users and groups
- Push groups to Okta Privileged Access
Add the Okta Privileged Access app to your Okta org
You can install only one instance of Okta Privileged Access to your Okta org.
-
In the Admin Console, go to .
- Select Browse App Catalog.
- Search for Okta Privileged Access in the search field and select it from the list.
- Select Add Integration.
- Enter a team name.
- Select Done.
After the Okta Privileged Access app is integrated into your Okta org, Single Sign-On (SSO) is automatically enabled. To view the SSO configuration, select the Sign On tab on your Okta Privileged Access app.
Assign an admin to Okta Privileged Access
- From the Applications page, select Okta Privileged Access .
- Go to the Assignments tab and select .
- Identify your account in the list and select Assign.
- Select Save and Go Back, then select Done.
Verify SSO and user configuration
After you successfully install the Okta Privileged Access app, it appears on your dashboard under My Apps. SSO is automatically configured. You can now sign in to the app.
- From your dashboard, select the Okta Privileged Access app.
- In the Okta Privileged Access Admin Console, you can view assigned users and groups. At this stage, one user is registered, and admins aren't configured. Okta adds more users and groups in the next steps.
Enable provisioning
- Go to the Provisioning tab and select Configure API Integration.
- Select Enable API Integration.
- Select Authenticate with Okta Privileged Access .
- On the dialog that appears, select your Okta Privileged Access team.
-
Enter a name for a service account and select Approve. You can use any name, such as svc-scim. The service account is automatically created in Okta Privileged Access for use by the Okta SCIM integration.
- Select Save.
- Select Edit.
- Select Create Users, Update User Attributes, and Deactivate Users provisioning options.
- Select Save.
Assign users and groups
You can assign users and groups to the Okta Privileged Access app in your Okta org. You can create groups that reflect the admin structure in Okta Privileged Access. For example, create a PAM admin group, a security admin group, and a resource admin group. Assign these groups to the app, and then push the groups to your Okta Privileged Access team.
-
Go to the Assignments tab.
-
The users assigned to the Okta Privileged Access app appear.
To assign users or groups to an app, see Assign an app integration to a user and Assign an app integration to a group.
Push groups to Okta Privileged Access
You can use Group Push to push existing Okta groups and their memberships to Okta Privileged Access. See Configure group sync.
After the Group Push operation is completed, user groups pushed from the Okta org to Okta Privileged Access will be visible under Okta Privileged Access. Check and .
This confirms that the integration is working and you can now start configuring Okta Privileged Access.