Okta Privileged Access user guide
As an Okta Privileged Access user, you can access privileged resources based on the groups you belong to and the access granted to those groups. This guide covers how to access and manage each resource type available in your dashboard.
Access server resources
Your dashboard lists the servers you have been granted access to. Connect to them through SSH or RDP using your Okta identity. Some servers require Access Requests approval before you can connect.
- Go to My Privileged Access.
- Select the Actions menu on the server you want to connect to.
- Click Connect.
- On the dialog that appears, select an account.
- Click Connect. The Okta Privileged Access client opens, where you can select an account or view any pending approval notifications.
- If a server account requires approval:
- Select an account.
- Click Request approval. Okta Privileged Access automatically creates an access request. When your request is approved, you can connect again.
Active Directory accounts
Your dashboard shows the Active Directory (AD) domains associated with your account. Within each domain, you can access AD accounts, reveal credentials, and review credential history.
Access an Active Directory account
- Go to .
- Select a domain name to view its accounts.
- Select an account name to open the account detail page.
- Click Request access for the access method you want to use.
- When your request is approved, complete any additional required steps, such as MFA or checkout.
- Click Show credentials to view the username and password.
- Click Done when you are finished.
View credential version history
The Version History tab on the account detail page lists up to 10 recent credential versions for that account. Use it to review past rotations or to reveal the credentials for a specific version. Previous versions are read-only and can't be restored as the active version.
View the version history for an account:
- Go to .
- Select a domain name, then select an account name.
- Select the Version History tab.
Reveal the credentials for a specific version:
- On the Version History tab, expand the version that you want to access.
- Click Show credentials.
- Click Done when you are finished.
SaaS app accounts
View SaaS app account credentials
- Go to .
- Select an app instance.
- Select the account assigned to the app.
- Click Show credentials to view the password.
- Optional. Click Override to update the password stored in Okta Privileged Access to match the current password used by the app. Use this when the app password was changed outside of Okta Privileged Access and the stored credentials no longer match.
- Optional. Click Rotate password to generate a new password for the account.
Generate a password for a SaaS app
Use the password generator to update the password for an unmanaged SaaS app.
- Go to .
- Select an app instance.
- Select .
- Click the lock icon beside the Password field.
- Use the Generate a strong password form to update the password settings.
- Click Save.
View credential version history
The Version History tab on the account detail page lists up to 10 recent credential versions for that account. Use it to review past rotations or to reveal the credentials for a specific version. Previous versions are read-only and can't be restored as the active version.
View the version history for an account:
- Go to .
- Select an app instance.
- Select an account.
- Select the Version History tab.
Reveal the credentials for a specific version:
- On the Version History tab, expand the version that you want to access.
- Click Show credentials.
- Click Done when you are finished.
Okta service accounts
View Okta service account credentials
- Go to .
- Select an account name to open the account detail page.
- Click Show credentials to view the username and password.
- Click Done when you are finished.
View credential version history
The Version History tab on the account detail page lists up to 10 recent credential versions for that account. Use it to review past rotations or to reveal the credentials for a specific version. Previous versions are read-only and can't be restored as the active version.
View the version history for an account:
- Go to .
- Select an account name.
- Select the Version History tab.
Reveal the credentials for a specific version:
- On the Version History tab, expand the version that you want to access.
- Click Show credentials.
- Click Done when you are finished.
Database accounts
Your dashboard lists database instances with their assigned aliases. Each instance shows the available access methods and their security settings, such as MFA or checkout.
Reveal a database user account
- Go to .
- Select the database you want to access. A list of discovered accounts you can access appears.
- Select an account.
- Complete any required steps, such as Access Requests, MFA, or checkout.
- Click Show credentials.
- Copy the username and password into your database client.
- Click Done when you are finished.
Create and manage secrets
When you are granted access to a secret folder, your level of access depends on the permissions assigned to you. Depending on your permissions, you can create, reveal, update, or delete secrets and folders. If an Access Requests condition is enabled in the policy, you must request approval before performing some actions within the folder. To use CLI commands, see Use the Okta Privileged Access client.
Reveal a secret
Okta Privileged Access users can reveal secrets to view key names and secret values.
- Go to .
- Open a top-level folder.
- Select a nested secret folder.
- Click Reveal value.
Create a nested folder
- Go to .
- Open a top-level folder.
- Select .
- Enter a folder name and description.
- Click Submit.
Create a secret
- Go to .
- Open a top-level folder.
- Select .
- On the Secret name page, enter the following:
Field Task Name Give the secret a name. The name can only contain alphanumeric characters (a-Z, 0–9), hyphens (-), underscores (_), and periods (.)
Description Enter a description. Add templated key values Create a secret from a predefined template.
-
Click Add templated key values.
-
Select one of the following templates:
-
API key
-
Username / password
-
-
Enter a Secret Value. The template field names are pre-populated.
Note:Secret key names in key-value pairs are case-sensitive.
-
- Optional. Click Add key value to add a key-value pair manually.
- Click Save secret.
Move a secret
Early Access release
You can move a secret to a different folder to better align with your team's organizational structure or security policies.
- Sign in to your Okta Privileged Access account.
- Go to .
- On the secret you want to move, click the Actions menu and then select Move.
- Select the destination folder.
- Click Move.
Reveal a secret
Okta Privileged Access users can reveal secrets to view key names and secret values.
- Sign in to your Okta Privileged Access account.
- Go to .
- Open a top-level folder.
- Select a nested secret folder.
- Click Reveal value.
View credential version history
The Version History tab on the account detail page lists up to 10 recent credential versions for that account. Use it to review past rotations or to reveal the credentials for a specific version. Previous versions are read-only and can't be restored as the active version.
View the version history for a secret:
- Go to .
- Open a top-level folder.
- Select a secret.
- Select the Version History tab.
Reveal the credentials for a specific version:
- On the Version History tab, expand the version that you want to access.
- Click Show credentials.
- Click Done when you are finished.
Delete a secret folder
- Go to .
- Open a top-level folder.
- Select a nested secret folder.
- Select the Actions menu, then click Delete.
- Click Delete secret folder.
Delete a secret
- Go to .
- Open a top-level folder.
- Select a nested secret folder.
- Select the Actions menu, then click Delete.
- Click Delete secret.