Okta Privileged Access user guide

As an Okta Privileged Access user, you can access privileged resources based on the groups you belong to and the access granted to those groups. This guide covers how to access and manage each resource type available in your dashboard.

Access server resources

Your dashboard lists the servers you have been granted access to. Connect to them through SSH or RDP using your Okta identity. Some servers require Access Requests approval before you can connect.

  1. Go to My Privileged Access.
  2. Select the Actions menu on the server you want to connect to.
  3. Click Connect.
  4. On the dialog that appears, select an account.
  5. Click Connect. The Okta Privileged Access client opens, where you can select an account or view any pending approval notifications.
  6. If a server account requires approval:
    1. Select an account.
    2. Click Request approval. Okta Privileged Access automatically creates an access request. When your request is approved, you can connect again.

Active Directory accounts

Your dashboard shows the Active Directory (AD) domains associated with your account. Within each domain, you can access AD accounts, reveal credentials, and review credential history.

Access an Active Directory account

  1. Go to My Privileged Access > Active Directory .
  2. Select a domain name to view its accounts.
  3. Select an account name to open the account detail page.
  4. Click Request access for the access method you want to use.
  5. When your request is approved, complete any additional required steps, such as MFA or checkout.
  6. Click Show credentials to view the username and password.
  7. Click Done when you are finished.

View credential version history

The Version History tab on the account detail page lists up to 10 recent credential versions for that account. Use it to review past rotations or to reveal the credentials for a specific version. Previous versions are read-only and can't be restored as the active version.

View the version history for an account:

  1. Go to My Privileged Access > Active Directory .
  2. Select a domain name, then select an account name.
  3. Select the Version History tab.

Reveal the credentials for a specific version:

  1. On the Version History tab, expand the version that you want to access.
  2. Click Show credentials.
  3. Click Done when you are finished.

SaaS app accounts

View SaaS app account credentials

  1. Go to My Privileged Access > SaaS apps.
  2. Select an app instance.
  3. Select the account assigned to the app.
  4. Click Show credentials to view the password.
  5. Optional. Click Override to update the password stored in Okta Privileged Access to match the current password used by the app. Use this when the app password was changed outside of Okta Privileged Access and the stored credentials no longer match.
  6. Optional. Click Rotate password to generate a new password for the account.

Generate a password for a SaaS app

Use the password generator to update the password for an unmanaged SaaS app.

  1. Go to My Privileged Access > SaaS apps.
  2. Select an app instance.
  3. Select Show credentials > Edit password.
  4. Click the lock icon beside the Password field.
  5. Use the Generate a strong password form to update the password settings.
  6. Click Save.

View credential version history

The Version History tab on the account detail page lists up to 10 recent credential versions for that account. Use it to review past rotations or to reveal the credentials for a specific version. Previous versions are read-only and can't be restored as the active version.

View the version history for an account:

  1. Go to My Privileged Access > SaaS apps.
  2. Select an app instance.
  3. Select an account.
  4. Select the Version History tab.

Reveal the credentials for a specific version:

  1. On the Version History tab, expand the version that you want to access.
  2. Click Show credentials.
  3. Click Done when you are finished.

Okta service accounts

View Okta service account credentials

  1. Go to My Privileged Access > Okta service accounts.
  2. Select an account name to open the account detail page.
  3. Click Show credentials to view the username and password.
  4. Click Done when you are finished.

View credential version history

The Version History tab on the account detail page lists up to 10 recent credential versions for that account. Use it to review past rotations or to reveal the credentials for a specific version. Previous versions are read-only and can't be restored as the active version.

View the version history for an account:

  1. Go to My Privileged Access > Okta service accounts.
  2. Select an account name.
  3. Select the Version History tab.

Reveal the credentials for a specific version:

  1. On the Version History tab, expand the version that you want to access.
  2. Click Show credentials.
  3. Click Done when you are finished.

Database accounts

Your dashboard lists database instances with their assigned aliases. Each instance shows the available access methods and their security settings, such as MFA or checkout.

Reveal a database user account

  1. Go to My Privileged Access > Databases.
  2. Select the database you want to access. A list of discovered accounts you can access appears.
  3. Select an account.
  4. Complete any required steps, such as Access Requests, MFA, or checkout.
  5. Click Show credentials.
  6. Copy the username and password into your database client.
  7. Click Done when you are finished.

Create and manage secrets

When you are granted access to a secret folder, your level of access depends on the permissions assigned to you. Depending on your permissions, you can create, reveal, update, or delete secrets and folders. If an Access Requests condition is enabled in the policy, you must request approval before performing some actions within the folder. To use CLI commands, see Use the Okta Privileged Access client.

Reveal a secret

Okta Privileged Access users can reveal secrets to view key names and secret values.

  1. Go to My Privileged Access > Secrets.
  2. Open a top-level folder.
  3. Select a nested secret folder.
  4. Click Reveal value.

Create a nested folder

  1. Go to My Privileged Access > Secrets.
  2. Open a top-level folder.
  3. Select Create > Create Folder.
  4. Enter a folder name and description.
  5. Click Submit.

Create a secret

  1. Go to My Privileged Access > Secrets.
  2. Open a top-level folder.
  3. Select Create > Create Secret.
  4. On the Secret name page, enter the following:
    Field Task
    Name Give the secret a name.

    The name can only contain alphanumeric characters (a-Z, 0–9), hyphens (-), underscores (_), and periods (.)

    Description Enter a description.
    Add templated key values

    Create a secret from a predefined template.

    1. Click Add templated key values.

    2. Select one of the following templates:

      1. API key

      2. Username / password

    3. Enter a Secret Value. The template field names are pre-populated.

  5. Optional. Click Add key value to add a key-value pair manually.
  6. Click Save secret.

Move a secret

Early Access release

You can move a secret to a different folder to better align with your team's organizational structure or security policies.

  1. Sign in to your Okta Privileged Access account.
  2. Go to My Privileged Access > Secrets.
  3. On the secret you want to move, click the Actions menu and then select Move.
  4. Select the destination folder.
  5. Click Move.

Reveal a secret

Okta Privileged Access users can reveal secrets to view key names and secret values.

  1. Sign in to your Okta Privileged Access account.
  2. Go to My Privileged Access > Secrets.
  3. Open a top-level folder.
  4. Select a nested secret folder.
  5. Click Reveal value.

View credential version history

The Version History tab on the account detail page lists up to 10 recent credential versions for that account. Use it to review past rotations or to reveal the credentials for a specific version. Previous versions are read-only and can't be restored as the active version.

View the version history for a secret:

  1. Go to My Privileged Access > Secrets.
  2. Open a top-level folder.
  3. Select a secret.
  4. Select the Version History tab.

Reveal the credentials for a specific version:

  1. On the Version History tab, expand the version that you want to access.
  2. Click Show credentials.
  3. Click Done when you are finished.

Delete a secret folder

  1. Go to My Privileged Access > Secrets.
  2. Open a top-level folder.
  3. Select a nested secret folder.
  4. Select the Actions menu, then click Delete.
  5. Click Delete secret folder.

Delete a secret

  1. Go to My Privileged Access > Secrets.
  2. Open a top-level folder.
  3. Select a nested secret folder.
  4. Select the Actions menu, then click Delete.
  5. Click Delete secret.