Set up Okta Privileged Access

When your org's Okta Privileged Access subscription becomes active, Okta automatically provisions the Okta Privileged Access app, creates your team, and enables SCIM provisioning. Your team name is generated automatically, so you don't need to add the app or configure provisioning manually. Okta also automatically syncs the super admins in your org to Okta Privileged Access and adds them to the owners group, granting them the PAM admin role.

Complete the following steps to finish setting up Okta Privileged Access:

  1. Assign an admin to Okta Privileged Access
  2. Verify SSO and user configuration
  3. Assign users and groups
  4. Push groups to Okta Privileged Access

Prerequisites

You must have an admin role in your Okta org.

Assign an admin to Okta Privileged Access

Super admins are added to the owners group automatically. To grant PAM admin access to another user, assign them to the app.

  1. From the Applications page, click Okta Privileged Access .
  2. Go to the Assignments tab and click Assign > Assign to People.
  3. Identify your account in the list and click Assign.
  4. Click Save and Go Back, then click Done.

Verify SSO and user configuration

After your subscription is activated, the Okta Privileged Access app appears on your End-User Dashboard under My Apps with SSO already configured. You can sign in to the app.

  1. From your dashboard, click the Okta Privileged Access app.
  2. In the Okta Privileged Access Admin Console, you can view assigned users and groups. At this stage, one user is registered, and admins aren't configured. Okta will add more users and groups in the next steps.

Assign users and groups

You can assign users and groups to the Okta Privileged Access app in your Okta org. You can create groups that reflect the admin structure in Okta Privileged Access. For example, create a PAM admin group, a security admin group, and a resource admin group. Assign these groups to the app, and then push the groups to your Okta Privileged Access team.

  1. Go to the Assignments tab.

  2. Users added to the Okta Privileged Access displays.

    To assign users or groups to an app, see Assign an app integration to a user and Assign an app integration to a group.

Push groups to Okta Privileged Access

You can use Group Push to push existing Okta groups and their memberships to Okta Privileged Access. See Configure group sync.

After the Group Push operation is completed, user groups pushed from the Okta org to Okta Privileged Access will be visible under Okta Privileged Access. Check Directory > Users and Directory > Groups.

This confirms that the integration is working and you can now start configuring Okta Privileged Access.