Configure BeyondTrust PowerBroker Password Safe to Interoperate with Okta via RADIUS

You can extend Adaptive MFA to your BeyondTrust PowerBroker Password Safe. This guide details how to configure PowerBroker Password Safe to use the Okta RADIUS Server AgentA software agent is a lightweight program that runs as a service outside of Okta. It is typically installed behind a firewall and allows Okta to tunnel communication between an on-premises service and Okta's cloud service. Okta employs several agent types: Active Directory, LDAP, RADIUS, RSA, Active Directory Password Sync, and IWA. For example, users can install multiple Active Directory agents to ensure that the integration is robust and highly available across geographic locations..

Okta and BeyondTrust interoperate through either RADIUS or SAMLAn acronym for Security Assertion Markup Language, SAML is an XML-based standard for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP). The SAML standard addresses issues unique to the single sign-on (SSO) solution, and defines three roles: the end user, the IDP, and the SP. 2.0. For each Password Safe deployment, you can assign one or more authentication providers. Each RADIUS authentication profile maps to to a group of usersIn Okta literature, we generally refer to "users" as the people who serve as Okta administrators. When we refer to "end users" we are generally referring to the people who the administrators serve. That is, those who use Okta chiclets to access their apps, but have no administrative control. via a filter (All Users, All Local Users, All DomainA domain is an attribute of an Okta organization. Okta uses a fully-qualified domain name, meaning it always includes the top-level domain (.com, .eu, etc.), but does not include the protocol (https). Users, Domain Contains, etc). Using RADIUS, Okta’s agent translates RADIUS authentication requests from BeyondInsight, the BeyondTrust web application and console, into Okta API calls.

For integration with Okta via SAML 2.0, in Okta, add the appAn abbreviation of application. Essentially, it is a web-based site used to perform any number of specific tasks, and requires authentication from end users by signing in. by navigating to Applications > Applications> Add Application, search for BeyondTrust MFA (RADIUS), and then click Add Application.

For the BeyondInsight SAML configuration, see the instructions on your Okta AdminAn abbreviation of administrator. This is the individual(s) who have access to the Okta Administrator Dashboard. They control the provisioning and deprovisioning of end users, the assigning of apps, the resetting of passwords, and the overall end user experience. Only administrators have the Administration button on the upper right side of the My Applications page. Console on the Sign On page for the BeyondInsight configuration.

There are five parts to the configuration, including optional settings and troubleshooting help; a list of additional resources is also provided.

Top