Review and assess browser OAuth grants

Review the AI agents that your users have granted access to.

About this task

After the SAM plugin is set up and sending data, ISPM analyzes the captured OAuth grants and lists them on the Browser OAuth grants page. Initial data can take up to two days to appear. After that, it syncs daily.

Use this page to review the AI agents your users have granted access to, investigate the connections, and remediate risky grants. ISPM marks AI-related grants with an AI label.

Before you begin

  • Ensure that the SAM browser plugin is configured and deployed to your managed browsers.
  • Confirm that the plugin is set for the Okta org that's connected as an ISPM source.

Procedure

  1. In the ISPM console, go to Inventory > AI agents > Browser OAuth grants.
  2. Review the table for client and resource app connections:
    • Client app: The app that requested access.
    • Resource app: The target app that holds the data being accessed.
    • First seen / Last seen: When the connection was first and most recently observed.
  3. Select a row to investigate the connection, including the authorizing users and the scopes granted.
  4. In the Category filter, choose AI.
  5. For a suspicious grant, contact the user to confirm intent.
    • If the grant is authorized and AI-related, click Register to bring the AI agent under management. Registering agents requires Okta for AI Agents.
    • If the grant is unauthorized, perform the appropriate remediation.
  • Assess grants with privileged OAuth scopes

    ISPM raises the AI Agent OAuth Grant with Privileged Scopes issue to track grants that carry risky scopes. Scopes that give over-privileged access to the resource app are considered risky.

    1. In the ISPM console, open Issues > Prioritized report.
    2. Locate and select the AI Agent OAuth Grant with Privileged Scopes issue.
    3. Assess the client and resource apps, the excessive scopes, the browser user, and related context.
    4. Select an OAuth grant for more detail.
    5. Remediate based on the resource app type.
      • Managed apps: Reduce or revoke the scopes in the app's admin console.
      • Unmanaged apps: Contact the user who granted the scopes and ask them to reduce or revoke.
    6. Optional. Dismiss the issue using its dismiss icon.
      • Snooze: ISPM shows the issue again if it recurs.
      • Acknowledge: ISPM stops displaying the issue.
      • False positive: For an incorrect or irrelevant detection.