Snowflake integration
Integrate Identity Security Posture Management (ISPM) with your Snowflake account.
Generate SQL Command
-
In the Identity Security Posture Management console, go to .
-
Select Snowflake.
-
In the Source Name field, enter a name for this source.
-
In the Generate SQL Command section, enter the following values:
-
Username / Login Name: Keep the default value or click Edit to make changes.
-
Role: Keep the default value or click Edit to make changes.
-
Warehouse name: Any standard extra-small warehouse. You can use an existing one or create one.
If you exit the integration window, the values for these fields are reset.
-
-
Click Generate SQL Command.
-
Copy or download the SQL command that you created. You need it later.
To change values for any of these fields after generating a SQL command, you must generate a new SQL command.
Create a Snowflake user
-
Sign in to Snowflake with an ACCOUNTADMIN role.
-
Click Worksheets.
-
Click + Create and select SQL Worksheet to add an SQL worksheet.
-
Paste the SQL command you generated earlier in the worksheet.
-
Click Run All.
-
From the Results tab, copy the SNOWFLAKE_ACCOUNT identifier and store it safely.
Allowlist ISPM IP addresses
If your Snowflake account is restricted by network policies, follow theses steps to add the Okta ISPM server IP addresses to your allowlist:
-
In Snowflake, use the sidebar to go to .
-
Click + Network Rule.
-
Enter a network rule name and choose where to create the rule.
-
Select IPv4 as the Type.
-
Select Ingress as the Mode.
-
Under Identifiers, add the following IP addresses:
-
18.98.16.160/27
-
3.44.64.96/27
-
3.40.0.96/27
-
13.52.68.184
-
54.193.209.206
-
13.57.96.208
-
184.72.14.192
-
13.57.65.107
-
13.57.96.250
-
-
Click Create Network Rule.
-
Go to the Network Policies tab.
-
Click + Network Policy.
-
Enter a network policy name.
-
Click Allowed.
-
Under Select rule, select the rule you created earlier.
-
Click Create Network Policy.
Share the parameters with ISPM
-
In the Identity Security Posture Management console, go to .
-
Select Snowflake.
-
In the Snowflake Account Identifier field, enter the full Snowflake account identifier that you copied earlier.
-
Click Submit.
If you leave this screen before clicking Submit, the Snowflake account identifier field becomes inactive. You must re-enter the warehouse name and generate a new SQL command to enable the Snowflake account identifier field.
