View the workload identities inventory
Review the workload identities inventory to assess the security posture of non-human apps across Okta, Salesforce, and Microsoft Entra ID.
About this task
Early Access release
The Inventory displays summaries and details of your workload identities.
- In the Identity Security Posture Management console, go to Inventory > Non-human identities > Workload identities.
-
Review the summaries at the top of the page.
- Workload identities: The total number of workload identities discovered across all connected sources.
- Identities by source: A summary of workload identities by identity provider: Okta, Salesforce, or Microsoft Entra ID.
- Identities and credentials: A summary of workload identities grouped by their authentication method.
- Credential rotation: A summary of credential rotation status across all workload identities, highlighting apps with stale or unrotated credentials.
-
Review the workload apps table.
- Workload identity name: The name of the workload identity, with an icon indicating its source: Okta, Microsoft Entra ID, or Salesforce.
- Active credentials: All authentication methods configured for the app, such as client secrets and certificates.
- Last rotation: The oldest credential rotation date across all sign-in methods for the app.
- High privileges: The app's permission level (Non-Privileged, Privileged, or High Privileges).
- Status: Active, inactive, or expired.
- Date created: The date the workload identity was created.
-
Review the credential details in the side pane.
- Creation time: When the credential was created.
- Expires at: The date when the credentials expire, if applicable.
- Status: Active, inactive, or expired.
-
Review the permissions details in the side pane.
- Permission name: The permission as it's named in the app.
- Permission type: Role, API scope, Application Permissions, or Delegated Permissions.
- Target application: The app where the permission applies.