Set up the Secure Access Monitor plugin

The Secure Access Monitor (SAM) plugin is a managed Chrome extension used to monitor unmanaged OAuth grants and transfer the collected data to Okta ISPM.

About this task

The SAM plugin is available by default with an Okta for AI Agents license. If you have the Okta ISPM license only, contact Support for plugin access.

This feature is excluded from the Okta for AI Agents - Core SKU for FedRAMP Moderate and High customers, and is not available in Okta for US Military cells. See the Okta US Public Sector Limitations or Exceptions support article.

Before you begin

  • Your ISPM tenant is in the same region as your Okta tenant. This feature isn't enabled for cross-region access.
  • Your org is connected to Google Chrome Enterprise. The plugin only works on managed browsers. See Integrate Okta with Chrome Enterprise.
  • Your browsers are enrolled in Chrome Enterprise Core. See Enroll cloud-managed Chrome browsers. Third-party MDM solutions alone are insufficient. On Windows, you also need the required registry or MDM settings.
  • You have the super admin role.
  • You have access to the Google Admin Console.
  • You have an active Okta ISPM tenant (ISPM or Okta AI license).
  • Your security policies don't block OAuth grants.
  • Be aware that the SAM client certificate interferes with manual certificate selection flows (Smart Card, PIV, Legacy Device Trust).

  • If you use a SASE solution, configure it to exempt the Okta URL from TLS inspection.

  • Your browser policies don't pin the browser to a specific client certificate.

Procedure

  1. Sign in to the Google Admin Console as an admin.
  2. Go to Chrome browser > Connectors.
  3. Select the target organizational unit.
  4. Click + New provider configuration. If a configuration already exists (for example, Okta Device Trust), add Google CA as an additional provider. Both apply to the same OU.
  5. Find Google Certificate Authority and click Set up.
  6. Click Provision.
  7. Click Details for Google Certificate Authority.
  8. Download GoogleCertificateAuthority.pem.
  • Configure the client certificate setting
    1. Sign in to the Google Admin Console.
    2. Go to Chrome browser > Settings.
    3. Select the appropriate organizational unit.
    4. On the UI & browser settings tab, click Client certificates.
    5. In Automatically select for these sites, enter the following pattern, replacing <org>:{"pattern": "https://.mtls.okta.com", "filter": {"ISSUER": {"CN":"Chrome Enterprise CA"}}}Preview orgs use.mtls.oktapreview.com.
    6. Verify at chrome://policy/ that the AutoSelectCertificateForUrls entry appears.
  • Upload the certificate authority to the Okta Admin Console
    1. Go to Security > Device Integrations.
    2. Click the Certificate authority tab.
    3. Click Add certificate authority.
    4. For Issue certificate to, select Secure Access Monitor plugin.
    5. Upload the CA certificate chain. The file type must be .pem.
  • Install the plugin
    1. Sign in to the Google Admin Console.
    2. Go to Chrome browser > Apps & extensions.
    3. Click the Users & browsers tab.
    4. Select your Okta organizational unit. To test on a subset of users, create a group or OU.
    5. Click the icon and select Add Chrome app or extension by ID.
    6. Enter the SAM plugin ID: galipinbbdandeicdicjbalcbpdbljjj.
    7. Click Save.
    8. Click the Secure Access Monitor extension to open its settings.
    9. Change Allow install to Force install.
    10. In Policy for extensions, enter the following JSON replacing <org>: { "orgUrl": { "Value": "https://<org>.okta.com" } }
    11. Click Save.

    What to do next

    Have end users sign in to their managed Chrome profiles and to the Okta End-User Dashboard using the org URL.

    Then, verify your installation.