Overview
The Okta integration polls the Okta System Log API and ingests events covering:
- Successful and failed logins, including MFA challenges
- Password changes, account lockouts, and session termination
- User, group, and application lifecycle changes
- Admin console activity and policy modifications
Prerequisites
- An Okta org with Super Admin or a custom admin role that includes the
okta.logs.readpermission. - The fully qualified Okta domain (for example,
yourorg.okta.comoryourorg.oktapreview.com).
Step 1: Create an API token in Okta
- Sign in to the Okta Admin Console.
- Navigate to Security → API → Tokens.
- Click Create token.
- Give the token a descriptive name such as
atatus-siem. - Copy the generated token value immediately — Okta only shows it once.
Note: API tokens inherit the permissions of the user that creates them. Create the token from a service account that has only the read permissions Atatus needs, not from a personal admin account.
Step 2: Connect Okta in Atatus
- In Atatus, go to Security → Cloud SIEM → Integrations.
- Locate the Okta card and click Connect.
- Fill in the form:
| Field | Description | Example |
|---|---|---|
| Okta API Token | The token created in Step 1. | 00aB...xyz |
| Okta Domain | Your Okta tenant domain, without https://. |
yourorg.okta.com |
| Poll Interval (minutes) | How often to fetch new events. | 5 |
| Enabled | Turn collection on. | true |
- Click Connect.
Verification
- The Okta card on the Integrations tab shows Configured.
- Within one poll cycle, events appear in Security → Cloud SIEM → Audit Logs → Events with the source
okta.
+1-415-800-4104