Skip to content

Connect Okta to Black Cat SSPM

Version française

Connect your Okta organization so Black Cat can review users, MFA enrolment, admin roles, app integrations and sign-on policies.

≈ 10 min · audit access · write-capable permissions are flagged below

What Black Cat reads, and why

PermissionWhat it lets Black Cat doStatus
okta.users.readLets Black Cat list users, their status, last login and group membership.Required
okta.policies.readLets Black Cat review password, sign-on and authentication policies.Required
okta.apps.readLets Black Cat review application integrations, their sign-on method, assignments and OAuth scopes.Required
okta.roles.readLets Black Cat see which accounts hold administrator roles and how far each role reaches.Required
okta.factors.readLets Black Cat see which multi-factor methods each user has enrolled.Required
okta.apiTokens.readLets Black Cat list Okta API tokens and when they were last used.Required
okta.logs.readLets Black Cat review sign-in and administrative events for dormant accounts and unusual activity.Optional
okta.users.manageLets Black Cat revoke an application's access for a user when you act on a finding.Optional Write (write-capable permission)
okta.threatInsights.readLets Black Cat see whether Okta ThreatInsight is switched on and how it is configured.Optional
okta.networkZones.readLets Black Cat review the network zones your sign-on policies rely on.Optional

What you'll need

  • Organization URL Required — Your Okta address, for example https://acme.okta.com.
  • Service app client ID Required — Shown on the read-only service app you create in the Okta admin console.
  • Private key (PEM) Required — Generated with the service app and held only by you and Black Cat.

Where to create it

What we check on Okta →

Other setup guides

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications are based on publicly available documentation and may change over time.

See your own SaaS posture in 10 minutes

Run a free posture scan — no credit card required, read-only-by-default access you can revoke any time.

Run a free posture scan