Connect Okta to Black Cat SSPM
Connect your Okta organization so Black Cat can review users, MFA enrolment, admin roles, app integrations and sign-on policies.
≈ 10 min · audit access · write-capable permissions are flagged below
What Black Cat reads, and why
| Permission | What it lets Black Cat do | Status |
|---|---|---|
okta.users.read | Lets Black Cat list users, their status, last login and group membership. | Required |
okta.policies.read | Lets Black Cat review password, sign-on and authentication policies. | Required |
okta.apps.read | Lets Black Cat review application integrations, their sign-on method, assignments and OAuth scopes. | Required |
okta.roles.read | Lets Black Cat see which accounts hold administrator roles and how far each role reaches. | Required |
okta.factors.read | Lets Black Cat see which multi-factor methods each user has enrolled. | Required |
okta.apiTokens.read | Lets Black Cat list Okta API tokens and when they were last used. | Required |
okta.logs.read | Lets Black Cat review sign-in and administrative events for dormant accounts and unusual activity. | Optional |
okta.users.manage | Lets Black Cat revoke an application's access for a user when you act on a finding. | Optional Write (write-capable permission) |
okta.threatInsights.read | Lets Black Cat see whether Okta ThreatInsight is switched on and how it is configured. | Optional |
okta.networkZones.read | Lets Black Cat review the network zones your sign-on policies rely on. | Optional |
What you'll need
- Organization URL Required — Your Okta address, for example https://acme.okta.com.
- Service app client ID Required — Shown on the read-only service app you create in the Okta admin console.
- Private key (PEM) Required — Generated with the service app and held only by you and Black Cat.