Okta
Connect Okta to Radiant Security to forward authentication and admin activity logs for AI triage, and enable identity response actions. -
Last updated
Was this helpful?
Connect Okta to Radiant Security to forward authentication and admin activity logs for AI triage, and enable identity response actions. -
Okta is an identity and access management (IAM) platform that authenticates workforce and customer users across web, mobile, and on-premises applications, defending against credential theft, account takeover, and unauthorized access. Connecting Okta forwards System Log records to Radiant Security via the Okta API, and enables identity response actions through the same connection. Radiant uses Okta authentication and admin telemetry to surface anomalous logins, MFA failures, and privilege changes, giving analysts the identity context needed to triage account-compromise alerts.
At the end of this configuration, you provide Radiant Security with the following values:
Okta domain, in the form https://my-org.okta.com
API token
The token is used for both data ingestion and Okta response actions. Response actions require write scopes on users, sessions, and network zones, so generate the token from a Super Admin service account. A read-only admin is sufficient only if you do not plan to enable response actions.
API tokens are valid only while the user who created them remains active. Tokens issued by deactivated users are rejected. Use a service account that will not be deactivated and whose permissions will not change. See Okta's API token management guidance for details.
Sign in to Radiant Security.
From the navigation menu, select Settings > Credentials and click + Add Credential.
Search for and select Okta, then click Configure Credential.
Under Credential Name, enter a descriptive name (e.g., Okta-Credentials).
Under Required Credentials, enter the values from Okta:
Okta domain, in the form https://my-org.okta.com
API token
Click Add Credential to save the configuration.
From the navigation menu, select Settings > Data Connectors and click + Add Connector.
Search for and select Okta, then click Data Feeds.
Under Select your data feeds, select Okta Alerts & Activity Logs and click Credentials.
From the drop-down, select the Okta credential you created.
Click Add Connector to save the configuration.
The Okta action connector lets Radiant execute identity response actions against the same Okta tenant, including user account lockdown, session termination, and IP blocking through Okta Network Zones. For the full list of supported actions and the Okta scopes each one requires, see Okta actions.
From the navigation menu, select Settings > Action Connectors and click + Add Connector.
Search for and select Okta.
Confirm that the Okta credential is selected.
Click Add Connector.
After Okta begins forwarding, confirm alerts and events are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by rs_connectorType:"okta_system_logs".
Confirm recent alerts and events appear.
Allow several minutes for alerts and events to be parsed, indexed, and available for search.
Last updated
Was this helpful?
Was this helpful?