Skip to main content
The Okta integration pulls user provisioning, MFA enrollment, and access-assignment data from your Okta org into Regentra. This data automatically evidences the access-review, provisioning, authentication, and least-privilege controls.

What it provides

  • User sync — Active and deactivated users; feeds the access-review and provisioning controls
  • Per-user MFA enrollment — Feeds the authentication control
  • Group memberships and assigned applications — Feeds the least-privilege control

Setup

1

Sign in to your Okta admin console

Use a service-account user with a read-only admin role for least privilege.
2

Open Security → API → Tokens

Navigate to the API tokens section in your Okta admin console.
3

Create a token

Click Create Token and name it something descriptive like Regentra Compliance.
4

Copy the token immediately

Okta will not show the token again after this screen.
5

Enter credentials in Regentra

In Regentra, go to Settings → Integrations → Okta. Paste the token and your Okta domain (e.g. mycompany.okta.com). Save and test the connection.

Sync frequency

  • Identity sync (users, MFA enrollment, group/app assignments) runs every 4 hours on the hour
  • System log poll (sign-in events, factor activity) runs hourly at :30 — aligned with the Duo auth-log poll to spread load
  • Manual sync can be triggered at any time from the integration card
Manual and scheduled syncs are serialized per organization so a Sync Now during a scheduled run waits for it to finish.

Frequently asked questions

Read-only is enough. Okta API tokens inherit the role of the user that created them. Best practice: create the token from a service-account user with a read-only admin role (e.g. Read-only administrator), so the token can never modify users, MFA factors, or apps even if it leaks.
Okta API tokens are valid until used at least once every 30 days, or rotated by an admin. Regentra polls daily, so tokens stay alive automatically. If you rotate manually, paste the new token; the old one stops working immediately.
API token for now. OAuth-based service-to-service is on the roadmap but not required for evidence sync.