You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: ATPDocs/okta-integration.md
+10-10Lines changed: 10 additions & 10 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -43,23 +43,23 @@ This section provides instructions for connecting Microsoft Defender for Identit
43
43
44
44
1. Select **Security** > **API**.
45
45
46
-
:::image type="content" source="media/okta-integration/okta-side-menu-security-api.png" alt-text="Screenshot of the Okta side menu and the option to select the API tab.":::
46
+
:::image type="content" source="media/okta-integration/okta-side-menu-security-api.png" alt-text="Screenshot of the Okta user interface showing the My Apps dashboard. The left menu includes My Apps, Notifications, and Add apps. The center shows “No new notifications.” The Admin button is highlighted in the top-right corner next to the user profile.":::
47
47
48
48
1. Select **Tokens**
49
49
1. Select **Create Token**.
50
50
51
-
:::image type="content" source="media/okta-integration/create-an-okta-token.png" alt-text="Screenshot showing how to create an API token.":::
51
+
:::image type="content" source="media/okta-integration/create-an-okta-token.png" alt-text="Screenshot of the Okta admin portal showing the left-hand navigation menu. The Security section is expanded, displaying options such as General, Authentication Policies, Identity Providers, and others. The API option is highlighted at the bottom of the Security section, indicating where to access API settings.":::
52
52
53
53
1. In the Create token pop-up:
54
54
1. Enter a name for your Defender for Identity token
55
55
2. Select Any IP
56
56
3. Select Create token.
57
57
58
-
:::image type="content" source="media/okta-integration/enter-okta-token-details.png" alt-text="Screenshot showing where to enter the name of your Okta token.":::
58
+
:::image type="content" source="media/okta-integration/enter-okta-token-details.png" alt-text="Screenshot of the Okta admin portal on the API > Tokens tab. The interface displays options for Authorization Servers, Tokens, and Trusted Origins. The “Create token” button is highlighted in the lower left area of the screen, indicating where to generate a new API token.":::
59
59
60
60
1. In the **Token created successfully** pop-up, copy the **Token value** and store it securely. This token is used to connect Okta to Defender for Identity.
61
61
62
-
:::image type="content" source="media/okta-integration/okta-token-created-successfully.png" alt-text="Screenshot of the token created successfully pop up message.":::
62
+
:::image type="content" source="media/okta-integration/okta-token-created-successfully.png" alt-text="Screenshot of the Okta token creation confirmation dialog. A success message states, “Token created successfully!” followed by a warning to save the token now, as it won’t be shown again. Below, the Token Value field displays the token with a copy button.":::
63
63
64
64
### Add Custom user attributes
65
65
@@ -81,7 +81,7 @@ This section provides instructions for connecting Microsoft Defender for Identit
81
81
1. Select Save.
82
82
1. Verify that the three custom attributes you added are displayed correctly.
83
83
84
-
:::image type="content" source="media/okta-integration/okta-custom-attributes.png" alt-text="Screenshot showing that all three custom attributes have been added correctly.":::
84
+
:::image type="content" source="media/okta-integration/okta-custom-attributes.png" alt-text="Screenshot of the Okta Attributes page. The table lists custom attributes with columns for Display Name, Variable Name, Data type, and Attribute Type. Three attributes are shown: ObjectGuid, DistinguishedName, and ObjectSid. An “Add Attribute” button appears at the top of the table..":::
85
85
86
86
87
87
### Create a custom Okta role
@@ -101,7 +101,7 @@ After assigning both roles, you can remove the Super Admin role. This ensures th
101
101
-**View roles, resources, and admin assignments**
102
102
1. Select **Save role**.
103
103
104
-
:::image type="content" source="media/okta-integration/okta-permissions.png" alt-text="Screenshot showing the a list of Okta permissions that need to be assigned when adding a custom role.":::
104
+
:::image type="content" source="media/okta-integration/okta-permissions.png" alt-text="Screenshot showing a list of Okta permissions that need to be assigned when adding a custom role. The User section includes selected permissions such as Suspend users, Unsuspend users, and Clear users sessions. The Identity and Access Management section includes View roles, resources, and admin assignments.":::
105
105
106
106
### Create a resource set
107
107
@@ -112,7 +112,7 @@ After assigning both roles, you can remove the Super Admin role. This ensures th
112
112
-**All users**
113
113
-**All Identity and Access Management resources**
114
114
115
-
:::image type="content" source="media/okta-integration/resource-set-information.png" alt-text="Screenshot showing how to enter all the users and identitity and access management resources.":::
115
+
:::image type="content" source="media/okta-integration/resource-set-information.png" alt-text="Screenshot showing the Resource set information page in Okta. The resource set is named and described as "Microsoft Defender for Identity." Under Resources, two entries are listed: "Users" with "All users" and "Identity and Access Management" with "All Identity and Access Management resources," each with edit and delete icons.":::
116
116
1. Select **Save selection**.
117
117
118
118
### Assign the custom role and resource set
@@ -133,17 +133,17 @@ To complete the configuration in Okta, assign the custom role and resource set t
:::image type="content" source="media/okta-integration/select-settings-okta-integration.png" alt-text="Screenshot showing how to connect your Okta instance in the Defender portal.":::
136
+
:::image type="content" source="media/okta-integration/select-settings-okta-integration.png" alt-text="Screenshot showing the Microsoft Defender for Identity settings page. The Settings menu is selected in the left-hand navigation pane, and under General, the Okta Integration option is highlighted. The right panel displays options to connect or disconnect Okta instances":::
137
137
138
138
1. Select **+Connect Okta instance**.
139
139
1. Enter your Okta domain (for example, acme.okta.com).
140
140
1. Paste the API token you copied from your Okta account.
141
141
1. Select **Save**.
142
142
143
-
:::image type="content" source="media/okta-integration/connect-okta-instance.png" alt-text="Screenshot showing the connect Okta instance pop up page.":::
1. Verify that your Okta environment appears in the table as enabled.
145
145
146
-
:::image type="content" source="media/okta-integration/new-okta-domain.png" alt-text="Screenshot showing how your Okta environment appears in the Identities table once it has been enabled.":::
146
+
:::image type="content" source="media/okta-integration/new-okta-domain.png" alt-text="Screenshot showing the Connect Okta Instance configuration screen in the Microsoft Defender portal. The screen includes required fields for Okta domain name and API token. The integration is toggled to “Enabled.” A blue Save button appears at the bottom of the screen.":::
0 commit comments