Skip to main content
{ Identity and Access / Reporting and Compliance }

Okta Posture Report

Delivers a weekly Okta report on admin factors, API tokens and the roles they carry, and policy changes, with what changed since last week.

What this agent does

This read-only agent checks the health of an Okta organization every week. It measures which active users have no enrolled authenticator or only a weak one, and which admins lack a phishing-resistant factor. It lists admin role holders and dormant accounts that are still active. It lists API tokens and the admin role each one carries. It compares the authentication, session, and password policies and the network zones with last week and names who changed what. It summarizes the suspicious sign-in events from the System Log.

The challenge

An Okta API token carries the current role of the admin who created it. A super admin creates a token for a migration, and the token runs as super admin for as long as a service uses it. An admin role reaches a user through a group, and nobody checks that admin's factors. An admin keeps a password and SMS as the only factors. A policy rule is relaxed during an incident and never restored. Nobody reviews the factors, admin roles, tokens, and policies together.

The solution

The agent reads users, factors, admin roles, policies, API tokens, and the System Log each week. It compares them with the previous week and leads with what changed. It ties each API token to the role of the admin who created it. It reports a count it cannot read as not available, never as zero. Provides a weekly briefing with the fix for each item.

Workflow

  1. 01

    Check users and factors

    List active users with their enrolled authenticators and last sign-in, and flag weak factors, no factors, and dormant accounts.

  2. 02

    Check admins

    List every admin role assignment, including custom roles, group-based assignments, and roles held by apps, and check each holder's factors and last sign-in.

  3. 03

    Check policies and tokens

    Compare authentication, global session, and password policies and network zones with last week, and list API tokens with the admin who created each one.

  4. 04

    Check the System Log

    Summarize sign-in failures, lockouts, ThreatInsight events, and admin actions since last week.

  5. 05

    Report

    Publish what changed and what needs action, with the fix for each item.

Agent template

# Okta Posture Report

## Measurable outcomes

Every week, the identity admin knows which admins lack a phishing-resistant factor, which API tokens run as super admin, and what changed in the policies. Track the users without a strong factor, the super admin count, the tokens created by super admins, and the open action items on every run.

## Procedure

Once a week, list the active users in the Okta organization with their enrolled authenticators and last sign-in. Count users with no enrolled authenticator beyond a password, and list them by group. Count users whose strongest factor is SMS, voice, or email, and list them by group. Flag active users with no sign-in in the last 90 days, unless I set another window. Flag users still in a provisioned or staged state for more than 30 days. List every admin role assignment. Include custom roles, roles granted through groups, and roles held by apps. Flag each admin without a phishing-resistant factor such as FIDO2 or Okta FastPass. Flag each admin with no sign-in in 30 days. Flag more super admins than the number I set. Compare the authentication policies and their rules, the global session policy, the password policies, and the network zones with last week's report. Name each change and who made it from the System Log. Flag any policy rule that allows password-only access. Flag any policy rule that exempts a network zone from MFA. List API tokens with the admin who created each one. A token carries that admin's current role, so flag every token created by a super admin. Flag every token held by a person instead of a service account. Summarize the sign-in failures, lockouts, ThreatInsight events, and admin actions since the last report. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine.

## Requirements

It needs an OAuth service app with only okta.*.read scopes, or an API token created by a Read-Only Administrator, and nothing more. It never changes users, factors, roles, policies, or tokens. Reports show counts, groups, and policy names. User names appear as stable pseudonyms.