About the Okta Identity Integration
Okta Identity is Okta’s workforce identity and access management platform, providing single sign-on, multi-factor authentication, lifecycle management, and identity governance for enterprise organizations managing users and applications across cloud and on-premises environments. Part of Synqly’s Identity Unified API, the Okta Identity integration enables security teams to access normalized identity data—including users, groups, authentication events, and access logs—through a standardized connector. Integrate with Okta Identity to incorporate identity and access context into your SIEM, threat detection, and security operations workflows, enabling identity-aware security operations and zero trust enforcement.
Integration Use Cases
Disable User
Disables a user in the identity system based on user ID.
Enable User
Reenables a disabled user in the identity system based on user ID.
Expire All User Sessions
Logs a user out of all current sessions so they must log in again.
Force User Password Reset
Forces a user to reset their password before they can log in again.
Get Group
Returns a `Group` object wrapped in an OCSF Entity Management event of type Read from the token-linked identity provider. Depending on the providers offerings, this may include additional group information, such as the roles assigned.
Get Group Members
Returns list of `User` objects wrapped in an OCSF Entity Management event of type Read from the token-linked identity provider that are members in the group referenced by ID.
Get User
Returns a `User` object wrapped in an OCSF Entity Management event of type Read from the token-linked identity provider. Depending
on the providers offerings, this may include additional user information, such as the user\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\'s current groups and roles.
Query Audit Log
Returns a list of `Event` objects from the token-linked audit log.
Query Groups
Returns a list of `Group` objects wrapped in the OCSF Entity Management event of type Read from the token-linked identity provider.
Query Users
Returns a list of `User` objects wrapped in the OCSF Entity Management event of type Read from the token-linked identity provider.
About Okta
Okta is the global leader in identity security and workforce identity management, trusted by thousands of enterprises to verify and protect every user, device, and application in their environment. As the foundation of zero trust security architectures worldwide, Okta's identity-first approach ensures that organizations can grant the right access to the right people at the right time across cloud and on-premises environments. Teams looking to integrate with Okta or build an Okta integration can use Synqly to normalize and route Okta identity events, access logs, and authentication signals into SIEM and security operations platforms.

