07 - Configure SSO & Provisioning Flashcards

1
Q

Demo 1: Okta Integration Network/Applications Demonstrate knowledge of the OIN and how to leverage Okta out-of-the-box app integrations

A

Applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Demo 1A: Okta Integration Network/Applications Demonstrate knowledge of the OIN and how to leverage Okta out-of-the-box app integrations

A

Okta Integration Network/Applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Demo 1B: Okta Essentials Module 5: Configure SSO and Provisioning Demonstrate knowledge of the OIN and how to leverage Okta out-of-the-box app integrations

A

Okta Essentials Module 5: Configure SSO and Provisioning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Demo 2: The Applications Page Demonstrate knowledge of how to search for pre-built integrations and identify the app capabilities

A

The Applications Page

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Demo 2A: Okta Essentials Module 5: Configure SSO and Provisioning Demonstrate knowledge of how to search for pre-built integrations and identify the app capabilities

A

Okta Essentials Module 5: Configure SSO and Provisioning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does configuring application in Okta enables you to do?

A

Configuring applications within Okta enables you to provide additional security layers on sensitive corporate data, while also providing insight to application and data usage by people at your company.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Okta supports integration with various SSO options. What does that include?

A

Delegated authentication Proprietary vendor specific protocols.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

SSO integration allows for:

A

Provide access to applications for all users Configure app access adhering to company policies. Create and maintain a single source of truth for your users, enabling new authN and provisioning scenarios.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the OIN stats:

A

6500 built-in and community generated apps 1300 enabled with SAML to provide secured enterprise-level SSO 150 are mobile ready to remote workforce. 230 are provisioning enabled so you can automate the process of account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is AIW?

A

In-product wizard called the Application Integration Wizard (AIW) that allow you to build your own SWA, SAML SSO, or SCIM provisioning integrations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is Okta in place?

A

Okta authenticates users and then SSO to all assigned applications with communications into Okta occurring over HTTPS. If a user opens an application without first authenticating to Okta, the application automatically redirects to Okta for authentication.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is AIW?

A

In-product wizard called the Application Integration Wizard (AIW) that allow you to build your own SWA, SAML SSO, or SCIM provisioning integrations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the problem with SAML and WS-Fed

A

The problem is they’re not very lightweight and not very easy to work with. They do not work with modern applications natively.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the advantage with OIDC?

A

One of the things you see is that OpenID connect is based on OAuth. So, we’re going to be able to achieve a single process for not only providing access to our apps, but we’re going to then also use the same request for secure access to our APIs. OpenID Connect has all these benefits.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is SWA

A

Secured Web Authentication. Okta’s pw manager feature.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How does SWA work?

A

What this does is when a user navigates to a site, we detect the URL and insert a username and password into that form.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is the drawback with SWA?

A

a. The drawback to SWA is that it requires a browser plug-in and so in a customer identity and access management situation, you wouldn’t be asking your customers to install a plug-in for secure access to your apps or sites. b. Also, it’s not Federated. So, even though it’s automated, you still have to think about password issues for those endpoints. The key benefit is that it doesn’t require any development. So, you just need that login form, but there’s a lot of drawbacks to working with SWA.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is the Signon Methods for SWA?

A

a. AuthN request b. Access request granted c. App access request through the Okta app d. UX: When users click an application icon, Okta securely posts their credentials to the application login page over SSL and the user is automatically authenticated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q
  1. Considerations of SWA
A

a. SWA was created for applications that do not support federated SSO b. For SWA applications, the Okta Browser Plugin is required. c. Okta stores the user credentials in an encrypted format using AES encryption combined with a customer-specific private key.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q
  1. SWA sign-in options.
A

a. User sets username and password b. Administrator sets username, user sets password c. Administrator sets username, password is the same as user’s Okta password d. Users share a single username and password set by administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q
  1. What is Authentication vs. Federation?
A

a. AuthN is the process of proving the identity of a person or system. b. Federation is the process by which an app or site requests proof of authN from a trusted source. c. Basically, it answers the question, “Who are you, and how do you prove it?” So, typically this requires a user entering their username and password and perhaps some sort of MFA. Secure authentication these days often involves multi-factor authentication. You’re starting to see it more with many sites adopting it, but other sites still use just a username and password. d. Now, when we talk about Federation, what we’re talking about is we have this app and we need to create a trust relationship between that app and Okta (IdP) essentially so that when a user goes to access that application, we are not going to require that they authenticate again. Instead, we’re going to request proof that they have already successfully authenticated and then provide, in an automated fashion, access. One of the key ways to think about the difference is that users are authenticated and apps are Federated.

22
Q

Signon Methods: SAML.

A

a. Standards-based i. Ensures interoperabilty across IdPs ii. Enterprises free to select a vendor b. For the most secure authentication, it’s recommended to use a standard-based protocol such as SAML. i. It eliminates the need for pw by using digital signature for authN. c. For Security: i. use SSO protocol. ii. It is used globally. iii. Based on digital signature for authN and integrity. d. IT friendly: i. Centralized authN, ii. Provides greater visibility, iii. Makes directory integration easier. e. Usability: i. One-click access from portals or intranet. ii. Deep linking, iii. password elimination, iv. automatic renewal of sessions.

23
Q

What are the 3 roles of SAML

A

a. IdP: the entity that actually authenticates the user; in this case, Okta. (assert) b. Service Provider (SP): the application or website the user is trying to access. (Provide) c.End User: the end-user trying to authenticate to the service. (authN)

24
Q

IdP initiated SAML

A

a. AuthN to Org b. Access request granted c. SAML response forwarded d. AuthN and SAML response creation

25
Q

SP initiated SAML:

A

a. Application opened b. SAML generation and redirection to Okta c. Follows redirect to Okta d. AuthN and SAMl response creation SAML verification and user authN

26
Q

Provisioning and de-provisioning are bi-directional?

A

True. Accounts can be created in an app and imported into Okta or added to Okta and then pushed to corresponding apps.

27
Q

What are the steps to provisioning a user?

A

a. Admin creates a new user in the “marketing group” (UI) b. Ad agent Sync grabs user info (Active Directory) c. Ad agent pushes user info (Okta Active Directory Agent) d. Okta creates new user in app (Okta > Salesforce, etc)

28
Q

All application support user provisioning.

A

False, Not all application support user provisioning.

29
Q

True/false. A provisioning API helps you manage the identity or user lifecycle, including onboarding through to departing the company by connecting your HR system or a directory such as Active Directory with your application.

A

a. True. With Okta and the account provisioning capabilities, these user identity changes can be leveraged to trigger appropriate actions in the integrated applications. b. By exposing the required account provisioning APIs, your application can rely on Okta to help manage and monitor users and access within your application.

30
Q

What are some of the provisioning features?

A

a. the provisioning of accounts for new users, b. deprovisioning accounts for deactivated users c. and synchronizing user attributes across multiple directories.

31
Q

What are some example of User Mastered

A

a. Okta-Mastered b. AD mastered, Active Directory mastered user, the user is created and maintained in Active Directory and Active Directory is doing the authentication. c. Application Mastered. This is also known as an application mastered user because it’s coming from Workday into Okta and again if I want to make a change to that user I would have to go to Workday to make that change.

32
Q

What is delegated authentication?

A

Delegated authentication and we’re delegating the authentication to AD

33
Q
  1. What are the steps to configure LCM (using SF)
A

a. Application > application
b. Provisioning Tab > “Enable API integration”
c. Enter user name and Password + Token
d. You can reset your token inside of Salesforce
e. Test API Credentials ( I’m just establishing that connection so Okta can call the Salesforce API’s).
f. Enable the right SF APIs that will “Create a user”, Update a User”, Deactivate a User”.
g. Default Mappings
h. Assign “Sales Staff” > Assignment tab > Assign Groups >
i. Assign Profiles > “Chatter Free” > Save
j. Check in SF to see if it provisioned “Sales Staff” > Salesforce > Manage Users > Users
k. Logout, then log back in as Ona admin. See SF in my list of apps and have SSO.

34
Q

What are the categories of OIN integration

A

Popular categories

35
Q

What are the categories of OIN integration

A

Human Resources

36
Q

What are the categories of OIN integration

A

Network Security

37
Q

What are the categories of OIN integration

A

Application Delivery Controllers

38
Q

What are the categories of OIN integration

A

Security Analytics

39
Q

What are the categories of OIN integration

A

Cloud Access Security Brokers

40
Q

What are the categories of OIN integration

A

API Gateway

41
Q

What are the categories of OIN integration

A

Infrastructure as a Service

42
Q

What are the categories of OIN integration

A

Identity Governance and Administration

43
Q

What are the categories of OIN integration

A

ID Proofing

44
Q

Privilege Access Management

A
45
Q

What are the categories of OIN integration

A

Endpoint Security and Management

46
Q

What are the categories of OIN integration

A

Healthcare Technologies

47
Q

What are the categories of OIN integration

A

Protocol-based Custom Integrations

48
Q

What are the categories of OIN integration

A

Bot Detection

49
Q

What are the categories of OIN integration

A

Customer Data Integrators

50
Q

What are the categories of OIN integration

A

Apps for Good

51
Q

What are the categories of OIN integration

A

EMAIL SECURITY

52
Q

What are the categories of OIN integration

A

SaaS Management Platform