Okta Professional Cert Study Flashcards
What are the 3 types of users in Okta?
Okta-Sourced (Mastered), Directory-Sourced (Mastered), App-Sourced
What is SAML?
Security Assertion Markup Language - standard protocol used to facilitate SSO. Can be used across multiple systems/domains by establishing a trusted relationship using digital certificates/signatures.
What is LDAP?
Lightweight Directory Access Protocol - Directory source for users.
What is AD?
Active Directory - MS Directory that is LDAP compliant can connect any app that uses LDAP.
What is DSSO?
Desktop Single Sign On - Okta solution to allow users to log into AD connected computer and extend SSO to Okta configured Apps, reduce logins to Company and Cloud based apps.
What is IWA?
Integrated Windows Authentication - AD version of DSSO, allows single login to company and some cloud apps
What is in Workforce Identity Cloud?
SSO, MFA, Universal Directory, LCM, API Access Management, Advanced Server Access, Access Gateway
What is in Customer Identity Cloud?
Auth0, Authenticating User management, MFA, LCM, B2B Int, Access Gateway
What are the methods of App integration?
SAML, SWA, OIDC and SCIM
What are the first two steps to create an app integration?
- Create Integration, 2. Add users or groups
What are the two sign-in flows for SAML?
- SP-Initiated flow - user attempts sign in, redirected to IdP, then prompt login to IdP or desktop SSO.
- IdP initiated flow - user logs into IdP, launches SP by clicking chicklet, if no SP account, SAML can JIT.
What needs to be provided to the SP to do SSO?
- IdP SSO URL
- IdP Issuer Entity ID
- The X.509 Cert
Describe the Okta Browser Plug-in.
Enables auto login to apps that would manually require credentials. SWA uses browser plug-in.
What is Universal Directory?
Manage Okta app and user profiles, 31 base attributes. Only you can modify or remove are First Name + Last Name. Default user name = email address
What is SCIM provisioning?
System for Cross-domain Identity Management, used to perform provisioning actions between Okta + Cloud-based or On-prem apps.
What are the advantages to using Okta for provisioning?
- Account management
- Importing users (AD, LDAP, or certain apps)
- Configuring rules + Workflows
- Reports
When do you use SAML for integration? and describe the authentication method.
When app supports SAML, like Salesforce, RingCentral, Box and ServiceNow. Between IdP and SP. SP is not authenticating, rather trusting the cert from the IdP. no user name or password exchanged, only encrypted token.
When do you use WS-FED for app integration?
When MS Mastered? - check this
When do you use OIDC for integration?
When you want to use social networking to authenticate or a third party app
When do you use SWA for integration?
Okta Secure Web Auth, when app doesn’t support proprietary federation or SAML. like Facebook, or Southwest Airlines. Requires Okta browser plug-in. Forms based integrations
What are the 4 major use cases for Workflows?
- Comprehensive provisioning for an app.
- Complex “joiner, mover, leaver” flows
- Resolve identity conflict and other data issues
- Logging and Alerting on key lifecycle events
What does a “Staged” user status mean?
The user account has been created, but the activation process has not been initiated. Account is in a dormant stage.
What does “Pending user action” user status mean?
The user account has been added and the activation has been initiated, but the user has not yet set a password.
What does “Active” user status mean?
The user account is active and the person can access all assigned applications.
What does “Deactivated” user status mean?
The user account is inactive and the admin can’t assign any applications to the user.
What does “Password Reset” user status mean?
The user is allowed to resolve forgotten password issue by resetting the password without relying on the service desk.