
Learn to administer Okta with a focus on the Okta Identity Engine, covering fundamentals, single sign-on, MFA, user provisioning, REST APIs, and practical hands-on exercises.
Explore identity and access management (IAM) as a framework of policies, authentication, authorization, access control, and lifecycle management that secures resources, enables single sign-on, and maintains audit logs and compliance.
Explore how Okta centralizes identity management, enables single sign-on and adaptive authentication, and secures APIs to streamline access, lifecycle management, and compliance.
Compare the user interface changes from Okta Classic to Okta Identity Engine, focusing on authenticators, authentication policies, global session policy, device integrations, and the new profile enrollment feature.
The Getting Started lab is attached. Feel free to download it to follow along.
Create a free developer Okta Identity Engine tenant by signing up at developer.com/signup, activate the welcome email, and access the admin console to configure users, applications, and security policies.
Explore how Okta creates users through multiple methods, including manual admin console creation, csv import, ad/ldap integration, skim provisioning, api integration, self-registration, social providers, and just-in-time provisioning.
Create and activate three Okta source user accounts from the admin console by adding people with first name, last name, username, and primary email, then set passwords and verify activation.
Import users into Okta from a CSV file using the provided template with login, first name, last name, and email. Activate new users automatically and verify activation via emails.
Learn to create groups in Okta, such as support, sales, and managers, and assign users like James Snow and Jake to these groups via the directory groups interface.
Configure group membership automatically with group rules that match a user's title to assign them to the managers group; edit profiles, activate rules, and preview matches.
Add a swa application from the app catalog in the admin console. Name it and enable secure web authentication with username and password, then assign to a user.
Create and configure a swa application in the admin console, choose secure authentication, assign it to yourself, and experience auto login from the end user dashboard.
Learn how to configure a SAML-based Okta integration for Salesforce, adding Salesforce to Okta, enabling SAML 2.0, creating a custom Okta username format for provisioning, and reviewing SAML setup details.
Enable Saml single sign-on in Salesforce. Create a new sso setting named fundamentals for the Okta integration, then configure issuer, certificate, login url, and entity id, and assign a user.
Configure a Salesforce SP-initiated SAML flow with Okta by creating a custom Salesforce domain, provisioning and deploying it, updating login URLs and entity IDs, and testing the single sign-on setup.
Configure Okta lifecycle management to provision Salesforce users, enabling create, update, and activate, link pre-existing accounts via external IDs, and verify three users are provisioned.
Review system logs to troubleshoot provisioning events for Salesforce integration and fix a guest user role ID error. Confirm profile pushes and downstream provisioning succeed.
Install Saml tracer in Firefox or Chrome to troubleshoot Saml authentication issues and inspect requests and responses between your browser and an IDP or service provider.
Learn to capture IDP-initiated SAML flow with the SAML tracer in Okta, inspecting the SAML assertion, issuer, certificate, and response for the Salesforce app.
Learn how SP-initiated login differs from IDP-initiated login by using the SAML tracer to capture authentication requests and responses between the service provider Salesforce, Okta, and the identity provider.
The Active Directory integrations lab guide is attached. Feel free to download it to follow along.
Set up an Okta admin and a service account, install the Active Directory agent, and configure AD integration to sync selected users and organization units with Okta Identity Engine.
Explore how to import and provision users and groups from Active Directory into Okta, configure import schedules and assignments to downstream apps, and enable just-in-time provisioning for seamless access.
Learn to troubleshoot Okta and Active Directory integration by inspecting the add agent, logs, and request IDs, and configure verbose logging and AD agent settings for reliable user imports.
The inbound SAML lab guide is attached. Feel free to download it to follow along.
Create a custom SAML 2.0 app in Okta org one, assign a user, and set placeholders for the SSO URL and audience URI for org two.
Run lab three tests user access via inbound SAML in org two, signing into the Okta dashboard, selecting the inbound SAML app, and provisioning the user into Salesforce for access.
Troubleshoot inbound saml sso with the saml tracer and logs across two orgs, identifying a missing login attribute and misconfigured attribute mapping.
Configure the Okta Policy Framework Lab Guide is attached. Download it to follow along.
Configure password policy in Okta Identity Engine, differentiate from Okta classic, add Okta Verify with Fastpass and push notifications, and create a sales group policy with complexity and expiry rules.
The Okta Identity Engine Lab Guide is attached. Feel free to download it to follow along.
Configure security outcomes by understanding assurance levels, from level one with any one factor type, to level two with possession and knowledge, and level three with inherence, possession, or knowledge.
Configure app level authentication policies for low, medium, and high assurance in Okta Identity Engine, assign apps, and define catch all rules, factors, and two minutes re-authentication.
Demonstrates app level authentication policy across low, medium, and high assurance apps with email magic links, password prompts, and google authenticator enrollment for two-factor security.
Explore flexible account recovery with Okta Identity Engine, enabling self-service password management and account unlock via email, Google Authenticator, and Okta verify push, aligned with the sales group password policy.
The Okta REST API Lab guide is attached. Feel free to download it to follow along.
Create an API token as a super administrator in Okta's UI security API, name and copy the token, and note its 30-day expiry with renewal on activity and inherited permissions.
Set up postman for Okta API testing by creating a new workspace, importing a preconfigured environment, and configuring the URL, API key, and username and password for secure API calls.
Create and activate new users with password and recovery questions, then assign a read-only admin role via the API in the Okta fundamentals with Okta Identity Engine course.
Manage Okta groups via api using Postman, including creating groups and configuring their name and description. Add or remove members, verify group membership, and list all groups in your tenant.
Learn to manage apps via the Okta API by registering a custom app, assigning it to the everyone group, and testing lifecycle operations with Postman.
Extend user attributes via API by adding a custom profile attribute, such as Twitter username, to a user and verify changes with get and post calls in Postman.
Master group rules via API to auto-assign users to groups based on attributes like cost center, then activate and validate the rule in Okta Identity Engine.
The OAuth and OIDC lab guide is attached. Feel free to download it to follow along.
Log in to your Okta developer tenant, gather the authorization server details, audience, and issue URI for the implicit flow, and prepare the v1/authorize, v1/token endpoints plus a Udemy scope.
Learn how the authorization code flow securely exchanges an authorization code for an access token in confidential web apps, using client ID and secret with the authorization and token endpoints.
Implement the authorization code flow with OpenID Connect scope openid and email to retrieve the user's ID and email from the ID token via Okta's token endpoint.
Learn how to use Postman to perform the authorization code flow and exchange a code for an access token, including environment setup and key endpoints.
Thank you for taking the course. I've added some resource links for your reference.
Hi, I'm Bryan. Welcome to "Okta Fundamentals with Okta Identity Engine". I'm thrilled to be your instructor on this exciting journey into the world of Okta.
With close to two decades of experience in the IT industry and four Okta certifications (Okta Certified Professional, Okta Certified Administrator, Okta Certified Consultant and Okta Certified Developer) under my belt, I've had the privilege of working with Okta's cutting-edge identity and access management solutions from both technical and training perspectives. As a former Okta Support Engineer and technical trainer, I've helped solved many customer problems and have seen firsthand how Okta empowers organizations to enhance security, streamline user access, and enable seamless collaboration.
Who Is This Course For?
Are you a professional looking to become an Okta administrator? Perhaps you're someone eager to dive into the world of identity and access management, with a particular interest in the new Okta Identity Engine. No matter your background, if you have an interest in Okta and want to harness the full potential of the Okta Identity Engine, this course is designed with you in mind. Whether you're an IT pro seeking to expand your skill set or a newcomer to the field, you'll find valuable insights and hands-on expertise here.
What Will You Learn?
In this course, we'll cover everything you need to know to become a proficient Okta administrator, with a strong emphasis on leveraging the Okta Identity Engine. We'll cover advanced topics like single sign-on (SSO), multi-factor authentication (MFA), Life Cycle Management (LCM), Okta REST API, OAuth & OIDC and the Okta Identity Engine's capabilities such as Global and Application level policies, Email Magic link, Profile enrollment and much more. I'll walk you through step-step lab exercises that you can follow along with lab guides for each section. This is meant for you to gain practical experience through the hands-on exercises.
Expected Learning Outcomes:
Upon completing this course, System Administrators and those responsible for configuring, integrating, and managing Okta are expected to:
Gain an understanding of identity and access management (IAM) concepts and Okta's role in IAM
Learn how to create users, groups, group rules, assigning users to groups and much more
Create different SWA applications
Configure salesforce application with SAML
Troubleshoot SAML configuration issues with Salesforce and SAML tracer
Understand Single Sign-On with Inbound SAML
Set up LifeCycle Management (LCM) through Salesforce provisioning and deprovisioning features
Understand the basics of Okta REST API
Understand OAuth & OIDC concepts and apply them in the different OAuth flows using Okta OIDC app
Sign up today, and look forward to:
Hands-on lab exercises
Video Lectures
Knowledge Check (Quizzes)
I would love to solve problems, specifically related to our course. I'll be more than happy to help assist with any issues you may run into as you go along with the exercises.
So what are you waiting for? Click Enroll Now button and join me in this learning journey. Can't wait to see you in the course.