We used the solution for domain control and password management. In my previous company, they had 40 different products. We used Okta for single sign-on management.
Okta Platform
Okta, IncExternal reviews
External reviews are not included in the AWS star rating for the product.
Improves security and productivity and enables integration with customers' domains quickly
What is our primary use case?
What is most valuable?
AuthO is a highly customizable access management tool for applications. When I want to integrate an application and enable SSO, it provides a single-click operation. It is very easy. Okta enables us to integrate with customers' domains quickly. It's one of the biggest advantages. The development team can easily pull out APIs and quickly code for identity management.
It also provides multifactor authentication features. The tool helps improve our security and productivity. We can easily pull up the APIs and integrate them quickly. We would have had to build our own solution if not for Okta. Okta has saved us tons of money by removing the pain of building a tool. It is easy to use.
What needs improvement?
We had some implementation issues.
For how long have I used the solution?
I have been using the solution for about three years.
What do I think about the scalability of the solution?
The tool is scalable.
How are customer service and support?
The support was very good.
How would you rate customer service and support?
Positive
How was the initial setup?
It is a SaaS product. It took us less than a month to implement the solution in our organization. However, it took a little longer for us to deploy the tool for our customers because we had to do it product by product. We deployed it for our customers in three to four months.
What's my experience with pricing, setup cost, and licensing?
We paid a license fee for our own use. For the customers’ use cases, we had an OEM model and paid a small percentage of the fee. We had a very nice Okta team. The overall cost was not bad.
What other advice do I have?
I am working with Keeper in my current organization. The business case is different. I'm not looking at integrating with customer's domains or products. I use Keeper primarily for personal use cases. Okta is a very good product. Overall, I rate the product an eight out of ten.
Very useful to have, not completely SSO
All software to be found in one platform
Fingerprint use is great
Offers universal directory that offers custom attribute capability and user permissions to read/write on their profiles or hide them
What is our primary use case?
Okta has recently built Okta Identity Engine (OIE). It has a lot more capabilities than the classic engines. The certificate-based system is one thing, and third-party tools like Intune and Jamf for iOS devices. There is a trust relationship between these device management tools, and that contributes to control over the end-user devices.
Scalacity was a company acquired by Okta, and its technology was integrated into Okta's Advanced Server Access (ASA) product.
What is most valuable?
Okta has introduced the Universal Directory. It has custom attribute capability and user permissions to read/write on their profiles or hide them. Profile sources and identity profile sourcing are two different components that I haven't seen in other products.
Okta can import many attributes into the Okta profile and send attributes from the engines. Multiple sources of truths and profile inheritance are done in granular ways. This plays a major role in ABACs going forward.
Okta's MFA features are good. Okta is looking forward with more on the push or less, relying on the Okta Verify factors. It also has extensive capabilities. It's adopting a layer-by-layer upgrade in developing the policies, like MFAs.
Okta has more when it comes to the policy level. It has distinctive features where you can do a mix and combination to have users access applications for various business cases. That's something unique and a selling feature.
What needs improvement?
Okta has a limitation with directory integrations. If you have multiple Active Directory integrations, the user distinguished name (DN) and the manager DN don't get imported properly into the Okta user profile. It has a property of Get AD user's property, but that has limitations when writing an expression language to import changes or updates to user DNs or manager DNs from AD, especially if you have AD master users.
Also, Okta doesn't have a partial push. It pushes down the full profile schema for lifecycle management or provisioning. Even if only one attribute gets updated, even though it is unmapped, it can override other values in the downstream application by nullifying the query. That's the biggest flaw in my experience.
The product releases a lot of brand-new features within the quarterly releases.
For how long have I used the solution?
It's definitely the leading Identity Access Management cloud platform. I have experience with Okta for almost six to eight years now.
I've been an Okta-certified consultant since last year. I got an opportunity to work on the workforce as well as the customer side.
I have experience with more than eight Okta tenants parallelly due to various business cases across my career. Ultimately, this product itself is a pioneer in Identity Access Management.
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
Scalability works very well. I've worked so far with Okta. It's like the heartbeat of that company. If Okta goes down, people are unable to authenticate anywhere. They can't get into applications. So there's a lot of dependency on Okta within the businesses and environments that I've seen so far. It's very critical.
How are customer service and support?
The customer service and support are awesome. They have a CSM assigned for each organization, and they are pretty much responsive to any events that occur. Or if there are any escalations or incidents that impact the business, they're pretty much around in a timely fashion to support the organization.
We have the flexibility with our CSMs to reach them in any manner, email or phone, and they're available most of the time.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We have long relationships with other vendors for things like Identity Governance and Privileged Access Management. But one thing I've noticed is that Okta has been expanding into wider ranges.
But, there are limits and restrictions to the existing features, which are not fully developed yet. Okta have added a lot of tech in the last couple of years.
What was our ROI?
I'm not a hundred percent sure about the return of interest because it is very much dependent on the size of the organization.
I came from smaller organizations working, like, midscale to, like, large scale. So overall, like, the security breach, like, there are, like, two to three security breaches that have happened, but nothing has been damaged so far for the organization.
So, investing more in Identity access management is a critical investment for any operation as applications are moving to like cloud and SaaS-based. So, there is a dire need to protect the digital identities of enterprise tech employees as well as their customers.
There are a lot of features you can automate. Okta Workflows is a key feature that has a separate pricing than adaptive MFA or SSO. It's a combination, but Okta has features and capabilities to reduce the IT burden. Within my experience, it's been helpful so far with a lot of overhead work that comes with onboarding and offboarding.
What's my experience with pricing, setup cost, and licensing?
The pricing itself is a bit more expensive than the other products in the market so far. Since I know the product is in full demand. But, again, the price texture, features, and everything suits well for small to medium.
But, for larger organizations, it's more expensive than the other platforms. But, usually, licensing is a bit expensive.
What other advice do I have?
I definitely recommend Okta. It has all the features you can utilize to protect any organization's digital entities. Considering a lot of other factors, like cost and the overall features the company wants to use. If you want to use Identity Governance, Identity Access Management, or Privileged Access Management, that's a different story. It's also a different story if you're using other products for different needs.
Overall, I would rate the solution an eight out of ten.
Provides an additional layer of protection and improves IT operations
What is our primary use case?
We use the solution for authentication purposes to access our applications.
How has it helped my organization?
The solution has improved our employee onboarding process. The tool has two layers. If something is compromised, there is another layer of protection for our enterprise application.
What is most valuable?
Single sign-on is a valuable feature. We can log in to Microsoft and Google applications. The additional layer of protection and the multi-factor authentication process helps secure our on-prem solutions. The layer before the production will be exposed to the internet. Our IT operations have improved a lot. The operation has become more automated and augmented. We face no challenges in integrating the product with our legacy systems.
What needs improvement?
The product is expensive compared to other tools.
For how long have I used the solution?
I have been using the solution for more than one year.
What do I think about the stability of the solution?
I rate the tool’s stability a nine out of ten. The stability is great. The tool is robust.
What do I think about the scalability of the solution?
The tool is highly scalable. I rate the scalability a ten out of ten. We have more than 500 users. The product is used every day.
How are customer service and support?
We have a team to raise tickets to the support team if we face any issues. The process is pretty straightforward.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is pretty straightforward. I rate the ease of setup eight to nine out of ten. The deployment took two to three weeks. One person is enough to operate and maintain the solution.
What's my experience with pricing, setup cost, and licensing?
Small and medium businesses cannot afford the tool. There are no additional costs associated with the tool. The vendor must reduce the price over time.
Which other solutions did I evaluate?
We used Microsoft Active Directory before. We evaluated Ping Identity, too.
What other advice do I have?
We do not use the tool for remote access management. I will recommend the product to others. Overall, I rate the solution a nine out of ten.
Which deployment model are you using for this solution?
Game Changer
Offers single sign-on for those who prefer Microsoft or a single sign-on solution
What is our primary use case?
Customers' workforce often operates within multiple scenarios and setups. For instance, some customers may use Microsoft Active Directory. For example, out of 5,000 employees, only 2,000 might be integrated into AD, while the rest could have access managed directly within specific applications by their respective owners. Users are burdened with managing multiple usernames and passwords, needing to input both separately whenever accessing an application. Moreover, there's a lack of visibility regarding which users possess privileged access, and whenever users change roles, it becomes challenging for customers to update access across various application layers due to the absence of centralised control. To address these issues, Okta Workforce Identity offers a solution. By consolidating identity and access management into a centralised repository, it streamlines access control, providing users with appropriate access levels based on their profiles. This centralised approach simplifies management for customers, enhancing security and efficiency.
How has it helped my organization?
Okta controls all the users. It has context-based access from the user and type of device. It identifies the risk and can do a step of authentication when that user is trying to access some sensitive application from an unknown device.
What is most valuable?
Okta offers single sign-on for those who prefer Microsoft or a single sign-on solution. They have integrated multiple applications with Azure. It still follows the old practice of creating usernames and passwords within the application for some legacy applications. We aim to address this issue by presenting an alternative. Instead of managing multiple username and password combinations. Azure can also integrate with IBM solutions. This creates a unified point of access once they adopt solutions like IBM's within their organisation.
What needs improvement?
If Okta Workforce Identity has a strong integration with other OEM solutions and can leverage intelligence from those OEMs to enable automatic restricted access for users, it would be highly appreciated. For instance, if it can integrate with DLP and EDR solutions, and if the DLP detects suspicious user activities, it should automatically restrict access to sensitive applications or prompt for multi factor authentication.
For how long have I used the solution?
I have been using Okta Workforce Identity as an integrator.
What do I think about the stability of the solution?
The product is stable.
What do I think about the scalability of the solution?
It is highly scalable. More than 2,000 users are using this solution. It is being used by some customers for their end customers, such as online e-commerce portals.
We work with all types of clients, but this particular solution is tailored for mid-scale enterprise customers. They should have at least 5,000 users and several hundred applications for this solution to be effective. The environment and the persona should be at a mature stage. In some organisations, there will be an IT manager, senior IT manager, and head of IT, who will be responsible for both infrastructure and security.
How are customer service and support?
Whenever we need information, we receive the required support from Okta. So, if I need clarification regarding integration, communication, or any related matters, I can get support from the local IT team.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup requires the expertise of the professional services team.
What's my experience with pricing, setup cost, and licensing?
Okta Workforce Identity is expensive due to currency differences, particularly between INR and USD.
I rate the product’s pricing a seven to eight out of ten, where one is cheap and ten is expensive.
What other advice do I have?
MFA must be implemented to access critical applications. Cost management is essential, as it's impractical to cover payments for all users across all applications. Therefore, a risk-based approach is necessary, where MFA is implemented selectively based on requirements from the same vendor or platform. This facilitates easier deployment, management, and provides a single dashboard view for identifying and managing risks effectively. It also enables the identification of the riskiest users within the organisation.
Overall, I rate the solution an eight out of ten.
Cant work without Okta!
As an organization In believe it helps a great deal with security and protection.
Reliable platform with simple setup process
What is our primary use case?
We use the product to manage access and identify several applications.
What is most valuable?
The product’s most valuable feature is multifactor authentication. It has an easier integration and configuration management process than Microsoft Entra ID. We can integrate it into different platforms.
What needs improvement?
An area for potential improvement in Okta lies in the absence of a dedicated feature for backing up the configuration of our tenants. It is challenging to obtain a comprehensive backup. We have to manually document all the configurations. They could provide a built-in tool for creating backups mitigating potential issues or crises.
For how long have I used the solution?
We have been using Okta Workforce Identity for five years.
How are customer service and support?
The technical support services are good. They respond to the queries immediately.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Compared with Okta Workforce Identity, Microsoft Entra ID is challenging to use in terms of integration and troubleshooting.
How was the initial setup?
The initial setup is simple. I rate the process an eight out of ten. It takes a few weeks to complete the integration for different projects. It is a reasonable time.
The deployment team includes administrators for the applications, as they are responsible for configuring integrations from their side. The administrator plays a crucial role in integrating the Active Directory. The project may require a collaborative effort of approximately three to five individuals. It requires two engineers for maintenance.
What other advice do I have?
The single sign-on (SSO) capability in Okta has significantly streamlined the user experience. It provides an ease of accessing applications. The subsequent access to other applications within the same browser is automatic, eliminating the need to initiate the multi-factor authentication (MFA) process repeatedly. We can define trusted sources and policies depending on the security requirements.
The centralized approach to managing everything from a central point has streamlined administrative tasks, eliminating the need to navigate through different systems for user and role management. It is one of the best solutions. We find a lot of information on their support website.
The overall reliability is commendable, as the platform strategically replicates its systems across various clouds, minimizing the likelihood of service disruptions. Over the past five years, we have not encountered any problems with the service.
I rate it a nine out of ten.
Valuing security
As its an extension, it's also very easy to click on it from any page and open up any pre-saved website you'd like
Has good provisioning and de-provisioning features
What is our primary use case?
We use Okta Workforce Identity for single sign-on (SSO).
What is most valuable?
One of the most beneficial features of the solution is the user provisioning and the de-provisioning feature. With the solution's universal directory, you can have all the user attribute information in one place. You can store it on Okta instead of in multiple places like your AD, applications, or different IdPs. You can get all the user attribute data onto your Okta, and then you can customize it. Okta allows you to modify the user attributes, which is also one of the useful features of Okta Workforce Identity.
Because it's a password-less authentication for personal sign-on, users don't need to use a password for it. That's how Okta comes into the picture, where it identifies the user based on the certificates for authentication. In that way, it also doesn't reveal the user identity to the applications if there is a man-in-the-middle (MITM) attack.
Okta Workforce Identity uses the System for Cross-domain Identity Management (SCIM) protocol for provisioning and de-provisioning. That is also one of the benefits of having your application's functionality on a platform like Okta Workforce Identity. It's easy from an admin point of view because when you de-provision a user on Okta, it will remove all the access from the respective applications without needing anything at the application level.
Because it's a cloud-based platform, installing the agents is the only integration you need to do in your current environment. You can have their agents installed on your Active Directory servers.
The integration is quite easy for other cloud applications. They have their own catalog of all the applications you can search and integrate. Applications like Microsoft Office 365 and Salesforce are already hosted on Okta. It's just a matter of configuring the applications with your company's metadata into your applications.
What needs improvement?
The solution's user interface needs to be improved and made easy. It has a lot of repetitive things. The solution should have a single pane of interface for admins.
For how long have I used the solution?
I have been using Okta Workforce Identity for six months.
What do I think about the stability of the solution?
I rate Okta Workforce Identity an eight out of ten for stability.
What do I think about the scalability of the solution?
Since it's a cloud-based platform, I haven't faced any scalability issues with Okta Workforce Identity. Our clients for Okta Workforce Identity are enterprise businesses.
I rate the solution an eight out of ten for scalability.
How are customer service and support?
The solution's technical support depends on the service level. Okta has certain packages, like gold or silver levels. If you have a silver-level agreement with Okta, you can get the right support at the right time.
How would you rate customer service and support?
Neutral
How was the initial setup?
On a scale from one to ten, where one is difficult and ten is easy, I rate the solution's initial setup an eight out of ten.
What other advice do I have?
Okta Workforce Identity is one of the market's leading and stable identity solutions.
Overall, I rate the solution an eight out of ten.