Sign in Agent Mode
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Okta Identity Platform [Private Offer Only]

Carahsoft Technology Corp.

Reviews from AWS customer

8 AWS reviews

External reviews

37 reviews
from

External reviews are not included in the AWS star rating for the product.


4-star reviews ( Show all reviews )

    reviewer2382102

Good for workforce productivity and customer security and offers MFA features

  • May 02, 2024
  • Review provided by PeerSpot

What is our primary use case?

It's mostly used for customer-facing applications (Customer Identity Management). API management and self-service flows are the most utilized capabilities. It offers a lot of customization in terms of branding, email notifications, and creating a good end-user experience.

For remote access, we have solutions proposed, like Okta Identity Engine (OIE). It has more capabilities than the classic engines. The certificate-based system is one thing, and third-party tools like Intune and Jamf for iOS devices. There is a trust relationship between these device management tools, and that contributes to control over the end-user devices.

How has it helped my organization?


What is most valuable?

Okta has introduced the Universal Directory. It has custom attribute capability and user permissions to read/write on their profiles or hide them. Profile sources and identity profile sourcing are two different components that I haven't seen in other products.

Okta can import many attributes into the Okta profile and send attributes from the engines. Multiple sources of truths and profile inheritance are done in granular ways. This plays a major role in ABACs going forward.

Okta's MFA features are good. Okta is looking forward with more on the push or less, relying on the Okta Verify factors. But it also has extensive capabilities for Ubiquiti. It's adopting a layer-by-layer upgrade in developing the policies, like MFAs.

Okta has more when it comes to the policy level. It has distinctive features where you can do a mix and combination to have users access applications for various business cases. That's something unique and a selling feature.

For security protocols we use most security protocols, such as OIDC and SAML.

What needs improvement?

Okta has a limitation with directory integrations. If you have multiple Active Directory integrations, the user distinguished name (DN) and the manager DN don't get imported properly into the Okta user profile. It has a property of Get AD user's property, but that has limitations when writing an expression language to import changes or updates to user DNs or manager DNs from AD, especially if you have AD master users.

Also, Okta doesn't have a partial push. It pushes down the full profile schema for lifecycle management or provisioning. Even if only one attribute gets updated, even though it is unmapped, it can override other values in the downstream application by nullifying the query. That's the biggest flaw in my experience.

The product releases a lot of brand-new features within the quarterly releases. There's a feature roadmap for Okta CIM, and most of it is coming in with a lot of users or the customer side.

For how long have I used the solution?

It's definitely the leading Identity Access Management cloud platform. I have experience with Okta for almost six to eight years now.

I've been an Okta-certified consultant since last year. I got an opportunity to work on the workforce as well as the customer side.

I have experience with more than eight Okta tenants parallelly due to various business cases across my career. Ultimately, this product itself is a pioneer in Identity Access Management.

What do I think about the stability of the solution?

It's pretty much stable most of the time, but I have come across a lot more outages recently within Okta.

But, Okta is definitely a very good product.

What do I think about the scalability of the solution?

Scalability works very well. I've worked so far with Okta. It's like the heartbeat of that company. If Okta goes down, people are unable to authenticate anywhere. They can't get into applications. So there's a lot of dependency on Okta within the businesses and environments that I've seen so far. It's very critical.

How are customer service and support?

The customer service and support are awesome. They have a CSM assigned for each organization, and they are pretty much responsive to any events that occur. Or if there are any escalations or incidents that impact the business, they're pretty much around in a timely fashion to support the organization.

We have the flexibility with our CSMs to reach them in any manner, email or phone, and they're available most of the time. Very good.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We have long relationships with other vendors for things like Identity Governance and Privileged Access Management. But one thing I've noticed is that Okta has been expanding into wider ranges. However, there are limits and restrictions to the existing features, which are not fully developed yet. I think they've added a lot of tech in the last couple of years.

How was the initial setup?

It's always smooth and straightforward to set up, but we can definitely have a bit of complex solutions.

What was our ROI?

I'm not a hundred percent sure about the return of interest because it is very much dependent on the size of the organization.

I came from smaller organizations working, like, midscale to, like, large scale. So overall, like, the security breach, like, there are, like, two to three security reasons that have happened, but nothing has been, like, damage so far for the organization.

So, investing more in Identity access management is a critical investment for any operation as applications are moving to like cloud and SaaS-based. So there is, like, a dire need to protect the digital identities of enterprise tech employees as well as their customers.

There are a lot of features you can automate. Okta Workflows is a key feature that has a separate pricing than adaptive MFA or SSO. It's a combination, but Okta has features and capabilities to reduce the IT burden. Within my experience, it's been helpful so far with a lot of overhead work that comes with onboarding, offboarding.

What's my experience with pricing, setup cost, and licensing?

The pricing model for the Customer Identity product is based on Monthly Unique Users (MUI).

The pricing itself is a bit more expensive than the other products in the market so far. Since I know the product is in full demand. But, again, the price texture, features, and everything suits well for small to medium, for sure.

But, for larger organizations, it's more expensive than the other platforms. But, usually, licensing is a bit expensive.

What other advice do I have?

I definitely recommend Okta.

Every organization needs workforce productivity as well as customer security. The need is definitely there for any enterprise or organization to protect their identity. Customer security also plays the utmost role in protecting customer data.

Overall, I would rate the solution an eight out of ten.


    Jamil Rashdi

Provides an additional layer of protection and improves IT operations

  • April 09, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use the solution for authentication purposes to access our applications.

How has it helped my organization?

The solution has improved our employee onboarding process. The tool has two layers. If something is compromised, there is another layer of protection for our enterprise application.

What is most valuable?

Single sign-on is a valuable feature. We can log in to Microsoft and Google applications. The additional layer of protection and the multi-factor authentication process helps secure our on-prem solutions. The layer before the production will be exposed to the internet. Our IT operations have improved a lot. The operation has become more automated and augmented. We face no challenges in integrating the product with our legacy systems.

What needs improvement?

The product is expensive compared to other tools.

For how long have I used the solution?

I have been using the solution for more than one year.

What do I think about the stability of the solution?

I rate the tool’s stability a nine out of ten. The stability is great. The tool is robust.

What do I think about the scalability of the solution?

The tool is highly scalable. I rate the scalability a ten out of ten. We have more than 500 users. The product is used every day.

How are customer service and support?

We have a team to raise tickets to the support team if we face any issues. The process is pretty straightforward.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is pretty straightforward. I rate the ease of setup eight to nine out of ten. The deployment took two to three weeks. One person is enough to operate and maintain the solution.

What's my experience with pricing, setup cost, and licensing?

Small and medium businesses cannot afford the tool. There are no additional costs associated with the tool. The vendor must reduce the price over time.

Which other solutions did I evaluate?

We used Microsoft Active Directory before. We evaluated Ping Identity, too.

What other advice do I have?

We do not use the tool for remote access management. I will recommend the product to others. Overall, I rate the solution a nine out of ten.


    GOMS A R

Offers single sign-on for those who prefer Microsoft or a single sign-on solution

  • April 04, 2024
  • Review provided by PeerSpot

What is our primary use case?

Customers' workforce often operates within multiple scenarios and setups. For instance, some customers may use Microsoft Active Directory. For example, out of 5,000 employees, only 2,000 might be integrated into AD, while the rest could have access managed directly within specific applications by their respective owners. Users are burdened with managing multiple usernames and passwords, needing to input both separately whenever accessing an application. Moreover, there's a lack of visibility regarding which users possess privileged access, and whenever users change roles, it becomes challenging for customers to update access across various application layers due to the absence of centralised control. To address these issues, Okta Workforce Identity offers a solution. By consolidating identity and access management into a centralised repository, it streamlines access control, providing users with appropriate access levels based on their profiles. This centralised approach simplifies management for customers, enhancing security and efficiency.

How has it helped my organization?

Okta controls all the users. It has context-based access from the user and type of device. It identifies the risk and can do a step of authentication when that user is trying to access some sensitive application from an unknown device.

What is most valuable?

Okta offers single sign-on for those who prefer Microsoft or a single sign-on solution. They have integrated multiple applications with Azure. It still follows the old practice of creating usernames and passwords within the application for some legacy applications. We aim to address this issue by presenting an alternative. Instead of managing multiple username and password combinations. Azure can also integrate with IBM solutions. This creates a unified point of access once they adopt solutions like IBM's within their organisation.

What needs improvement?

If Okta Workforce Identity has a strong integration with other OEM solutions and can leverage intelligence from those OEMs to enable automatic restricted access for users, it would be highly appreciated. For instance, if it can integrate with DLP and EDR solutions, and if the DLP detects suspicious user activities, it should automatically restrict access to sensitive applications or prompt for multi factor authentication.

For how long have I used the solution?

I have been using Okta Workforce Identity as an integrator.

What do I think about the stability of the solution?

The product is stable.

What do I think about the scalability of the solution?

It is highly scalable. More than 2,000 users are using this solution. It is being used by some customers for their end customers, such as online e-commerce portals.

We work with all types of clients, but this particular solution is tailored for mid-scale enterprise customers. They should have at least 5,000 users and several hundred applications for this solution to be effective. The environment and the persona should be at a mature stage. In some organisations, there will be an IT manager, senior IT manager, and head of IT, who will be responsible for both infrastructure and security.

How are customer service and support?

Whenever we need information, we receive the required support from Okta. So, if I need clarification regarding integration, communication, or any related matters, I can get support from the local IT team.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup requires the expertise of the professional services team.

What's my experience with pricing, setup cost, and licensing?

Okta Workforce Identity is expensive due to currency differences, particularly between INR and USD.

I rate the product’s pricing a seven to eight out of ten, where one is cheap and ten is expensive.

What other advice do I have?

MFA must be implemented to access critical applications. Cost management is essential, as it's impractical to cover payments for all users across all applications. Therefore, a risk-based approach is necessary, where MFA is implemented selectively based on requirements from the same vendor or platform. This facilitates easier deployment, management, and provides a single dashboard view for identifying and managing risks effectively. It also enables the identification of the riskiest users within the organisation.

Overall, I rate the solution an eight out of ten.


    SaravanaKumar8

Useful for authorization and other zero-trust authentication

  • April 03, 2024
  • Review provided by PeerSpot

What is our primary use case?

I use the solution mostly to integrate into Active Directory to get MFA and other IAM features. In Okta, we can get features similar to those in Active Directory. We also use the tool for authorization and other zero-trust authentication.

What is most valuable?

We can integrate two-factor authentication with the applications. Two-factor authentication is used for mobile applications like OneDrive.

What needs improvement?

The product must be provided for free. We cannot substantiate the cost with the features provided by the tool. Microsoft provides similar features for free. I don’t see any extra features in Okta.

For how long have I used the solution?

I have been using the solution for more than five to ten years.

What's my experience with pricing, setup cost, and licensing?

The tool is not free. However, Microsoft is free. So, people prefer Microsoft.

What other advice do I have?

If we wanted to access the Azure portal or any other portal, we used to scan with Authenticator. Once it was approved, we accessed the portals. The product is equivalent to Microsoft’s solution. I used Duo instead of Authenticator to authorize applications. People use Conditional Access Policy. People generally prefer Microsoft because it is free. I will recommend the tool to others. Our recommendations are based on the customer’s requirements, bandwidth, and budget. Overall, I rate the tool an eight out of ten.


    MiguelPurizaca

Reliable platform with simple setup process

  • March 01, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use the product to manage access and identify several applications.

What is most valuable?

The product’s most valuable feature is multifactor authentication. It has an easier integration and configuration management process than Microsoft Entra ID. We can integrate it into different platforms.

What needs improvement?

An area for potential improvement in Okta lies in the absence of a dedicated feature for backing up the configuration of our tenants. It is challenging to obtain a comprehensive backup. We have to manually document all the configurations. They could provide a built-in tool for creating backups mitigating potential issues or crises.

For how long have I used the solution?

We have been using Okta Workforce Identity for five years.

How are customer service and support?

The technical support services are good. They respond to the queries immediately.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Compared with Okta Workforce Identity, Microsoft Entra ID is challenging to use in terms of integration and troubleshooting.

How was the initial setup?

The initial setup is simple. I rate the process an eight out of ten. It takes a few weeks to complete the integration for different projects. It is a reasonable time.

The deployment team includes administrators for the applications, as they are responsible for configuring integrations from their side. The administrator plays a crucial role in integrating the Active Directory. The project may require a collaborative effort of approximately three to five individuals. It requires two engineers for maintenance.

What other advice do I have?

The single sign-on (SSO) capability in Okta has significantly streamlined the user experience. It provides an ease of accessing applications. The subsequent access to other applications within the same browser is automatic, eliminating the need to initiate the multi-factor authentication (MFA) process repeatedly. We can define trusted sources and policies depending on the security requirements.

The centralized approach to managing everything from a central point has streamlined administrative tasks, eliminating the need to navigate through different systems for user and role management. It is one of the best solutions. We find a lot of information on their support website.

The overall reliability is commendable, as the platform strategically replicates its systems across various clouds, minimizing the likelihood of service disruptions. Over the past five years, we have not encountered any problems with the service.

I rate it a nine out of ten.


    Mihir Parekh

Has good provisioning and de-provisioning features

  • February 05, 2024
  • Review provided by PeerSpot

What is our primary use case?

We use Okta Workforce Identity for single sign-on (SSO).

What is most valuable?

One of the most beneficial features of the solution is the user provisioning and the de-provisioning feature. With the solution's universal directory, you can have all the user attribute information in one place. You can store it on Okta instead of in multiple places like your AD, applications, or different IdPs. You can get all the user attribute data onto your Okta, and then you can customize it. Okta allows you to modify the user attributes, which is also one of the useful features of Okta Workforce Identity.

Because it's a password-less authentication for personal sign-on, users don't need to use a password for it. That's how Okta comes into the picture, where it identifies the user based on the certificates for authentication. In that way, it also doesn't reveal the user identity to the applications if there is a man-in-the-middle (MITM) attack.

Okta Workforce Identity uses the System for Cross-domain Identity Management (SCIM) protocol for provisioning and de-provisioning. That is also one of the benefits of having your application's functionality on a platform like Okta Workforce Identity. It's easy from an admin point of view because when you de-provision a user on Okta, it will remove all the access from the respective applications without needing anything at the application level.

Because it's a cloud-based platform, installing the agents is the only integration you need to do in your current environment. You can have their agents installed on your Active Directory servers.

The integration is quite easy for other cloud applications. They have their own catalog of all the applications you can search and integrate. Applications like Microsoft Office 365 and Salesforce are already hosted on Okta. It's just a matter of configuring the applications with your company's metadata into your applications.

What needs improvement?

The solution's user interface needs to be improved and made easy. It has a lot of repetitive things. The solution should have a single pane of interface for admins.

For how long have I used the solution?

I have been using Okta Workforce Identity for six months.

What do I think about the stability of the solution?

I rate Okta Workforce Identity an eight out of ten for stability.

What do I think about the scalability of the solution?

Since it's a cloud-based platform, I haven't faced any scalability issues with Okta Workforce Identity. Our clients for Okta Workforce Identity are enterprise businesses.

I rate the solution an eight out of ten for scalability.

How are customer service and support?

The solution's technical support depends on the service level. Okta has certain packages, like gold or silver levels. If you have a silver-level agreement with Okta, you can get the right support at the right time.

How would you rate customer service and support?

Neutral

How was the initial setup?

On a scale from one to ten, where one is difficult and ten is easy, I rate the solution's initial setup an eight out of ten.

What other advice do I have?

Okta Workforce Identity is one of the market's leading and stable identity solutions.

Overall, I rate the solution an eight out of ten.


    Peter Barnett

An user-friendly solution that helps to store passwords in one place

  • January 15, 2024
  • Review provided by PeerSpot

What is our primary use case?

Okta Workforce Identity stores all your applications in a portal. It saves passwords, eliminating the need to remember them. In addition, we use 1Password as a backup in case someone forgets their password.

How has it helped my organization?

In my organization, people thank me for integrating the product. Integrating applications with the solution makes it simple to access various applications. You can easily navigate through a list of 50 applications, click the one you need, and log in.

What is most valuable?

I like the tool's workflows, which is user-friendly. It can integrate with different applications. I particularly like that users are delighted to access their applications without the hassle of entering their username and password each time. It truly enhances user-friendliness.

What needs improvement?

I would appreciate it if Okta Workforce Identity becomes more user-friendly. Its API technology is complicated. Certain applications may pose challenges in terms of integration, especially when they require IDP technologies that aren't easily codable. While I can't provide specific examples, some applications may not integrate with Okta Workforce Identity.

For how long have I used the solution?

I have been working with the product for eight years.

What do I think about the stability of the solution?

The product works at times, and sometimes it doesn't. You will have to change the conditions when it doesn't work.

What do I think about the scalability of the solution?

Okta Workforce Identity is scalable. My company has 650 users for it.

How are customer service and support?

The tool's tech support is hard to get a hold of. Also, you would speak to a robot who knows a lot of information, doesn't listen to your questions, and misguides you.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have worked with Microsoft Azure, Slack, Teams, and Adobe Creative Suite. Microsoft Azure and Okta Workforce Identity allow applications to be implemented similarly. The process involves having an extension for the application, often a download file. However, it's important to note that while this implementation works on PCs, it might work on Macs.

How was the initial setup?

The tool's deployment is straightforward. You begin implementing applications once you've established your IDP. Deployment doesn't need a team of people. It can be done with the help of one person. Setting it up and integrating applications typically takes about a week, with additional time required for a more extensive list of applications, ranging from 50-100.

The product is not difficult to maintain once you have integrated it.

What other advice do I have?

I would rate the product an eight out of ten. My advice would be to exercise caution when implementing applications. Incorrect configurations may lead to issues, such as not having the correct username and password saved when clicking on the title. Additionally, when working with workflows, paying attention to the order of conditions is crucial. The tool is user-friendly, and you can have your applications in one place. This makes it less confusing for the users.


    Heiko Humpert

An easy-to-use solution that can be used to verify and provide access to users

  • September 15, 2023
  • Review provided by PeerSpot

What is our primary use case?

We use the solution to give access to the server. It verifies and allows users to access the server.

What is most valuable?

The product is easy to use. I just have to click on the Okta app on my mobile. The verification takes two seconds. We need to verify once we start the software because we use single sign-on.

What needs improvement?

The stability could be better.

For how long have I used the solution?

I have been using the solution since April. I am using the latest version of the solution.

What do I think about the stability of the solution?

I rate the tool’s stability an eight or a nine out of ten.

What do I think about the scalability of the solution?

Around 2000 to 3000 people use the product in our organization.

What about the implementation team?

The deployment was done in-house.

What other advice do I have?

I would recommend the product to others. It is a good solution. Overall, I rate the tool an eight out of ten.


    Fabio Camargo

A highly scalable and stable solution that is easy to use and provides a single sign-on feature

  • September 06, 2023
  • Review provided by PeerSpot

What is our primary use case?

We use the product for a variety of applications to establish the basic functionality of single sign-on for the company. We are looking for more use cases for our users. We are a marketing company. We have a high turnover rate. The processes are key to us. We are exploring how we can take advantage of Okta to help us streamline processes.

How has it helped my organization?

We used to have around 12 systems that had unique logins. There were too many central repositories. Now, we can log in using a single presenter.

What is most valuable?

The end user's ease of use is the most valuable feature.

What needs improvement?

We faced a bit of an issue integrating the product with some applications. The integration process takes a bit longer than we would want it to.

For how long have I used the solution?

I have been using the solution for around three years.

What do I think about the stability of the solution?

I rate the tool’s stability a nine out of ten.

What do I think about the scalability of the solution?

I rate the tool’s scalability a ten out of ten.

How was the initial setup?

The initial setup was complex. It was not Okta’s issue. We are a holding company with over 30 Active Directory. There were complexities on our side. The product is deployed on the cloud.

What was our ROI?

It’s a long-term game. We don't expect to see a return on investment very soon.

What's my experience with pricing, setup cost, and licensing?

The solution is really expensive. We are struggling a bit.

What other advice do I have?

People considering the product must not only think about whether the tool will solve their immediate problem. They must think of all the things they want in the future before deploying the tool. Overall, I rate the product a nine out of ten.


    Gabe Sterritt

Ability to work with a wide range of applications and security mechanisms

  • June 08, 2023
  • Review provided by PeerSpot

What is our primary use case?

I have implemented a number of applications as far as accessing them through their IDPs. And they're an identity provider; they also provide some alternative active directory slash l dash services. And I have purchased those for getting user data onto other systems.

It's very straightforward. The automation that they have and the way that they let you assign applications to groups or to users and do things dynamically, it is very straightforward other than just that there's a lot of nuance because of the breadth of applications out there that they can work with. It's more a matter of knowing how to work with the security mechanisms in place, such as SAML or OAuth, these may require specific expertise.

What is most valuable?

As far as our security team is concerned, the ease of implementing multifactor authentication is definitely the biggest value for our organization. Additionally, the single sign-on services provided by Okta allow users to log in to their Okta account and access a variety of other applications. That's why we implemented Connect to leverage this feature more efficiently across MacOS.

What needs improvement?

There are areas for improvement. One thing that seems odd to me is the lack of a built-in way to export all user data. They have a solution available on GitHub that they basically endorse, and it's developed internally, but for some reason, it's not integrated into their product. So, that's a peculiar aspect.

Instead, the support says they don't offer it but provide an alternative solution that we have to manage separately. So, it's a situation where they don't want to include it in their product, but they offer assistance outside of it? It's unclear what kind of support you would need for it. It just works.

Another area of improvement is scalability.

For how long have I used the solution?

I have been working with Okta for two and a half years.

What do I think about the stability of the solution?

Okta is pretty stable. Occasionally, we encounter notifications indicating some issues, but that has happened only once or twice in the two years I've been using it.

There have been situations where our own users were temporarily affected by disruptions in the cloud, but those incidents lasted only for a couple of hours. Taking into account a 99.9% uptime SOA.

What do I think about the scalability of the solution?

I would rate its scalability seven out of ten. There are definitely challenges we encounter, not related to the number of users but rather in terms of implementing various applications. Each application we work with can be completely different, resulting in highly variable implementation processes.

It ultimately depends on the specific use cases you have and the tools you utilize. It's important to find the best solution tailored to your needs.

We have around 500 users utilizing Okta Customer Identity.

How was the initial setup?

The initial setup is fairly easy. I would estimate it to be at least an eight in terms of ease of setup.

The actual setup and configuration can be done in half a day or less. However, the main challenge lies in communicating with users and getting them to adopt and use it, rather than the technical setup itself.

It's more about informing everyone about the new requirement, that instead of logging in to each application separately, they can now log in to the Identity Provider (IDP) and utilize its Single Sign-On (SSO) capabilities to simplify the login process for all applications.

What's my experience with pricing, setup cost, and licensing?

Okta's pricing is right where it needs to be and right in the middle of the market. You can pay them extra for services for assistance in implementing certain applications. You can hire one of their engineers to work with you and ensure successful implementation.

And that's something worth considering because they have expertise in their product and can get the job done more efficiently. It's worth paying for their services to ensure the solution is implemented successfully rather than struggling internally and failing to get it done.

What other advice do I have?

Overall, I would rate Okta a nine out of ten because there is always room for improvement. However, it is best in class as far as doing the things it does. And it's something that I've implemented with multiple businesses.

And it's really well-regarded. Yes. There are alternatives out there. Like, they all do somewhat different in each thing, whereas Okta seems to really be trying to cover all the bases as far as providing solutions that integrate with people's OSBAP, people's active directory, companies that wanna get serverless, touching on, the zero test network security that they're really kind of playing in the center of that zone.