okta:modules

Okta's modules, in plain English.

Okta sells its platform as suites and à la carte add-ons — and the packaging changes often enough that even IT teams lose track of what they own. Here's what each module actually does, when you need it, and where we come in.

module-group:agentic-identity

AI agent identity

The newest — and fastest-moving — part of the catalogue. AI agents are now the fastest-growing identity type in the enterprise, and mostly the least governed. Okta's answer is to treat every agent as a first-class identity: owned, scoped, auditable, and revocable.

okta-for-ai-agents

Okta for AI Agents

Discovers known and shadow AI agents across your environment, registers them in Universal Directory with a named human owner, and replaces long-lived API keys with short-lived, scoped credentials. Includes a universal-logout "kill switch" to instantly revoke a misbehaving agent. Generally available since April 2026.

how we help

Agent discovery and inventory (you have more shadow agents than you think), delegation scope design, ownership and lifecycle policies, and governance workflows so every agent action traces back to an accountable human.

cross-app-access

Cross App Access (XAA)

An open protocol extending OAuth for agent-to-app and app-to-app connections. Replaces ad-hoc integrations and endless user consent prompts with centralised, policy-driven access decisions made by your identity provider — including what agents can reach via MCP servers and APIs.

how we help

Connection policy design for agent-to-resource access — which agents may reach which APIs, under whose delegation, with what scopes — and staged enablement as your app vendors adopt the protocol.

auth0-for-ai-agents

Auth0 for AI Agents

For teams building their own agents: embedded authentication, secure token vaulting, asynchronous human-in-the-loop approvals, and fine-grained authorisation — so an agent acting inside your product is as governed as a user signing into it.

how we help

Identity architecture for agent builds — delegation chains, token lifetime strategy, and approval flows — designed before the agent ships, not retrofitted after the incident.

non-human-identity

Non-human identity governance

Agents are the sharp end of a broader problem: service accounts, API tokens, and machine credentials now outnumber your people many times over. The same discover–own–scope–revoke discipline applies to all of them.

how we help

NHI audits across your tenant — dormant service accounts, over-scoped tokens, credentials with no owner — with remediation automated through Workflows where it makes sense.

module-group:core-access

Core access

The foundation layer — who your users are and how they sign in. Almost every Okta tenant starts here.

sso

Single Sign-On

One set of credentials for every application — cloud, on-prem, and custom. Users get one dashboard; you get one place to control and log access across 8,000+ pre-built integrations.

how we help

App integrations done right the first time — SAML/OIDC configuration, sign-on policies, and a rollout sequence that doesn't break anyone's Monday.

adaptive-mfa

Adaptive MFA

Multi-factor authentication that responds to risk — device posture, location, network — rather than challenging everyone equally. Fewer prompts for low-risk sign-ins, harder walls where it matters.

how we help

Policy design that balances security with friction: who gets challenged, when, with which factors — informed by your actual sign-on data, not guesswork.

universal-directory

Universal Directory

A single, flexible user store that consolidates identities from Active Directory, LDAP, HR systems, and CSVs — with custom attributes and profile mappings feeding every downstream app.

how we help

Attribute architecture and profile mastering — deciding which system owns which attribute, so your directory is a source of truth, not a source of arguments.

access-gateway

Access Gateway

Extends Okta SSO and MFA to legacy on-premises applications that don't speak modern protocols — no code changes to the apps themselves.

how we help

Assessment of which legacy apps are worth fronting with the gateway versus migrating or retiring — then the deployment itself.

passwordless:fastpass

Passwordless & FastPass deployment

Okta FastPass, Device Assurance, and FIDO2 passkeys replace passwords with phishing-resistant, device-bound sign-in. Users stop typing credentials; attackers stop having credentials to steal. This is also the authentication strength the Essential Eight demands at Maturity Level 2 and above.

01 pilotEnrol a pilot group, verify device posture signals, tune fallback behaviour.
02 expandRoll out by cohort with self-service enrolment and clear comms — adoption, not mandates.
03 enforceRequire phishing-resistant factors for sensitive apps and admins, then everywhere.
how we help

End-to-end passwordless programmes: factor strategy, Device Assurance policy design, staged enrolment, and the edge cases that stall rollouts — shared workstations, BYOD, frontline workers, and the day someone loses their phone.

module-group:automation

Lifecycle & automation

Where Okta stops being a login box and starts removing work. Joiners, movers, and leavers — handled without tickets.

lifecycle-management

Lifecycle Management

Automated provisioning and deprovisioning driven by your HR system or directory. New starters get their apps on day one; leavers lose access the moment they should — not weeks later.

how we help

HR-as-a-source integrations, group rule design (including the Okta Expression Language edge cases that trip people up), and deprovisioning that actually deprovisions.

workflows

Okta Workflows

No-code automation for the identity logic that doesn't fit standard lifecycle policies — inactivity handling, staged offboarding, custom notifications, cross-system API calls. Suites include a workflow allowance; heavy use is licensed beyond it.

how we help

We design and build production-grade flows — like automated handling of dormant privileged accounts — and document them so they're maintainable, not magic.

module-group:governance

Governance & privileged access

The modules auditors ask about. Proving that the right people have the right access — and only that.

identity-governance

Okta Identity Governance (OIG)

Access certifications, access requests with approval flows, and separation-of-duties controls. This is how you stop privilege creep and answer "who has access to what, and why?" with evidence instead of spreadsheets.

how we help

Certification campaign design, request/approval workflows that people actually use, and governance reporting mapped to your compliance framework — ISO 27001, SOC 2, Essential Eight.

privileged-access

Okta Privileged Access (OPA)

Just-in-time, zero-standing-privilege access to servers and infrastructure, plus secure vaulting of shared secrets and service credentials. Admin access becomes something you check out, not something you keep.

how we help

Privileged account discovery, vault migration, and access policies that satisfy security without making your engineers route around them.

framework:essential-eight

Where Okta fits in the Essential Eight.

The ACSC's Essential Eight is the baseline for Australian government and, increasingly, the private sector. Identity is central to it — but no single platform covers all eight, and anyone telling you otherwise is selling something. Here's the honest map.

Multi-factor authentication direct Okta's core strength. Maturity Level 2 and 3 require phishing-resistant MFA — delivered through FastPass, Device Assurance, and FIDO2 passkeys rather than push notifications alone.
Restrict administrative privileges direct Privileged Access provides just-in-time admin with zero standing privileges; Identity Governance adds certification of privileged access and automated handling of dormant admin accounts.
Patch operating systems supporting Okta doesn't patch anything — but Device Assurance can require a minimum OS version before granting access, turning your patch policy into an enforced access condition.
Patch applications supporting Patching itself belongs to your endpoint tooling. Okta's device posture integrations can deny access from non-compliant endpoints, closing the gap between "policy" and "enforced".
Application control outside okta An endpoint control, delivered by tools like AppLocker or WDAC. Identity complements it but doesn't implement it.
Restrict Microsoft Office macros outside okta Group Policy and Intune territory. Not an identity control.
User application hardening outside okta Browser and application configuration hardening sits with your endpoint management stack.
Regular backups outside okta Your backup platform's job — though privileged access to backup systems is exactly what the two "direct" rows above should be protecting.

Working toward a maturity level? We run Essential Eight–aligned identity assessments: where your Okta configuration currently lands against ML1–ML3 for the identity-relevant strategies, and a sequenced plan to close the gaps — including the move to phishing-resistant MFA.

licensing:decoded

Licensing without the guesswork.

Okta packages these modules into suites — Starter through Enterprise — and sells most of them à la carte as well. Buying the wrong mix is easy and expensive. As a registered Okta reseller we can quote and transact the licences too — after right-sizing, with commercial terms on the table rather than buried in them.

01 — entitlement review

Know what you own

We map your current SKUs against what's actually deployed and in use. Shelfware is more common than you'd think.

02 — right-sizing

Buy only what you need

Suite versus add-on maths, based on your roadmap — not the vendor's. Sometimes one module à la carte beats a whole tier upgrade.

03 — renewal support

Renew from strength

Usage evidence before renewal, and registered-deal pricing where we transact the licence — informed customers pay less either way.

access:request

Not sure which modules you actually need?

That's the most common question we get — and the consultation is free. Tell us your environment and goals, and we'll give you a straight answer on the smallest licence footprint that gets you there.

Book a consultation
© 2026 Crossover IT Pty Ltd, trading as Identity One · Sydney, Australia · Independent consultancy — not affiliated with Okta, Inc.