Okta sells its platform as suites and à la carte add-ons — and the packaging changes often enough that even IT teams lose track of what they own. Here's what each module actually does, when you need it, and where we come in.
The newest — and fastest-moving — part of the catalogue. AI agents are now the fastest-growing identity type in the enterprise, and mostly the least governed. Okta's answer is to treat every agent as a first-class identity: owned, scoped, auditable, and revocable.
Discovers known and shadow AI agents across your environment, registers them in Universal Directory with a named human owner, and replaces long-lived API keys with short-lived, scoped credentials. Includes a universal-logout "kill switch" to instantly revoke a misbehaving agent. Generally available since April 2026.
Agent discovery and inventory (you have more shadow agents than you think), delegation scope design, ownership and lifecycle policies, and governance workflows so every agent action traces back to an accountable human.
An open protocol extending OAuth for agent-to-app and app-to-app connections. Replaces ad-hoc integrations and endless user consent prompts with centralised, policy-driven access decisions made by your identity provider — including what agents can reach via MCP servers and APIs.
Connection policy design for agent-to-resource access — which agents may reach which APIs, under whose delegation, with what scopes — and staged enablement as your app vendors adopt the protocol.
For teams building their own agents: embedded authentication, secure token vaulting, asynchronous human-in-the-loop approvals, and fine-grained authorisation — so an agent acting inside your product is as governed as a user signing into it.
Identity architecture for agent builds — delegation chains, token lifetime strategy, and approval flows — designed before the agent ships, not retrofitted after the incident.
Agents are the sharp end of a broader problem: service accounts, API tokens, and machine credentials now outnumber your people many times over. The same discover–own–scope–revoke discipline applies to all of them.
NHI audits across your tenant — dormant service accounts, over-scoped tokens, credentials with no owner — with remediation automated through Workflows where it makes sense.
The foundation layer — who your users are and how they sign in. Almost every Okta tenant starts here.
One set of credentials for every application — cloud, on-prem, and custom. Users get one dashboard; you get one place to control and log access across 8,000+ pre-built integrations.
App integrations done right the first time — SAML/OIDC configuration, sign-on policies, and a rollout sequence that doesn't break anyone's Monday.
Multi-factor authentication that responds to risk — device posture, location, network — rather than challenging everyone equally. Fewer prompts for low-risk sign-ins, harder walls where it matters.
Policy design that balances security with friction: who gets challenged, when, with which factors — informed by your actual sign-on data, not guesswork.
A single, flexible user store that consolidates identities from Active Directory, LDAP, HR systems, and CSVs — with custom attributes and profile mappings feeding every downstream app.
Attribute architecture and profile mastering — deciding which system owns which attribute, so your directory is a source of truth, not a source of arguments.
Extends Okta SSO and MFA to legacy on-premises applications that don't speak modern protocols — no code changes to the apps themselves.
Assessment of which legacy apps are worth fronting with the gateway versus migrating or retiring — then the deployment itself.
Okta FastPass, Device Assurance, and FIDO2 passkeys replace passwords with phishing-resistant, device-bound sign-in. Users stop typing credentials; attackers stop having credentials to steal. This is also the authentication strength the Essential Eight demands at Maturity Level 2 and above.
End-to-end passwordless programmes: factor strategy, Device Assurance policy design, staged enrolment, and the edge cases that stall rollouts — shared workstations, BYOD, frontline workers, and the day someone loses their phone.
Where Okta stops being a login box and starts removing work. Joiners, movers, and leavers — handled without tickets.
Automated provisioning and deprovisioning driven by your HR system or directory. New starters get their apps on day one; leavers lose access the moment they should — not weeks later.
HR-as-a-source integrations, group rule design (including the Okta Expression Language edge cases that trip people up), and deprovisioning that actually deprovisions.
No-code automation for the identity logic that doesn't fit standard lifecycle policies — inactivity handling, staged offboarding, custom notifications, cross-system API calls. Suites include a workflow allowance; heavy use is licensed beyond it.
We design and build production-grade flows — like automated handling of dormant privileged accounts — and document them so they're maintainable, not magic.
The modules auditors ask about. Proving that the right people have the right access — and only that.
Access certifications, access requests with approval flows, and separation-of-duties controls. This is how you stop privilege creep and answer "who has access to what, and why?" with evidence instead of spreadsheets.
Certification campaign design, request/approval workflows that people actually use, and governance reporting mapped to your compliance framework — ISO 27001, SOC 2, Essential Eight.
Just-in-time, zero-standing-privilege access to servers and infrastructure, plus secure vaulting of shared secrets and service credentials. Admin access becomes something you check out, not something you keep.
Privileged account discovery, vault migration, and access policies that satisfy security without making your engineers route around them.
The ACSC's Essential Eight is the baseline for Australian government and, increasingly, the private sector. Identity is central to it — but no single platform covers all eight, and anyone telling you otherwise is selling something. Here's the honest map.
Working toward a maturity level? We run Essential Eight–aligned identity assessments: where your Okta configuration currently lands against ML1–ML3 for the identity-relevant strategies, and a sequenced plan to close the gaps — including the move to phishing-resistant MFA.
Okta packages these modules into suites — Starter through Enterprise — and sells most of them à la carte as well. Buying the wrong mix is easy and expensive. As a registered Okta reseller we can quote and transact the licences too — after right-sizing, with commercial terms on the table rather than buried in them.
We map your current SKUs against what's actually deployed and in use. Shelfware is more common than you'd think.
Suite versus add-on maths, based on your roadmap — not the vendor's. Sometimes one module à la carte beats a whole tier upgrade.
Usage evidence before renewal, and registered-deal pricing where we transact the licence — informed customers pay less either way.
That's the most common question we get — and the consultation is free. Tell us your environment and goals, and we'll give you a straight answer on the smallest licence footprint that gets you there.
Book a consultation