
Okta
AccessPeople
Access & Identity
Mycroft reads Okta users, groups and application assignments to build the account inventory behind access reviews, and tests MFA, password and session policy.
Okta answers who has access to what, and its deactivation events give offboarding a measurable clock. Accounts in other connected systems are reconciled against the Okta roster, and any without a matching identity are surfaced as orphans.
How Mycroft connects to Okta
- How it connects
- You create an Okta OAuth service app and authorize it against your org. The grant includes offline_access so the connection refreshes itself.
- What Mycroft can access
- Read-only, and narrower than Okta's full management API: the granted scopes are okta.users.read and okta.authenticators.read.
Which controls Okta evidence maps to
Each row is a control an auditor tests and the specific artifact Mycroft collects from Okta to satisfy it. Collection runs on a schedule and every result is timestamped.
| Framework | Control | What it requires | Evidence collected from Okta |
|---|---|---|---|
| SOC 2 | CC6.1 | Logical access controls restrict access to information assets. | Full user, group and application assignment inventory, with MFA policy configuration and per-user enrolled factors. |
| SOC 2 | CC6.2 | Registration and authorization precede credential issuance; access is reviewed. | User creation and activation events from the Okta system log, matched to the hire date in your HRIS, plus the completed access review record for each account. |
| SOC 2 | CC6.3 | Access is granted on least privilege and removed when no longer needed. | Deactivation and suspension events with timestamps, and the measured interval to removal of each downstream account, giving an offboarding interval that is computed rather than asserted. |
| SOC 2 | CC6.7 | Authentication protects against unauthorized access. | Password policy settings (length, complexity, history, lockout), session lifetime and idle timeout, and MFA enforcement per application and per group. |
| ISO 27001 | A.5.16 | Identity management covers the full identity lifecycle. | Lifecycle event history for every identity (created, activated, suspended, deactivated) with the actor and timestamp for each transition. |
| ISO 27001 | A.5.17 | Authentication information is allocated and managed securely. | Enrolled factor inventory per user, factor policy configuration, and identification of users without a second factor. |
| ISO 27001 | A.5.18 | Access rights are provisioned, reviewed and revoked. | Periodic access review records: reviewer, accounts reviewed, decisions, exceptions raised and the date completed. |
| ISO 27001 | A.8.2 | Privileged access rights are restricted and controlled. | Inventory of Okta super administrators and other admin role holders, with MFA state and last sign-in for each. |
| HIPAA | §164.308(a)(3)(ii)(C) | Procedures terminate access when workforce membership ends. | Termination-to-deactivation interval for every departure, reconciled against the HRIS termination date. |
| HIPAA | §164.312(a)(2)(i) | Unique user identification is assigned and used. | Account inventory showing one identity per person, with shared and generic accounts flagged for exception handling. |
What Mycroft collects automatically
Gathered from Okta on a schedule, dated and stored against the controls above.
- Complete user roster with status, groups, application assignments and last sign-in
- MFA policy configuration and per-user enrolled factors, including users with none
- Password policy: length, complexity, history, expiry and lockout thresholds
- Session lifetime and idle timeout settings per policy
- Admin role holders (super admin, org admin, app admin) with MFA state
- Provisioning and deprovisioning events with actor and timestamp
- Dormant accounts identified by last-sign-in age against your threshold
- Orphaned downstream accounts with no matching Okta identity
Manual work this removes
The tasks that disappear from someone's quarter once Okta is connected.
- Exporting the user list, distributing it to managers and chasing responses each quarter
- Cross-referencing the leaver list against Okta to confirm access was removed in time
- Screenshotting MFA and password policy settings for each audit
- Searching for accounts in other systems with no matching identity
- Compiling the administrator list by hand
Okta and Mycroft: frequently asked questions
What does Mycroft read from Okta?
Can Mycroft change or deactivate users in Okta?
How does Okta automate user access reviews?
What is an orphaned account and why does it matter?
Does Mycroft read Okta system logs?
We turn the compliance nightmare into a dream
Talk to us


