Confirm Okta Identity Engine
Atomation's assessment supports Okta Identity Engine orgs only. Classic Engine orgs are not supported.
This is the assessment connection path. Customer portal SSO and SCIM are configured separately after your workspace is ready.
Atomation's assessment supports Okta Identity Engine orgs only. Classic Engine orgs are not supported.
During onboarding, a full-privilege temporary Super Admin SSWS token creates and configures the API Services app, assigns Super Administrator to the permanent app, grants 31 assessment reads plus org-level okta.appGrants.manage, verifies the result, and must be revoked before setup succeeds. Routine scans request only the reads.
Atomation verifies token issuance and confirms the granted scopes before the first snapshot. Runtime assessment calls do not manage users, groups, policies, apps, or settings.
The first scan captures point-in-time assessment data, evaluates the versioned rule library, and produces the initial report for review.
The customer portal can use Okta SSO and SCIM for team access. That integration is separate from the assessment connector that reviews your Okta org.
Repeat these steps for each additional Okta org under your main account. Atomation currently supports up to six orgs per account by default; higher limits can be approved by exception.
The Okta API Services app lets Atomation assess your Okta configuration. SAML SSO and SCIM provision users into the Atomation customer portal. They serve different purposes and should be configured separately.
Once the first scan completes, review the findings, control mappings, and remediation sequence before making changes in Okta.
Read the report guideThe assessment, its security model, delivery options, and report format in more detail.
Request a scoped Okta assessment. We'll align the baseline around your org count, reporting needs, evidence requirements, and delivery model.