Okta Plugin for User Risk Exchange

Okta Plugin for User Risk Exchange

This document explains how to configure Okta with User Risk Exchange in the Netskope Cloud Exchange platform. This integration enables seeing multiple connected systems’ risk values for individual users and groups.


To complete this configuration, you need:

  • A Netskope tenant (or multiple, for example, production and development/test instances)
  • A Netskope Cloud Exchange tenant with the User Risk Exchange module already configured.
  • Okta Domain and API Token for perform group operations.
  • No special license (Advanced Threat Protection) is needed.


  1. Obtain an Okta Domain and create an API token.
  2. Configure the Okta plugin.
  3. Configure Actions for the Okta plugin.
  4. Validate the Okta plugin.

Click play to watch a video.


Get your Okta Domain and Create an API Token

  1. Log in to Okta.
  2. Click Admin.
  3. Click on the downward arrow in the right upper corner.
  4. Copy the Okta domain.
  5. Go to Security > API.
  6. Click Create Token.
  7. Enter a token name and click Create Token
  8. Copy the token value. You need this to configure the Okta plugin.

Configure the Okta Plugin for User Risk Exchange

  1. Go to Settings > Plugins.
  2. Search for and select the Okta box to open the plugin creation dialog.
  3. Enter a Configuration Name
  4. Keep the Sync Interval default.
  5. Click Next.
  6. Enter your Okta Domain and the API Token obtained in the previous section.
  7. Click Next.
  8. Keep the Select Range default because the Okta plugin does not support fetching user scores.
  9. Click Save.

Configure Actions for the Okta Plugin

  1. Go to User Risk Exchange and click Actions.
  2. Click Add Action Configuration.
  3. Click the Business rule dropdown list and choose the appropriate Business rule.
  4. Select the Configuration dropdown list and choose Okta.
  5. Select Actions from the dropdown list and choose (Add to Group, Remove to Group or No Action).
    • Add to Group : When triggered, users are added to that group.
    • Remove to Group : When triggered, users are removed from that group.
    • No Action : This does not perform any actions on users.
  6. From the Group dropdown list, select a Group Name, or select Create new group from the Group dropdown list. Enter the Group Name if you want to create a new group in Okta.
  7. Click Save.
  8. Click Sync to perform the action manually.
  9. Enter the days, then click Fetch to see the number of users will be affected by this action.
  10. Click Sync for performing actions.

Validate the Okta Plugin for User Risk Exchange

To validate the plugin workflow, you can check in Netskope Cloud Exchange and in the Okta Platform.

Validate in Cloud Exchange

In Cloud Exchange, go to Action Logs.


Validate in Okta

  1. Open the Okta Admin section.
  2. Click Groups. Find the group you selected in the Business Rules for Okta.
Share this Doc
In this topic ...