Okta saved us a lot of time and confusion
Overall Satisfaction with Okta
Okta is the primary cloud IdP for the campus. Several years ago we started a project to move all services and servers over to a more secure authentication and authorization system than local password databases within each application. Also, our Information Security department wanted to enforce uniform password criteria across the campus such that passwords would meet minimum criteria for best practices.
Pros
- Centralized control of enterprise passwords
- Extensive customization of acceptable password criteria
- One system for Identity and Access Management to learn
- Scalable throughout the university for all central services
- Uniform login experience for students, faculty, and staff
- Single point of response to address termination of access
- Ability to use FastPass for lower priority systems
- Excellent support of multi-factor requirements
Cons
- More provision for local branding would be appreciated
- Easier integration with campus MDM (Jamf Pro)
- Simpler console for non-Identity Management staff
- Greatly reduced offboarding access control changes
- Organized system access by functional groups
- Reduced the number of password control interfaced to one
- Enforcement of password standards/best practices
- Reduction of poor media exposure due to breaches
This has allowed us to reduce the familiarization period for students, staff, and faculty greatly. By only having one identity provider that is the same across all services, we only have to train them on one way to log in, and if they are having trouble for some reason, the Service Desk only has one system to need to troubleshoot or have a run book to lead them through to resolve their issue.
I haven't had any experience with their Professional Services or Education Services group, but I have had a couple of very good interactions with their Customer Success function when we were updating our macOS MDM system (Jamf Pro) to Okta authentication. As one of the engineers for that product, I was fairly nervous about downtime during the changeover. However, they made it very clear what was happening and what needed to be done, and working with them and our own local Identity and Access Management group made the whole process less stressful. The new access system works great, and is easy to use, and no longer is unique just to Jamf Pro.
We always strive to have minimum downtime for any reason on our campus/enterprise systems. Generally, if one of our systems were to go down, it would not be strictly due to the internal authentication, but if there were an access problem due to an end user having a problem with their password or level of access, it is very good to have a very reliable central one-stop shop for analyzing and correcting the problem.
Previous to Okta, we did not have a central cloud IdP system, each app had it's own authentication and authorization internally. That led to a fairly messy and divergent situation where every system had a different method and look for authentication and authorization. Cross-remembering what password went with what was a constant problem for the Service Desk, who had to know how to manipulate all of the various local password systems.
Do you think Okta delivers good value for the price?
Yes
Are you happy with Okta's feature set?
Yes
Did Okta live up to sales and marketing promises?
I wasn't involved with the selection/purchase process
Did implementation of Okta go as expected?
Yes
Would you buy Okta again?
Yes


Comments
Please log in to join the conversation