
The implementation process for Okta software typically follows a structured methodology to ensure a smooth and successful deployment. This process is divided into several phases, starting with the Get Ready phase, where Okta evaluates the organization's preparedness, examines team details, and discusses data and environment challenges. This phase includes a streamlined assessment of customer readiness for implementation and deployment, as well as recommended next steps to achieve optimal results. The goal is to understand the long-term vision, primary problems to solve, timeframes, and any deadlines or other technology partners involved.
The next phase is Plan where a comprehensive plan is created. This involves onboarding the extended Okta and customer project teams, planning for project kickoff, designing workshop content, and coordinating attendees and scheduling. Regular steering check-ins are planned and scheduled during this phase, and continue throughout the rest of the project. The plan phase concludes with a project kickoff event and completion of a high-level timeline, including a formal project overview to determine the budget, resources, risks, and tasks involved.
Following the planning phase, the Design phase begins, where the detailed architecture and configuration of the Okta solution are developed. This includes defining user provisioning, authentication and credentialing processes, and the facilitation of these processes through APIs or other systems. The design phase ensures that the solution aligns with the organization's specific needs and strategic goals, and prepares for the subsequent build phase.
Okta software is highly customizable to fit specific business needs, offering a versatile platform with a spectrum of features designed to meet the dynamic requirements of diverse organizations. Customization involves tailoring authentication protocols, such as Single Sign-On (SSO) and Multi-Factor Authentication (MFA), to seamlessly integrate with existing applications and workflows. This allows organizations to select authentication methods that best align with their security policies and user preferences, enhancing both security and user experience.
For instance, Okta's SCIM (System for Cross-domain Identity Management) implementation is customizable, accommodating the diverse identity management needs of different systems. This adaptability streamlines identity management processes, making them more automated, efficient, and reliable. Okta's RESTful API also supports customization, allowing developers to create, read, update, and delete users from any script or code written, facilitating integration with various systems.
Okta provides a range of configurable security controls that allow customers to tailor the security of their use. These include configuring the complexity and rotation schedule for vaulted passwords, creating security administration policies, and managing access requests and approvals. This level of customization ensures that Okta can be adapted to meet the specific operational nuances and security requirements of any organization.
Okta offers comprehensive training and support to new users to ensure they can effectively use the platform. This includes various training programs, such as the Okta Training course provided by CloudFoundation, which covers advanced platform functionalities, identity and access management principles, and hands-on labs for practical experience. The course content includes topics like integrating Okta into an existing organization, creating and configuring user accounts, managing groups, configuring applications for secure access, and implementing password policies and multi-factor authentication.
Additionally, Okta provides Private Help Desk Training designed to quickly ramp up help desk teams on key end-user support processes. This training includes hands-on sessions where students learn about creating users, groups, administrator roles, password policies, and MFA policies. The training aims to prepare help desk teams to support end-users effectively, leading to faster case resolution and more successful end-user experiences.
Okta also offers a range of support services, including 1st and 2nd line training available at extra cost through professional services. These services include the development of support guides and knowledge articles, online training, and access to Okta certified resources. The support packages include features like incident response, platform maintenance, monthly health checks, and new feature recommendations, ensuring that organizations have the necessary support to maintain and optimize their Okta deployment.
Okta employs a comprehensive approach to security, ensuring the protection of customer data through a range of measures. The platform operates under a shared security responsibility model, where Okta is responsible for the secure delivery of the Identity Cloud and its underlying infrastructure, while customers are provided with configurable policy options to secure access to applications according to their requirements.
One of the key security measures is the implementation of robust data protection policies and procedures. Okta ensures that customer data is processed only as instructed by the customer and maintains policies for the secure deletion of customer data. Data is deleted using secure methods in accordance with applicable NIST guidelines, ensuring that it cannot be practicably read or reconstructed.
Okta also complies with a range of industry-standard certifications and authorizations, including SOC2, ISO 27001, CSA-Star, and FedRAMP. These certifications demonstrate Okta's commitment to maintaining high standards of security and data protection. Additionally, Okta undergoes regular third-party audits and participates in public bug bounty programs to identify and address potential vulnerabilities in its software.
Okta releases updates on a monthly basis, with each release including new features and fixes. These updates are rolled out gradually over a one-week period to ensure stability and minimize disruption. The release dates for upcoming updates are not final and are subject to change, which allows Okta to adapt to any unforeseen issues that may arise during the deployment process.
In addition to the monthly releases, Okta also provides weekly updates that follow each monthly release. These weekly updates include general updates and minor fixes that address any issues identified after the monthly release. This approach ensures that any critical bugs or security vulnerabilities are promptly addressed, maintaining the reliability and security of Okta's services.
Okta's release lifecycle is divided into several stages: Beta, Early Access (EA), General Availability (GA), and deprecated. Beta releases involve regular contact with Okta's product team and are primarily for testing new features. Early Access releases are new or enhanced functionalities made available for selective opt-in by customers. General Availability releases are features that have been thoroughly tested and are enabled by default for all customers. Deprecated features are those that are being phased out and will eventually be removed from the service.
Okta's policy on data ownership is clear: the customer retains ownership of all their data. According to the Master Subscription Agreement, as between Okta and the customer, the customer owns its data. Okta is granted a limited-term license to host, copy, transmit, and display customer data as reasonably necessary to provide the service in accordance with the agreement. This ensures that Okta does not acquire any right, title, or interest in the customer data beyond what is necessary to deliver the service.
Regarding data portability, Okta provides mechanisms for customers to retrieve their data. Upon termination of the agreement, customers can request a file of their data in a comma-separated value (.csv) format. This file will be made available for download at no cost for a maximum of thirty days following the end of the term. After this period, Okta has no obligation to maintain or provide any customer data and may delete all customer data from its systems, except for backup copies which will be deleted in the normal course of business.
During the term of the agreement, customers can also extract their data from the service using Okta's standard web services. This allows customers to maintain control over their data and ensures they can access and use their data as needed throughout the duration of their subscription.
Okta's services are designed to be flexible and scalable, allowing organizations to adjust their usage as their needs change. This flexibility is particularly important in dynamic work environments where the number of users and the level of service required can fluctuate significantly.
Organizations can scale up their usage by purchasing additional subscriptions or services as needed. This can be done through the execution of new order forms or statements of work that incorporate the terms of the existing agreement. This process ensures that any additional services are subject to the same terms and conditions as the original agreement, providing consistency and predictability for the customer.
Scaling down is also accommodated within Okta's framework. If an organization needs to reduce its usage, it can do so by not renewing certain subscriptions or by terminating specific order forms. The Master Subscription Agreement allows for the termination of the agreement or specific services if the customer provides written notice of non-renewal at least thirty days prior to the end of the current term or renewal term. This notice period gives both parties time to adjust and plan for the change in service levels.
Okta's pricing model is typically based on the number of users and the level of service required, which means that costs can be adjusted in line with the organization's actual usage. This usage-based pricing model helps organizations manage their IT budgets more effectively by aligning costs with actual needs. Additionally, Okta offers professional services to help organizations optimize their use of the platform, ensuring they get the most value from their investment.
The term of the Okta Master Subscription Agreement commences on the effective date and continues until the stated term in all order forms has expired or has otherwise been terminated. Subscriptions to the service commence on the date and for the period set forth in the applicable order form. Upon expiration of the term, unless otherwise stated, the service will automatically renew for additional terms equal in duration to the initial term, unless either party gives notice of non-renewal at least thirty days prior to the end of the then-current term or renewal term.
Either party may terminate the agreement by written notice to the other party if the other party materially breaches the agreement and does not cure such breach within thirty days of notice. Additionally, either party can terminate the agreement immediately if the other party becomes the subject of a petition in bankruptcy or any other proceeding relating to insolvency, receivership, liquidation, or assignment for the benefit of creditors. Upon termination for cause by the customer, Okta will refund a pro-rata portion of any prepaid fees that cover the remainder of the applicable term after the termination.
Upon termination of the agreement, all rights, and subscriptions granted to the customer will immediately terminate, and the customer must cease using the service. Okta will make available to the customer a file of their data in a .csv format for download for a maximum of thirty days following the end of the term. After this period, Okta has no obligation to maintain or provide any customer data and may delete all customer data from its systems, except for backup copies which will be deleted in the normal course of business.
Okta meets a wide range of compliance standards, demonstrating its commitment to security and regulatory requirements. These standards include:
ISO Certifications: Okta is ISO 27001:2013 certified, which is an international standard for information security management systems. Additionally, Okta is ISO 27018:2019 compliant, which focuses on the protection of personal data in the cloud, and ISO 27017 compliant, which provides guidelines for information security controls applicable to the provision and use of cloud services.
HIPAA: Okta's HIPAA Compliant Service instance serves customers in the healthcare industry, ensuring that they can meet the stringent security and privacy requirements of the Health Insurance Portability and Accountability Act.
PCI-DSS: Okta has a PCI Attestation of Compliance, and its multi-factor authentication (MFA) solution qualifies as a compliant solution under the Payment Card Industry Data Security Standard (PCI-DSS) requirements. This enables customers to use Okta as a supporting system for PCI compliance.
GDPR: Okta's Identity and Access Management (IAM) system provides a strong foundation for General Data Protection Regulation (GDPR) compliance, helping organizations reduce their risk and meet the requirements of this European data protection regulation.
Sarbanes-Oxley (SOX): Okta's tools help ensure that SOX controls are in place and generating evidence for auditors. This includes application provisioning and provisioning, enforcing password complexity requirements, and providing single sign-on access.
NYDFS: Okta's IAM solutions help organizations comply with the access requirements specified by the New York Department of Financial Services (NYDFS).
ENS High: Okta achieved ENS High certification status, which is a framework established by the Spanish government to ensure the security of information systems. This certification signifies that Okta has met the highest level of security requirements defined by the ENS.
APEC PRP: Okta's Asia-Pacific Economic Cooperation (APEC) Privacy Recognition for Processors (PRP) certification demonstrates its ability to support cross-border data transfers in compliance with APEC privacy principles.
EU Cloud Code of Conduct: Okta's services are verified to be adherent to the European Union Cloud Code of Conduct, which is a mechanism for service providers to demonstrate their adherence to the requirements of Article 28 of the GDPR.
These certifications and compliance standards highlight Okta's dedication to maintaining high levels of security and regulatory compliance, providing customers with confidence in the protection and management of their data.