Microsoft Sentinel
Developer and API

Connect to Microsoft Sentinel using a Unified Connector

In brief

The article now uses updated navigation and permission guidance, identifies the Okta API token explicitly, and warns that deleting a connector stops ingestion, removes its configuration, and cannot be undone.

What Defender admins need to know

Review the updated setup references and consider the deletion warning before removing a connector.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

The user setting up the Okta connector must have these roles:

  • Log Analytics Contributor: Required to write data into the Log Analytics workspace and manage the Data Collection Rule (DCR).
  • Microsoft Sentinel Contributor: Required to modify connector settings in Sentinel.

If you connect to both Sentinel and Defender for Identity, you need permissions for both products.

Check user roles under the Access control (IAM) section of the Log analytics workspace. If you assign thesethe Log Analytics Contributor and Microsoft Sentinel Contributor roles, allow up to 15 minutes for the changes to take effect.

Okta credentials

To create a unified connector in Microsoft Sentinel:

  1. Go to the Data connectors Gallery Data connectors Gallery, or navigate to it via System > Data management > Data connectors.

    :::image type="content" source="./media/unified-connector-integration/connectors-gallery.png" alt-text="Screenshot of connectors gallery.":::

    For more information aboutinformation, see Data connectors Gallery in the Dataunified connectors Gallery, see Data connectors Gallery.article.

  2. In the My connectors tab, find the Unified connectors section.

  3. In the Name and connection details section, provide the following information:

    • Connector name: A descriptive user friendly name for the connector.
    • Domain name: The Okta domain, such as yourcompany.okta.com.
    • API key: Paste the Okta API token. Include only the token value, not the Authorization prefix. Select Next.
  4. In the Select products section, check the products you want to connect to. Check SIEM to enable the connector for Microsoft Sentinel.

  5. Configure the product details for each product you selected:

  6. Select Connect. The Connect button is only active when all the required fields are valid.

Edit a connector

To edit a connector, select it and then select Manage from the connector side panel.

:::image type="content" source="./media/unified-connector-integration/manage-connector.png" alt-text="Screenshot of Okta health page with Manage button highlighted.":::

Delete a connector

You can delete a connector in one of two ways:

  • Select it and then select Delete from the connector side panel.
  • Check the connector in the My Connectors tab and then select Delete from above the connector list.

:::image type="content" source="./media/unified-connector-integration/delete-connector.png" alt-text="Screenshot of Okta connector selected and the delete button highlighted.":::

Considerations and limitations

  • Unified connectors aren't visible in the Content hub. To see all connectors, including the traditional Sentinel connectors, go to the Data connectors Gallery

    You can delete a connector in one of two ways:

    • Select it and select Delete from the connector side panel.
    • Check the connector in the My Connectors tab and select Delete from above the connector list.

    :::image type="content" source="./media/unified-connector-integration/delete-connector.png" alt-text="Screenshot of Okta connector selected and the delete button highlighted.":::

    Considerations and limitations

    Consider the following limitations when using unified connectors:

    • Unified connectors aren't visible in the Content hub. To see all connectors, including the traditional Sentinel connectors, go to the Data connectors Gallery.