Microsoft Defender XDR
Identity protection

Enable attack disruption actions in Okta with Microsoft Defender XDR

In brief

The article updates its title and terminology, clarifies Okta and Microsoft prerequisites, and specifies that the saved token is used when creating an integration profile in the Defender portal. The prerequisite link text and documentation metadata were also updated.

What Defender admins need to know

Administrators configuring the Okta integration should follow the revised prerequisite wording and setup terminology.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Enable attack disruption actions in Okta with Microsoft Sentinel (preview)

Microsoft Defender XDR's automatic attack disruption capabilities can help protect your Okta-managed identities by automatically responding to threats. When an identity managed by Okta is compromised, Defender XDR can take remediation actions directly in Okta to contain the attack, limit lateral movement, and reduce overall impact.

This article describes how to set up the Okta integration within Microsoft Defender for Identity to enable attack disruption actions in your Okta environment. Before you begin, review the prerequisites to ensure your Okta and Microsoft environments are properly configured.

Prerequisites

BeforeMake sure you begin, make sure the following prerequisites are met:meet these requirements:

Okta requirements

You haveneed an Okta account with admin privileges andaccess. You also need a developer or enterprise license.

Microsoft requirements

Make sure the following Microsoft prerequisites are completedComplete these steps before you continue:

  • YourConnect your Microsoft Sentinel analytic workspace is connected to the unified security operations portalportal.
  • TheDeploy and enable the Okta connector for Microsoft Sentinel is deployed and enabled.Sentinel.
  1. Create an Okta API key

    • Provide a friendly name for your token
    • Make sure to keep the generated token value to be used later when creating the integration.integration profile in the Defender portal.

Related content