What problem does it solve?
Provides a structured playbook to assess Okta as an identity provider in red-team engagements, detailing tenant discovery, user enumeration vectors, MFA configuration awareness, and post-compromise exposure surfaces across federated apps and IdP integrations.
Core Features & Use Cases
- Tenant discovery across Okta domains and federation endpoints (e.g., tenant.okta.com, tenant.okta-emea.com, oktapreview.com).
- User enumeration and authentication-flow analysis using primary Okta endpoints such as /api/v1/authn, /oauth2, and per-app SAML configurations.
- Password spray discipline and MFA configuration assessment with risk-aware guidance and rate-limiting considerations.
- Per-app misconfiguration checks (redirect_uris, SAML attributes, app metadata) and post-compromise API surface exploration.
- Evidence collection, reporting templates, and remediation guidance for red-team findings.
Quick Start
Map the target Okta tenant domains and known IdP configurations to scope the engagement and begin the discovery workflow.