Okta Secure LDAP
Okta is commonly used for SSO with SAML but it also has a Secure LDAP interface which can be used for both authentication and authoritzation. This section documents the steps to add Okta as a Secure LDAP authentication source in ClearPass
less than a minute
ClearPass can work with any open LDAP based directory as an authentication and authorization source. Here are the steps to integrate ClearPass with Okta for LDAP authentication. This integration can be used with TACACS+ / Captive Portal / Onboard workflows amongst others
- Create an authentication source of type Generic LDAP
- Configure Okta LDAP host details
- Configure auth filter to lookup using uid
- Configure filter to lookup group membership
Once the auth source is configured, we can now use it as part of authZ policies. Note that the username is the full email address since uid attribute in okta is usually email. Sample attributes from access tracker:
Feedback
Was this page helpful?
Glad to hear it!
Sorry to hear that.