ClearPass can work with any open LDAP based directory as an authentication and authorization source. Here are the steps to integrate ClearPass with Okta for LDAP authentication. This integration can be used with TACACS+ / Captive Portal / Onboard workflows amongst others
- Create an authentication source of type Generic LDAP
- Configure Okta LDAP host details
- Configure auth filter to lookup using uid
- Configure filter to lookup group membership
Once the auth source is configured, we can now use it as part of authZ policies. Note that the username is the full email address since uid attribute in okta is usually email. Sample attributes from access tracker: