What is our primary use case?
My use cases for Okta Platform involve having a single place for authentication, as my company requires it for all of our applications that we use with our organization, which includes SAML and SSO. It's a critical piece for authentication, and the token generally lasts about eight hours based on our company's configuration, allowing us to sign in once a day and eliminating the need to enter credentials multiple times for different applications. Okta Platform authentication is essential because it minimizes the hassle of signing into multiple applications while maintaining security. Essentially, all my critical apps are secured with Okta Platform, which also provides features like second-factor authentication through cell phone verification or facial recognition. Overall, it's very functional and an integral part of our business processes.
Regarding how Okta Platform helps secure access to cloud infrastructure, APIs, containerized workloads, or AI services in our architecture, I can't provide an authoritative answer on how security is hardened since I wasn't involved in that aspect. However, I know that it provides security. My company has been using it for four years without plans to change because it remains secure, even as we increase our internal applications and expose some to clients.
The workloads secured by Okta Platform are hosted across multiple cloud providers, including AWS, Azure, and some GCP, so it encompasses all of those.
For AWS, we have integrated EC2 instances with Okta Platform, and I'm not sure about other services or buckets related to the things you mentioned, such as Amazon Voice.
What is most valuable?
I see the benefits of Okta Platform immediately upon deployment, as it saves time. Dealing with multiple authentications without a federated system is time-consuming, requiring different passwords for different applications, which is a hassle. As soon as Okta Platform was implemented, there was an immediate improvement in the ease and speed of secure authentication.
Personally, I have noticed measurable security and operational improvements since implementing Okta Platform, primarily due to the ease of access it provides in a more secure manner while saving time.
What needs improvement?
What I dislike about Okta Platform is that sometimes there has been some downtime. It doesn't happen often, but ironically, it did occur on a day I knew this call was coming, leading to a brief period when Okta Platform authentication didn't work. We had to rely on third-party IT support to resolve it. When this happens, it stops us from accessing what we need until the issue is fixed.
I have to mention some occasional downtime with Okta Platform. It doesn't occur very often, but when it happens, it's crucial because you can feel stuck without it.
For how long have I used the solution?
I have been working with Okta Platform for just over four years.
What do I think about the stability of the solution?
Regarding stability, there hasn't been much to note aside from some occasional downtime, but I appreciate the different options provided by Okta Platform for verification. You can manually enter a password, use push notifications, or facial recognition, which can be more convenient depending on the context, whether mobile or at a desk.
What do I think about the scalability of the solution?
I believe Okta Platform has been scalable. My company has integrated all major applications, and it has supported our growth without issues.
How are customer service and support?
I've contacted internal company IT support a few times while learning the intricacies of Okta Platform, but I've never reached out to Okta Platform's direct customer support.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
My organization hasn't tried any alternatives to Okta Platform, and I personally haven't had the need to seek them out. Some people look for alternatives such as password managers, but those are not the same. Implementing a solution such as Okta Platform isn't straightforward without a team behind it, so once it was working here, there wasn't a felt need to explore other options. I'm unsure of what the previous system was, but I believe they considered Cisco Duo at one point without ultimately proceeding.
How was the initial setup?
The initial deployment of Okta Platform was easy and without any significant bumps, as far as I know.
What about the implementation team?
The deployment of Okta Platform involves a lot of collaboration across the security team, working with the CISO to ensure adherence to standards such as SOC and FINRA. Though technically it's not a one-person job, my company wouldn't implement it that way either, as there is always a team behind it.
What other advice do I have?
I probably don't think of anything else, as Okta Platform does what it intends to do. Given my experience in the field, I recognize that these tools work well, but they're only as effective as their configuration and security hardening. My company has done an excellent job with Okta Platform, and I feel it's a quality product because it effectively integrates single sign-on and SAML authentication.
I'm not entirely sure if our organization uses Okta Platform to protect non-human identities, such as service accounts or AI agents, as we've rolled out chatbots and are developing them. I can't confidently answer that question.
Okta Platform does help address specific industry or regulatory requirements, such as those in healthcare and financial services, for both our organization as an outsourced IT service provider and internally when accessing platforms.
On my end, there are updates from time to time for apps on mobile devices or operating systems that need to be addressed, but company policies manage updates for company-owned workstations, so it's not too burdensome.
I'm not aware of any formal partnerships with Okta Platform in my department, so I can't speak to that.
I would rate this review an 8 overall.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.