Configure authentication to Okta
Beta
This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Okta System Logs from the Previews page. See Manage Databricks previews.
Configure Okta to enable authentication from Databricks for the Okta System Logs connector. Use the API token and organization domain from these steps to create a Unity Catalog connection.
Prerequisites
- An active Okta super administrator, org administrator, or read-only administrator account. Databricks recommends using a read-only administrator account for least-privilege System Log access.
- Access to the Okta Admin Console.
note
An API token has the same permissions as the administrator who creates it. If that administrator's permissions change or the account is deactivated, the token is affected. For details, see Manage Okta API tokens.
Configure Okta
- Sign in to the Okta Admin Console with the administrator account that will own the token.
- Go to Security > API.
- Click the Tokens tab.
- Click Create token.
- Enter a name for the token.
- For API calls made with this token must originate from, select Any IP.
- Click Create token.
- Copy the displayed SSWS API token. Okta doesn't display the token again.
- Note your Okta organization domain, such as
company-name.okta.com. - On the Tokens tab, confirm that the token's Role is Super Admin, Organization Admin, or Read-only Admin.
For more information, see Manage Okta API tokens.
Next steps
Create a Okta System Logs connection in Databricks. See Create an Okta System Logs connection.