Skip to main content

Configure authentication to Okta

Beta

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Okta System Logs from the Previews page. See Manage Databricks previews.

Configure Okta to enable authentication from Databricks for the Okta System Logs connector. Use the API token and organization domain from these steps to create a Unity Catalog connection.

Prerequisites​

  • An active Okta super administrator, org administrator, or read-only administrator account. Databricks recommends using a read-only administrator account for least-privilege System Log access.
  • Access to the Okta Admin Console.
note

An API token has the same permissions as the administrator who creates it. If that administrator's permissions change or the account is deactivated, the token is affected. For details, see Manage Okta API tokens.

Configure Okta​

  1. Sign in to the Okta Admin Console with the administrator account that will own the token.
  2. Go to Security > API.
  3. Click the Tokens tab.
  4. Click Create token.
  5. Enter a name for the token.
  6. For API calls made with this token must originate from, select Any IP.
  7. Click Create token.
  8. Copy the displayed SSWS API token. Okta doesn't display the token again.
  9. Note your Okta organization domain, such as company-name.okta.com.
  10. On the Tokens tab, confirm that the token's Role is Super Admin, Organization Admin, or Read-only Admin.

For more information, see Manage Okta API tokens.

Next steps​

Create a Okta System Logs connection in Databricks. See Create an Okta System Logs connection.