4 ms·
My organization evaluated Okta and I also came away worried about introducing another third party that had access to all of our services, both from a security p
by mnutt 9y ago
My organization evaluated Okta and I also came away worried about introducing another third party that had access to all of our services, both from a security perspective and as another point of failure.
In particular, in Okta's SWA apps they have a setting for those apps to use the same password as the user's Okta password. If there's a way they do this without storing all of their user passwords unhashed, I couldn't figure it out and the Okta reps weren't able to provide a clear answer.
Edit: I _can_ think of one potential solution: Okta initially sets user's password to a random string, when you authenticate with Okta / change your Okta password, they use the unhashed version to make admin calls to update the apps' password and never persist it. But they didn't give any indication that this was the case.