Okta Identity Engine Access Management Security Training Course
| Course code | SD-CS-048 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Cyber Security |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Okta administrators and identity security teams are often expected to strengthen access controls without creating sign-in friction, breaking critical applications, or producing policy sprawl that cannot be audited. Okta Identity Engine provides granular controls for authentication, assurance, session management, application access and lifecycle-driven provisioning, but these controls must be designed as a coherent policy model. This course addresses the practical challenge of translating security requirements—such as phishing resistance, privileged access, device posture and contractor access—into maintainable Okta configurations.
Participants build and test an access-management design using Okta Identity Engine features, including authenticators, enrollment policies, authentication policies, global session policies, application sign-on policies, assurance requirements, groups, profile attributes and network zones. They learn to apply contextual access controls, use Okta Expression Language for attribute-based decisions, configure SAML and OIDC application integrations, implement SCIM provisioning patterns, and investigate authentication events through the System Log. The course also covers policy ordering, exception handling, break-glass access and change-control practices that reduce operational risk.
Delivery combines instructor-led technical walkthroughs with guided configuration labs in an Okta training environment. Participants work through a realistic enterprise scenario involving workforce users, administrators, contractors and sensitive SaaS applications. By the end of the week, each participant produces an Okta Identity Engine access-management blueprint containing policy rules, group and attribute design, authentication assurance decisions, application access patterns, test cases and an operational monitoring plan.
The course is designed for experienced identity practitioners who configure, operate, secure or govern Okta environments and need to make defensible access-policy decisions.
Course objectives
By the end of this course, participants will be able to:
- Design an Okta Identity Engine policy architecture that separates enrollment, authentication, session and application access decisions
- Configure authenticators and enrollment policies for passwordless, MFA and phishing-resistant authentication flows
- Build authentication and global session policies using user, group, network zone, device and risk context
- Create application sign-on policies that enforce differentiated controls for standard, sensitive and privileged applications
- Apply Okta Expression Language to implement attribute-based group rules and access decisions
- Configure SAML, OIDC and SCIM integrations with appropriate assignment, provisioning and deprovisioning controls
- Investigate sign-in, policy and provisioning events through Okta System Log queries and event evidence
- Produce an access-management blueprint with policy mappings, test cases, exception paths and operational ownership
Benefits of attending
For you
- Gain the ability to design Identity Engine policies that can be explained to security auditors and application owners
- Build practical confidence configuring phishing-resistant authentication and contextual access controls in Okta
- Develop a reusable method for separating workforce, contractor, privileged and break-glass access requirements
- Improve incident-investigation capability by linking Okta System Log evidence to authentication and policy outcomes
- Strengthen credibility for IAM engineering, Okta administration and identity security architecture roles
For your organisation
- Reduce account-compromise exposure through consistent MFA, assurance and contextual authentication policy design
- Lower access-control errors by standardising policy order, naming, exceptions and test-case documentation
- Improve protection of high-value SaaS applications through differentiated application sign-on policies
- Support faster onboarding and offboarding with group-driven assignments and SCIM lifecycle controls
- Provide an actionable access-management blueprint that can be reviewed by security, IAM and application teams
Target competencies
Who should attend
- Okta Administrators — who configure Identity Engine policies and need to secure access without disrupting users
- Identity and Access Management Engineers — who design authentication, authorization and provisioning patterns across enterprise applications
- Cyber Security Engineers — who translate conditional-access and phishing-resistance requirements into enforceable controls
- Identity Architects — who define scalable group, attribute, assurance and application-integration models
- Security Operations Analysts — who investigate sign-in anomalies, policy outcomes and identity-related security events
- IT Application Owners — who approve application access rules and need to understand SSO, MFA and provisioning implications
Requirements and prerequisites
Participants should have practical experience administering Okta or another enterprise identity platform and understand users, groups, MFA, SSO and least-privilege access. Familiarity with SAML 2.0, OpenID Connect, OAuth 2.0 concepts and basic SCIM provisioning is expected, as is confidence navigating a web-based administration console. Participants should be able to interpret simple JSON payloads and policy logic. Prior programming, API development or advanced scripting experience is not required. This is not an introductory identity-management course; complete beginners should first gain operational experience with authentication and SaaS application administration.
Training methodology
The instructor demonstrates each Okta Identity Engine control in a live tenant before participants configure the same capability in guided labs. Short design sessions use enterprise scenarios to compare assurance levels, policy conditions, application sensitivity and exception routes. Teams review deliberately flawed policy sets, identify security and usability failures, and propose corrected rule logic. Daily exercises produce configuration artefacts that feed into a final access-management blueprint, including policy maps, application controls, test evidence, monitoring queries and an implementation plan for the participant’s own environment.
Course outline
Day 1: Identity Engine architecture and access design
- Okta Identity Engine object model and policy evaluation flow
- Identity assurance, authentication context and access decision points
- Users, groups, profile attributes and group-rule design
- Network zones and contextual access conditions
- Policy hierarchy across enrollment, authentication, session and applications
- Access-control requirements mapping for workforce and contractor populations
- Policy naming, ownership and change-control conventions
Workshop: Participants map a multi-population enterprise access scenario into users, groups, attributes, network zones and a documented Identity Engine policy hierarchy.
Day 2: Authentication assurance and session security
- Authenticator types, enrollment requirements and authenticator assurance
- Password, Okta Verify, WebAuthn and FIDO2 authentication patterns
- Phishing-resistant MFA design for privileged and high-risk users
- Authenticator enrollment policies and recovery-factor controls
- Authentication policy rules and contextual MFA challenges
- Global session policies, session lifetime and reauthentication triggers
- Break-glass account controls and emergency access procedures
Workshop: Participants configure a tiered authentication model for standard users, administrators and emergency accounts, then test expected sign-in outcomes.
Day 3: Application access and federation controls
- SAML 2.0 application integration configuration and assertion controls
- OpenID Connect and OAuth 2.0 application access patterns
- Application sign-on policies and rule precedence
- Application sensitivity classification and assurance mapping
- Group assignments, application entitlements and least-privilege access
- Okta Expression Language for attribute-based assignment logic
- Testing SSO, MFA prompts, denied access and fallback paths
Workshop: Participants configure SAML and OIDC applications with separate sign-on policies for standard, sensitive and privileged access tiers.
Day 4: Lifecycle management and security monitoring
- SCIM 2.0 provisioning, profile mappings and attribute governance
- Just-in-time provisioning and directory-sourced identity considerations
- Deprovisioning, application assignment removal and orphan-account risk
- Service accounts, API tokens and administrative access separation
- Okta System Log event structure and event-type selection
- System Log searches for failed authentication, MFA and policy events
- Evidence collection for access reviews, investigations and audit support
Workshop: Participants build a SCIM lifecycle flow and create a System Log investigation worksheet for a simulated suspicious sign-in and deprovisioning failure.
Day 5: Policy validation and implementation planning
- Policy conflict analysis and unintended access-path detection
- Negative testing for bypasses, weak assurance and overbroad group membership
- Exception handling for contractors, legacy applications and offline recovery
- Access-policy test cases and acceptance criteria
- Production rollout sequencing, pilot groups and rollback decisions
- Operational ownership, policy review cadence and configuration documentation
- Access-management blueprint presentation and peer security review
Workshop: Participants complete and present an Okta Identity Engine access-management blueprint with policy diagrams, configuration decisions, test cases and a phased rollout plan.
Tools & standards covered
Okta Identity Engine, Okta Admin Console, Okta Expression Language, SCIM 2.0
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Cyber Security
Splunk Enterprise Security SIEM Operations Training Course
Security operations teams need more than dashboards and alert queues: they need a repeatable way to determine which detections represent cre…
Cyber Security Compliance for Healthcare Organisations Training Course
Healthcare organisations must protect electronic protected health information (ePHI) while keeping clinical, administrative and patient-faci…
Burp Suite Web Application Security Testing Training Course
Web applications expose business processes, customer data and internal services through complex combinations of APIs, authentication flows, …
COBIT 2019 Cyber Risk Governance Training Course
Cybersecurity teams often maintain risk registers, security controls and incident reports without a clear governance mechanism for deciding …