NEWFreshservice is now a Ploy integrationSee what shipped
INTEGRATIONSIDENTITY PROVIDER
OktaENABLED · 28 OF 28 CAPABILITIES ASSESSED

Okta groups and app assignments are granted from Ploy

Okta knows who your people are. Ploy reads what that actually grants them: every group, app assignment and MFA factor. Then it grants, expires and revokes on your rules.

TYPE · IDPAUTH · OAUTH + SCIMDOMAIN · OKTA.COMLAST ASSESSED · 29 JUL 2026
Okta connectorHOURLY SYNCCAPABILITIES
WHAT PLOY DOES
Sync users, status and last sign-inEvery Okta user, whether the account is active, suspended or deactivated, and when they last signed in.
READ
Import Okta profiles as peopleName, email, department, division, manager, employment type and dates from the Okta profile. This is directory data, not a dedicated HR system.
READ
Discover groups and application assignmentsThe grantable things in Okta, with who holds which group and which SSO tile, at what level.
READ
Read MFA factorsWhether a user has a second factor enrolled and which methods are registered.
READ
Map groups to the applications they unlockGroup-to-application assignments are captured, so a request for an app resolves to the group that actually grants it. No document or file content is scanned.
READ
Create and update usersPloy opens the Okta account a joiner needs and keeps the profile in step when their role changes.
WRITE
Suspend, reactivate or delete a userLifecycle changes run through the update-user path rather than dedicated actions, so suspend, unsuspend, activate and delete all happen there.
WRITE
Grant and revoke group membership and application assignmentsApproved access is written straight into the Okta group or app assignment that carries it, and pulled when the grant ends.
WRITE
2.1WHAT IT UNLOCKS

Three jobs this connector does on day one

OFFBOARDING

Suspended the day the end date lands

The HR system records a leaver. Ploy suspends the Okta account and removes the group memberships and application assignments that came with it.

leaver detected · 09:04
okta user suspended · 09:04
6 group memberships removed · 09:05
9 app assignments removed · 09:05
JUST IN TIME ACCESS

Group membership with a clock

Requests land in Slack, approvals write straight to the group, and the grant drops itself when the window closes. Nobody has to remember.

okta-admins-billing4H LEFT
salesforce-superuserREVOKED
REVIEWS AND EVIDENCE

Reviewers see context, not a list

Each row carries department, MFA factors and last sign-in as they were at review time. Revocations execute in Okta and land in the certificate.

Department (at review time)MFA enabled (at review time)Last sign in (at review time)
2.2CAPABILITY MATRIX

All 28 capabilities, tested weekly

Ploy runs the same assessment against every integration and shows you the result. Nothing here is aspirational.

23 / 28 PASSING
USERS7 / 7
List usersREAD
Read profile attributesREAD
Read lifecycle statusREAD
Read MFA factorsREAD
Suspend userWRITE
Restore userWRITE
Deactivate userWRITE
GROUPS AND ROLES6 / 7
List groupsREAD
Read membershipREAD
Read group rulesREAD
Read admin rolesREAD
Add memberWRITE
Remove memberWRITE
APPS AND ENTITLEMENTS7 / 7
List applicationsREAD
Read assignmentsREAD
Read granted scopesREAD
Read app adminsREAD
Read app profile mappingREAD
Assign applicationWRITE
Unassign applicationWRITE
ACTIVITY AND SESSIONS3 / 7
Read last sign inREAD
Read device contextREAD
Read API tokensREAD
2.3

SETUP

TYPICALLY 10 MINUTES
STEP 01

Authorise the app

A super admin approves the Ploy OAuth app in your Okta org. Read only to begin with.

STEP 02

Watch the first sync

Users, groups and app assignments land in the graph. Most orgs finish in under two minutes.

STEP 03

Turn on writes

Pick which groups and apps Ploy may change, and who approves. Everything else stays read only.

SCOPES REQUESTEDokta.users.readokta.groups.manageokta.apps.manageokta.logs.read
2.4OFTEN CONNECTED TOGETHER
MicrosoftIDENTITY PROVIDERGoogle WorkspaceIDENTITY PROVIDERWorkdayHR SOURCESlackAPPROVALS
BROWSE ALL 62 INTEGRATIONS

Connect Okta, see it in 10 minutes.