Deep Linking is a ZeroTek feature that helps you manage customer Okta organizations. It lets eligible ZeroTek users SSO into customer Okta Admin Consoles with Okta Super Administrator privileges in a single click.
This article covers the MSP benefits and best practices of Deep Linking. To learn how the feature works, see Deep Linking – how it works. For instructions on using it, see Deep Link to a customer Okta org.
ROLE REQUIRED
ZeroTek Administrator
ZeroTek Technician
MSP benefits of Deep Linking
Deep Linking makes it easy to securely access the Okta Admin Console for the few one-time tasks that cannot be performed from ZeroTek, while also offering significant workflow and security advantages over logging directly into customer Okta orgs.
Better access management
With Deep Linking:
MSPs eliminate the need to create and manage a user account in each customer Okta org for every Technician who needs administrative access.
ZeroTek Admins and assigned ZeroTek Technicians can perform one-time management tasks in the customer Okta org that cannot be executed from ZeroTek via the Okta API, such as:
Initial Okta org/tenant one-time setup tasks like adjusting branding/customizing the org
Integrating on premises Active Directory, Microsoft 365 (M365), or other identity directories with Okta
Modifying app provisioning settings
Triggering app import actions manually
More efficient workflow
Instead of logging into your MSP's Okta and then into each customer Okta organization to manage it, Deep Linking lets you use ZeroTek as a control center for multi-tenant Okta management. ZeroTek Admins and assigned Technicians simply extend their access into specific customer Okta Admin Consoles as required.
Better auditing
Each Deep Linking session requires the user to enter Audit Notes before access is granted, which produces more meaningful event logs. Users can also optionally enter a ticket ID to link the session to a specific help desk ticket from their PSA tool.
BEST PRACTICE
Secure the Deep Link account according to MSP best practices — The Deep Link account is highly privileged, so it must be secured according to MSP best practices when setting up every new Okta org you create in ZeroTek. For instructions, follow the New Org Setup guide.
Give your MSP team guidelines for Audit Notes – For example, many MSPs require Technicians to enter the internal ticket number relevant to the Deep Link session in the Ticket ID field.
Never Deep Link to your own Okta Admin Console – While technically possible, this can result in multiple active sessions in the browser, which Okta does not support. Instead, log into your own Okta org and open the Okta Admin Console from there.
Never Deep Link into an Okta Admin Console where you already have an active session – This can cause browser issues, whether the existing session came from a previous Deep Link or from logging into the customer Okta Admin Console directly. If you run into problems, close all browser instances and reopen the browser.
