Skip to main content

Service accounts

Service accounts are:

  1. User accounts that are dedicated to non-human, non-interactive logins—by things like Windows services or applications—which allow the associated services/applications to run.

  2. Tied to permissions. If a service account is disabled or permissions are removed, the service won’t function.

WARNING

NEVER delete or modify an Okta service account after its correct initial setup is complete. Doing so will disable the related integration and result in service disruption.

Where can you create service accounts?

You can create service accounts in Okta or in other directories. For example, the Okta integration with Microsoft 365 (or M365, formerly branded Office 365) requires the creation of a dedicated service account in M365 to support the necessary API.

What are Okta service accounts?

Okta service accounts are Okta user accounts set up for use by a service. They:

  1. Consume Okta licenses. MSPs typically describe the extra licenses to customers as required security accounts.

  2. Are useful for auditing because you can isolate activities related to specific Okta service accounts in Okta system logs. You can easily view these events in the ZeroTek Log Viewer.

Common Okta service accounts

The MSP-Okta Integration and Deep Link accounts described below are relevant to all ZeroTek Partners.

MSP-Okta Integration account

ZeroTek automatically creates this Okta service account whenever you create a new Okta Org/tenant in ZeroTek. It is required for the integration between ZeroTek and Okta to work. It is automatically assigned Okta Super Administrator privileges.

Deep Link account

The Deep Link account is automatically created in the target customer Okta Org the first time a ZeroTek user successfully Deep Links to the customer's Okta Admin Console. This account always has Okta Super Administrator privileges.

OktaADAgent service account

If you integrate an Okta Org with on-premises Active Directory, it is an MSP best practice to manually create this Okta service account and assign it Okta Super Administrator privileges as part of the process.

OktaRADIUS service account

Okta Orgs that are integrated with on-premises AD are often integrated with RADIUS. If so, it is an MSP best practice to manually create this Okta service account as part of the integration process.

BEST PRACTICE

Always secure Okta service accounts as described in the Secure Service Accounts guide.


Did this answer your question?