ZeroConfig Automated Reports is a paid add-on that automatically scans your managed Okta orgs each week to detect configuration drift—that is, any deviation between what is defined in an applied ZeroConfig template and what is currently configured in the org—and then notifies specific ZeroTek Administrators about the findings by email. This add-on works in conjunction with the ZeroConfig paid add-on.
Use case
When a ZeroConfig template is applied to an Okta org, it establishes a baseline configuration. Over time, settings in that org can drift from that baseline, whether due to an accidental change, an unauthorized modification, or a deliberate and justifiable customization. Automated Reports give you regular, systematic visibility into which orgs remain compliant and which require your attention, without any manual effort.
Because ZeroConfig templates typically represent an MSP's core security baseline consisting of essential groups, policies, authenticator requirements, network zones, and more, this drift detection directly supports the security and consistency of your clients' environments.
How it works
When active, Automated Reports runs a Report Only scan every Saturday morning for all Okta orgs that have an active ZeroConfig template applied.
By default, all ZeroTek Administrators receive an email notification summarizing the results of the scan, indicating which orgs align with their applied ZeroConfig template, and which orgs have drifted. You can manage which ZeroTek Admins receive these emails on the ZeroConfig > Automated Reports tab.
To view detailed results, navigate to ZeroConfig > Activity and look for runs where the Activity Type is System Scheduled.
Each report includes:
A summary showing overall compliance status across all orgs the template was run against
A per-component breakdown listing each template component and its compliance status
Outcome details for each component, showing which orgs are affected and the nature of the issue. For example, whether a network zone is missing entirely or simply doesn't require modification
Once you've identified which orgs and components need attention, you can investigate the specific org and decide on the appropriate next step. For example, while non-compliant results typically require remediation, you might decide to maintain a deliberate configuration change through a separate template.
Activating and deactivating
Automated Reports can be activated or deactivated from the ZeroConfig > Automated Reports tab. Note that this setting applies to all orgs with an active ZeroConfig template applied. Before activating, review the billing details for this add-on. Learn more about Automated Reports billing.
