Okta US Public Sector Limitations or Exceptions
Last Updated:
Overview
The list below outlines any limitations or exceptions to specific features of an Okta product that are Audit-Ready, Supported, and/or Authorized for US Public Sector Service.
Okta for AI Agents - Core
Okta Identity Governance
Okta for AI Agents - Core
Okta for AI Agents - Core excludes Okta Privileged Access and Identity Security Posture Management. The Okta for AI Agents - Core SKU is the version of Okta for AI Agents available to FedRAMP Moderate and FedRAMP High customers. It is not available for Okta for US Military.
The following features are supported, just not yet authorized:
Okta Identity Governance
- Customers running OIG for the Public Sector
- FedRAMP High authorized as of January 27, 2026
- FedRAMP Moderate supported as of September 15, 2025
- Okta Identity Governance (OIG)
Below are services that have Federal variants that are not yet supported. These integrations were built using commercial versions of each vendor’s API and may not work with FedRAMP and DoD IL5 versions of those services. It is planned for release in the future.
Access Request and Access Certification Collaboration Tools
- MSFT Teams Notifications for Access Requests.
- These integrations were built using the commercial versions of the respective APIs and are not yet supported in our FedRAMP environments with the IL5/FRH/FRM versions of these apps. In the interim, users will still be able to receive notifications and submit approvals using email and the web UI.
- JIRA Integration for Access Request Request Types.
- ServiceNow Integration for Access Request Request Types.
- These integrations were built using the commercial versions of the respective APIs. Okta recommends, even for commercial customers, to use the workflows integration and JIRA/ServiceNow connectors to provide greater flexibility in what information is passed to these services. In our federal environments, JIRA/ServiceNow are roadmap connectors for the Workflows product, and customers can follow those timelines.
NOTE: For customers in Okta for Government Moderate for non-Fedramp purposes (for example, HIPAA environment support), they will be connected to a commercial cell for Okta Access Requests, which will be full-featured, similar to the structure used for Okta Workflows.
Entitlement Connectors
- On-Prem Entitlement Connectors (for example, SAP, Oracle EBS).
- The On-Prem Entitlement Connectors are not yet FedRAMP authorized and will not be available for purchase in the FedRAMP cells.
NOTE: Existing Entitlement Connectors work in both Commercial and FedRAMP.
Access Certifications
- LLM-generated summaries in Security Access Review are not currently available in compliance cells. It is planned for release in the future.
- Governance Analyzer with Okta AI.
- Governance Analyzer will not be available in the Federal cells when released to commercial customers. It is planned for release in the future.
Identity Threat Protection
Disclosures for Signal Detection Providers are Not Included in Regulated Cells
ITP Risk Detection is not authorized in Okta for Government High and Okta for US Military for:
- Suspicious login from an IP flagged by FastPass
- Suspicious login from an IP flagged in a credential-based attack
- Breached credential detected
Workflows
With the introduction of Workflows to Okta’s FedRAMP and DoD IL5, Okta is also including the full Connectors catalog that commercial customers use. Connectors are out-of-the-box integrations to a 3rd party vendor. They allow customers to connect to different APIs using productized event and action cards.
Most connectors were built using commercial versions of each vendor’s API and may or may not work with FedRAMP and DoD IL5 compliant versions of those services. The Okta team is currently testing and addressing these gaps to ensure all connectors in the applicable FedRAMP and/or DoD IL5 cell work as expected.
NOTE: The Customer is responsible for connecting Workflows to appropriate systems, vendors, and APIs based on their compliance obligations, and the Customer accepts the risk of using any non-FedRAMP or DoD authorized or compatible Connectors with their Workflow service.
The Vendor Product/Feature FedRAMP Status column is illustrative and not intended to accurately represent FedRAMP authorization status. Customers are responsible for confirming the FedRAMP status of Vendor Products, which is available at the FedRAMP Marketplace site.
Please review this article frequently for the most up-to-date information on Connector compatibility.
Workflow Connectors
|
Workflows Connector tested with US Public Sector APIs** |
Requirements to integrate | |
|---|---|---|
|
Okta |
Yes |
Enter the federal domain when creating a connection |
|
Okta Devices |
Yes |
Enter the federal domain when creating a connection |
|
SFTP |
Yes |
Enter the federal host and IP when creating a connection |
|
Azure AD |
Yes - GCC High only | FRM/FRH, GCC High only |
|
O365 (Mail, Calendar) |
Yes - GCC High only | FRM/FRH, GCC High only |
|
Excel Online |
No | FRM/FRH, GCC High only |
|
OneDrive |
No | FRM/FRH, GCC High only |
|
Microsoft Teams |
No | FRM/FRH, GCC High only |
|
ServiceNow |
No | |
|
Slack |
No | |
|
Slack Admin | No | |
|
Google Cloud Functions |
No | |
|
Google Workspace Admin |
No | |
|
Gmail | No | |
|
Google Calendar | No | |
|
Google Docs | No | |
|
Google Drive | No | |
|
Google Sheets | No | |
|
AWS Lambda | No | |
|
AWS Multi-Account Access | No | |
|
AWS S3 | No | |
|
Box | No | |
|
Smartsheet | No | |
|
Zoom | No | |
|
DocuSign | No | |
|
Oracle HCM | No | |
|
Oracle IAM | No | |
|
Splunk | No | |
|
Workday |
No | N/A |
|
Adobe User Management |
No | N/A |
|
Duo Security Admin |
No | N/A |
|
KnowBe4 |
No | N/A |
|
Proofpoint |
No | N/A |
|
Okta Identity Governance |
No | N/A |
|
Okta Realms |
No | N/A |
|
Netskope |
No | N/A |
|
Advanced Server Access |
No | N/A |
|
AirTable |
No | N/A |
|
Atlassian |
No | N/A |
|
Asana |
No | N/A |
|
Auth0 |
No | N/A |
|
BambooHR |
No | N/A |
|
Citrix ShareFile |
No | N/A |
|
Coupa |
No | N/A |
|
DataGrail |
No | N/A |
|
Dropbox for Business |
No | N/A |
|
Evident ID |
No | N/A |
|
Freshservice |
No | N/A |
|
GitHub |
No | N/A |
|
Greenhouse |
No | N/A |
|
Harmony SASE |
No | N/A |
|
HubSpot CRM |
No | N/A |
|
IBM Cloud |
No | N/A |
|
Jamf Pro Classic |
No | N/A |
|
Jira |
No | N/A |
|
Jira Service Management |
No | N/A |
|
Lucidchart |
No | N/A |
|
Marketo |
No | N/A |
|
Mimecast |
No | N/A |
|
Mixpanel |
No | N/A |
|
No | N/A | |
|
Netsuite |
No | N/A |
|
OneTrust |
No | N/A |
|
OpenAI |
No | N/A |
|
Opsgenie |
No | N/A |
|
PagerDuty |
No | N/A |
|
Personio |
No | N/A |
|
Salesforce |
No | N/A |
|
SAP Analytics Cloud |
No | N/A |
|
SendGrid |
No | N/A |
|
SentinelOne |
No | N/A |
|
Shopify |
No | N/A |
|
SmartHR |
No | N/A |
|
SmartRecruiters |
No | N/A |
|
Snowflake |
No | N/A |
|
Tableau |
No | N/A |
|
Tenable Vulnerability Management | No | N/A |
|
Trend Micro |
No | N/A |
|
Zendesk |
No | N/A |
|
Zoho Mail |
No | N/A |
If a specific connector is not available in the Connector catalog today, a custom one can be created using the Okta Workflows Connector Builder. The connector builder forum is also a resource for assistance.
Alternatively, suggestions for new vendors to be included in the catalog can be submitted via Okta Ideas.
________________________________**Any products, features, or functionality referenced in this material that are not currently generally available may not be delivered on time. Product roadmaps are not a commitment, obligation, or promise to deliver any product, feature, or functionality. Therefore, purchase decisions should not be based on them. Okta’s forward-looking statement applies to this article.
