<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Using the Okta Access Testing Tool

Multi-Factor Authentication
Okta Identity Engine

Overview

The Okta Access Testing Tool enables simulations of real-world user requests to verify application access. This tool evaluates authentication, authenticator enrollment, global session, and user enrollment policies to determine if a user or group meets the configured requirements. Administrators use this tool to validate policy configurations and ensure Okta applies the correct access controls.

Applies To

  • Okta Identity Engine (OIE)
  • Access Testing Tool

Solution

What are the steps to use the Okta Access Testing Tool?

Open the target policy, navigate to the Access Testing Tool in the Okta Admin Console, configure the simulation parameters, and execute the test to review the matching policies as detailed in either the video demonstration or the written instructions.

 

     

    1. Open the policy to test and note the options present in the rules.
    2. In the Okta Admin Console, go to Reports > Access testing tool. Navigate through the Reports menu to locate and select the Access testing tool option.
      &quot;Access testing tool&quot; menu
    3. Select the same options present in the target policy:
      • Application: Choose the application that requires access testing. Select the target application from the dropdown menu to configure the simulation.
        NOTE: Only the first ten apps display in the dropdown menu. To target a specific app, type the name and select the desired app.
        Access Testing tool - Application field
      • Username: Enter the username of a user for access testing and select it from the list. To add another user, enter the name and select it from the list. To view groups, click Specify group instead. To return to adding usernames, select Specify username instead.


    NOTE: When entering any value in the user search field on the Access Testing Tool page, the search function compares the search value with the user profile attributes firstName, lastName, and email.

     

      • Device state: (Optional) Choose a device state to include in the test.
      • Device platform: (Optional) Choose a device platform to include in the test.
      • IP address / Network Zone: (Optional) Select a network zone or enter a single IP address, and press Enter to include it in the test.


    NOTE: The Access Testing Tool does not support dynamic zones or Advanced Posture Checks (osquery). Okta cannot collect or execute real-time osquery signals from Okta Verify on a physical device, which causes rules enforcing custom posture checks to evaluate to Deny in simulations.

     

      • Risk score: (Optional) Choose a risk score level to include in the test.
    1. Click Run test.
    2. Review the results in the Results section of the page. Analyze the simulation output to determine which policies match the configured criteria.
      Results
    3. In the Matching Policies section, review the policies that match the criteria. Choose the format to display the results:
      • Sign-in journey view: View which policies and rules match the criteria present in the simulator for each stage of the sign-in journey. Click each tile to view the information for that stage.
        • Authenticate: View which policies contain the authenticators and authentication requirements that match the criteria present in the simulator.
        • Fulfill authenticator enrollment requirements: View which rules contain the authenticator enrollment criteria present in the simulator.
        • Fulfill user registration requirements: View which rules contain the criteria for the profile attribute enrollment present in the simulator.
      • List all views: View all policies and rules that match the criteria in a list.
    4. Click Clear test to clear the criteria and configure a new test.

     

    Related References

    Loading
    Using the Okta Access Testing Tool | Okta Support