0D5WR00001WQhpr0ADOkta Classic EngineIntegrationsAnswered2026-04-09T15:11:45.000Z2026-04-08T19:10:37.000Z2026-04-09T15:11:45.000Z

NicolasR.94674 (Customer) asked a question.

How to activate Okta Cloud Connect (OCC) for Palo Alto Networks integration to remove 10-user limit?

Hi Community,

I am a Palo Alto Networks customer attempting to integrate our firewalls with Okta using the Cloud Identity Engine. I have already added the 'Palo Alto Networks - GlobalProtect' app to my tenant, but I am currently stuck with a 10-user limit on a Free Trial plan.

My tenant ID is: integrator-1938521

According to the strategic alliance between Okta and Palo Alto, I should be eligible for the Okta Cloud Connect (OCC) / Palo Alto Networks Starter Pack, which provides unlimited users for this specific integration.

Unfortunately, I cannot open a support case directly as my permissions are restricted. Could someone guide me on how to get this license activated for my organization?

Thank you!"


  • Paul S. (Okta, Inc.)

    Hello @NicolasR.94674 (Customer)​ Thank you for posting on our Community page!

     

    That type of Okta environment is provided by Palo Alto, not by Okta. I would recommend to reach out to Palo Alto and discuss with them about the enviromnet.

     

    Thank you for reaching out to our Community and have a great day!

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Expand Post
  • NicolasR.94674 (Customer)

    Thank you for your response. However, we are in a deadlock situation. We have already reached out to Palo Alto's TAC, and their official stance is that the activation must be handled directly by Okta Support.

     

    Since both providers are pointing to each other, could you please provide an official Okta Knowledge Base (KB) article or documentation stating that Okta is not responsible for the activation of this specific environment? Having this documentation will help us escalate the matter internally with Palo Alto and find a resolution.

     

    We need to clarify who owns the provisioning process for this OCC to move forward. Thank you.

    Expand Post
    • Paul S. (Okta, Inc.)

      Hello @NicolasR.94674 (Customer)​  In this documentation it stated that your ISV (Palo Alto in your case) needs to create the tenant from their side:

      https://www.okta.com/integrate/documentation/embedded-okta-cloud-connect/

      "1. Administrator navigates to Okta Configuration UI in the ACME administrator console. Enters the necessary information for new Okta tenant creation and hits submit.

      2. ACME uses the input and calls the Okta tenant creation API (/orgs). A tenant is created. API call returns tenant-specific information including an API key for subsequent API access against this newly created Okta tenant."

       

      Additionally you can try our Sales department for more info: https://www.okta.com/contact-sales/

       

      Thank you for reaching out to our Community and have a great day!

      --

      Help others in the community by liking or hitting Select as Best if this response helped you.

      Expand Post

Recommended content

No recommended content found...