<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5WR00001ekgLF0AYOkta Classic EnginePrivileged AccessAnswered2026-05-18T22:19:24.000Z2026-05-15T15:56:02.000Z2026-05-18T22:19:24.000Z

ShabnamS.07614 (Customer) asked a question.

OPA integration with Workflows for Identity Security

I am building a scenario which integrates Okta Workflows with Okta Privileged Access for Identity security. The idea is-

  1. ITP detects High risk user
  2. Workflow gets invoked and global token revocation
  3. In OPA, the user is moved to High-Profile project and then access revoked to certain projects.
  4. Notify the Security Admins

 

Any help in building this scenario will be helpful.

 

I am also open to any other use-case.

 

Thanks


  • Mihai N. (Okta, Inc.)

    Hi @ShabnamS.07614 (Customer)​ , Thank you for reaching out to the Okta Community! 

     

    The scenario is interesting and looks plausible but its complexity would lead me to recommend discussing it with your Okta Account Executive for a possible Professional Services engagement to review your environment as well as the variables/requirements, or at least extensive testing in a preview environment.  

    While we can provide general guidance, a step-by-step guide is outside of Okta Community scope.  

    Assuming you have all the required features (ITP, OPA, Workflows & an app integration for notification like Slack, Teams, email server etc), you should be able to implement a trigger in Workflows based on Event Hooks and the Risk level detected. 

    From there have Workflows leverage the Okta Connector to clear the user session and move the user to a different group associated with your "High-Profile" project in OPA.  

    After that, implement a notification flows as discussed for example in this tutorial

     

    We'll leave this question open for additional insight/input from the community. I'm curious to find out if anyone implemented this or something similar and what difficulties they encountered(if any). 

     

    If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you. 

     

    Hope my answer helps! 

     

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Collect them all. Learn a new skill and earn a new Okta Learning badge.

    Just released: More Okta Community badges just added

    Expand Post
    Selected as Best
  • Mihai N. (Okta, Inc.)

    Hi @ShabnamS.07614 (Customer)​ , Thank you for reaching out to the Okta Community! 

     

    The scenario is interesting and looks plausible but its complexity would lead me to recommend discussing it with your Okta Account Executive for a possible Professional Services engagement to review your environment as well as the variables/requirements, or at least extensive testing in a preview environment.  

    While we can provide general guidance, a step-by-step guide is outside of Okta Community scope.  

    Assuming you have all the required features (ITP, OPA, Workflows & an app integration for notification like Slack, Teams, email server etc), you should be able to implement a trigger in Workflows based on Event Hooks and the Risk level detected. 

    From there have Workflows leverage the Okta Connector to clear the user session and move the user to a different group associated with your "High-Profile" project in OPA.  

    After that, implement a notification flows as discussed for example in this tutorial

     

    We'll leave this question open for additional insight/input from the community. I'm curious to find out if anyone implemented this or something similar and what difficulties they encountered(if any). 

     

    If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you. 

     

    Hope my answer helps! 

     

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Collect them all. Learn a new skill and earn a new Okta Learning badge.

    Just released: More Okta Community badges just added

    Expand Post
    Selected as Best

Loading
OPA integration with Workflows for Identity Security