This document describes how to provision user groups from OKTA to Cisco Secure Access.
Cisco recommends that you have knowledge of these topics:
This document is not restricted to specific software and hardware versions.
The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared (default) configuration. If your network is live, ensure that you understand the potential impact of any command.
Cisco Secure Access supports the provisioning of users and groups from OKTA.
This provisioning enables Secure Access to maintain a directory of users authorized to:
Note: This document focuses specifically on the provisioning of users and groups from OKTA. The configuration of Entra ID or other Identity Providers (IdP) for ZTA enrollment, VPNaaS authentication, or specific Umbrella Roaming settings is outside the scope of this guide.
In order to begin the provisioning process, you must first configure the directory integration within the Cisco Secure Access dashboard. This step generates the necessary credentials and configuration parameters required to establish a secure connection with OKTA.
Sign in to the Cisco Secure Access Dashboard.
Sign in to CSA
Navigate to Connect > Users, Groups and Endpoint Devices.
Users and Groups
Click Configuration management.
Configuration Management
Integrate Directory
Directory Configuration
Click Generate Token. Save the generated token and the provisioning URL, then click Done.
Generate Token
Once you have generated your credentials in the Cisco Secure Access dashboard, you must configure the provisioning settings within your OKTA tenant to enable the synchronization of users and groups.

Browse App Catalog
Cisco App
Add Integration
Add App
Configure API Integration
API Test
Provision to App
Note: Verify that you select these attributes for synchronization to Secure Access. Secure Access only lists the Display name and Username attributes for users, not the Given name and Family name attributes: Username, Given name, Family, name, Display name, Email
(Optional) Add an objectGUID Attribute and Create the User Profile Mapping. If you need to import the objectGUID attribute for users, add a new attribute and map the attributes in the profile mapping.
Assignment
Assign Groups
Users and Groups in CSA
Verify Users in CSA
OKTA LogsProvision Users and Groups from Okta
| Revision | Publish Date | Comments |
|---|---|---|
1.0 |
11-May-2026
|
Initial Release |