Before beginning the Data Protection setup for Okta, ensure you have the necessary privileges and are aware of the required application access scopes.
Required Administrative Privileges
You will need these administrative privileges to complete the configuration across both consoles:
Role | Console | Purpose |
Okta Super Admin | Okta Admin Console | Required to grant administrative API scopes and authorize the OAuth connection. |
Druva Cloud Admin | Druva Console | Required to enable the Okta integration and manage global app settings. |
Product Admin | Druva Console | Sufficient for day-to-day monitoring once the initial connection is established. |
Understanding Required Permissions
The Druva application requires specific API scopes to perform essential backup and recovery operations within your Okta tenant. Understanding these permissions is essential for security and compliance teams.
Permission Scope | What it Does |
.manage | Allows the application to create, read, or update identity data (e.g., restoring a deleted Group or updating a User attribute). |
.read | Allows the application to read all identity data necessary for comprehensive backups and discovery from Okta. |
You can find the complete, detailed list of scopes required to grant access in the Permission Required documentation.
Set up the Druva App in Okta
Start by logging in your Okta Admin Console.
Once you are there, navigate to Applications > API Service Integrations.
Then, click Add Integration to begin the process.
4. In the list of available integrations, search for and select Druva Data Security Cloud. Click Next to proceed. The following screen displays the integration details and the list of permission scopes being requested. You should review these details carefully, and then click Install & Authorize.
5. A modal displaying your Client Secret appears.
6. Click Copy to Clipboard and save this secret in a secure location.
βImportant: This secret is required to link your Okta instance within the Druva Console and will not be shown again.
7. After you have safely saved the secret, click Done to close the modal.
