How to connect Cyber Aware to Okta for SSO and SCIM provisioning

Connect Cyber Aware to Okta in 2026 for SAML single sign-on, SCIM auto-enrolment and leaver removal - a full admin setup guide for IT teams and MSPs.

How to connect Cyber Aware to Okta in 2026 for single sign-on, automatic training enrolment and leaver removal - a full admin setup guide for IT teams and MSPs that run Okta as their identity provider.

TL;DR

Why this matters

Manual enrolment fails the same way everywhere. A CSV import in January misses everyone hired in February, leavers keep seats they no longer use, and the gap surfaces only when an auditor asks who completed what. Directory sync removes the human step: Okta becomes the single source of truth, and the training list follows it.

SSO closes the other half of the adoption problem. When learners sign in to the training portal with the Okta credentials they already use, there is one fewer password to forget and one fewer reason to postpone the course sitting in their queue.

The sync is also what makes the reporting defensible. Human risk reporting ties overdue courses and phishing results to individual learners - a chain that only holds if the learner list matches reality from day one.

Who this is for

Internal IT teams running Okta as their identity provider, and MSPs managing Okta tenants for clients. If enrolment currently depends on someone remembering to run a CSV export, this connection removes the step entirely.

Before you start

Step 1 - Create the SAML app integration in Okta

  1. Sign in to the Okta admin console.
  2. Open Applications, then Applications, and select Create App Integration.
  3. Choose SAML 2.0 as the sign-in method and select Next.
  4. In General Settings, name the app Cyber Aware.
  5. In SAML Settings, paste the Single sign-on URL (the ACS URL) and the Audience URI (SP Entity ID) from the Cyber Aware connection screen. Set Name ID format to EmailAddress and Application username to Email.
  6. Add attribute statements if your Cyber Aware setup maps extra fields, and group attribute statements if you plan to scope enrolment by Okta group.
  7. Select Finish, then copy the app's metadata URL or IdP metadata from the Sign On tab.

Expected result: the app exists in Okta, unassigned, with its SAML configuration saved. If Cyber Aware publishes an app in the Okta Integration Network for your plan, you can use that listing instead of a custom app - the SAML and SCIM values come pre-filled and you skip to authorising them.

Step 2 - Enable SCIM provisioning on the same app

  1. On the app, open the General tab, edit SAML Settings, and set Provisioning to SCIM.
  2. Paste the SCIM connector base URL and the OAuth bearer token from the Cyber Aware connection screen.
  3. Select Test Connector Configuration - you want a success result against the tested endpoints.
  4. Open the To App tab and enable Create Users, Update User Attributes and Deactivate Users.

Expected result: the connector test passes and Okta is allowed to create, update and deactivate users in Cyber Aware.

Step 3 - Connect Cyber Aware to Okta

  1. Sign in to your Cyber Aware admin area and open the Auto Enrol sync settings.
  2. Choose Okta as the directory source and complete the connection using the SAML and SCIM details from steps 1 and 2.
  3. Run the first sync manually.

Expected result: the learner list populates from your Okta directory within minutes. Cyber Aware's directory sync supports multiple identity sources alongside CSV upload and signup links, so if a field label on screen does not match this guide, use its on-screen equivalent - the Okta-side provisioning test in step 2 is what actually gates everything.

Step 4 - Assign users and set arrival, cadence and leaver rules

  1. On the app's Assignments tab, assign your test user, then the Okta groups that should join the programme.
  2. Arrival: new hires picked up by the sync land in the default training schedule automatically, welcome email included.
  3. Departure: leavers are deactivated on the next sync, so ex-staff stop counting as active learners.
  4. Cadence: enable auto-add to place a new course in every learner's queue each month, with due and overdue reminders queued on schedule.
  5. Group-based assignment: use Okta groups to scope who joins - contractors, part-timers and executives do not always need the same schedule.
  6. Branding: portals, notification emails and certificates carry your brand rather than Cyber Aware's - confirm it before the first learner logs in.

Verify before you roll out

  1. Check the test user appears in the learner list after the first sync.
  2. Confirm the welcome email arrived.
  3. Deactivate the test user in Okta and sync again to confirm removal.
  4. Sign in to the learner portal as the test user to confirm SAML SSO works.
  5. Then extend assignment to the full set of Okta groups.

What the Okta connection carries

CapabilityWhat it doesWho benefits
SAML SSOLearners sign in with their Okta credentialsEveryone - one fewer password
SCIM provisioningNew hires enrol, leavers are deactivated, automaticallyAdmins - no spreadsheet
Group-based assignmentScope enrolment by Okta groupMixed workforces
Auto Enrol cadenceMonthly course plus reminders, on scheduleProgramme owners

Standardise on the sync wherever the client runs Okta, Microsoft 365 or Google Workspace; keep CSV for one-off migrations only.

Troubleshooting

What to do next

Enrolment is plumbing; the programme itself runs on security awareness training - story-driven courses, quizzes and branded certificates on a monthly cadence. Pair it with phishing simulations so every click becomes a coaching moment, and the reporting turns the whole thing into a defensible monthly read for you and your clients.

FAQ

Does Cyber Aware sync automatically from Okta? Yes. With SCIM provisioning enabled, new hires are created in Cyber Aware from Okta automatically and leavers are deactivated on the next sync, so the learner list always matches your directory.

Do I need SCIM if I only want single sign-on? No - SAML SSO works on its own. But without SCIM there is no automatic enrolment or leaver removal, so you are back to maintaining the learner list by hand.

What is SCIM provisioning? It is the standard protocol Okta uses to create, update and deactivate users in connected applications. It is what makes new hires appear in the training programme without anyone importing a list.

Can we scope enrolment to part of the company? Yes. Assign the app to specific Okta groups, and only members of those groups enter the programme - useful for contractors, part-timers and departments with different schedules.

What happens when an employee leaves? They are deactivated on the next sync, so ex-staff stop appearing as active learners in your reports.

Do I need the Okta Integration Network listing or a custom app? Either works. If Cyber Aware publishes an app in the Okta Integration Network for your plan, the SAML and SCIM values arrive pre-filled; otherwise build a custom SAML app and enable SCIM on it, as this guide describes.

One last thing

Grant and test from an admin account you can name. A provisioning token pasted from a shared password vault is exactly the credential nobody can rotate confidently when a security review asks who has write access to your training data.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.