How to connect Cyber Aware to Okta in 2026 for single sign-on, automatic training enrolment and leaver removal - a full admin setup guide for IT teams and MSPs that run Okta as their identity provider.
TL;DR
- Cyber Aware connects to Okta with SAML single sign-on plus SCIM provisioning.
- SCIM provisioning auto-enrols new hires in training and removes leavers on the next sync.
- The Okta side is one app integration: SAML for sign-in, SCIM enabled on the same app.
- Verify with one test user - enrolment, welcome email, removal - before assigning the app company-wide.
Why this matters
Manual enrolment fails the same way everywhere. A CSV import in January misses everyone hired in February, leavers keep seats they no longer use, and the gap surfaces only when an auditor asks who completed what. Directory sync removes the human step: Okta becomes the single source of truth, and the training list follows it.
SSO closes the other half of the adoption problem. When learners sign in to the training portal with the Okta credentials they already use, there is one fewer password to forget and one fewer reason to postpone the course sitting in their queue.
The sync is also what makes the reporting defensible. Human risk reporting ties overdue courses and phishing results to individual learners - a chain that only holds if the learner list matches reality from day one.
Who this is for
Internal IT teams running Okta as their identity provider, and MSPs managing Okta tenants for clients. If enrolment currently depends on someone remembering to run a CSV export, this connection removes the step entirely.
Before you start
- Okta admin access. Creating app integrations and enabling provisioning requires an Okta administrator role - Super Administrator, or Application Administrator with the right scope. A plain user account cannot complete this guide.
- A Cyber Aware partner account with Auto Enrol available on the plan, and access to the SSO and directory-sync settings.
- A test user in Okta, so you can verify enrolment, the welcome email and removal end to end.
- The gotcha: SAML and SCIM live on the same app integration. If your team creates one app for sign-in and a separate one for provisioning, the sync will half-work - users enrol but never deactivate, or sign-in breaks while provisioning looks fine. Build one app and enable both.
Step 1 - Create the SAML app integration in Okta
- Sign in to the Okta admin console.
- Open Applications, then Applications, and select Create App Integration.
- Choose SAML 2.0 as the sign-in method and select Next.
- In General Settings, name the app Cyber Aware.
- In SAML Settings, paste the Single sign-on URL (the ACS URL) and the Audience URI (SP Entity ID) from the Cyber Aware connection screen. Set Name ID format to EmailAddress and Application username to Email.
- Add attribute statements if your Cyber Aware setup maps extra fields, and group attribute statements if you plan to scope enrolment by Okta group.
- Select Finish, then copy the app's metadata URL or IdP metadata from the Sign On tab.
Expected result: the app exists in Okta, unassigned, with its SAML configuration saved. If Cyber Aware publishes an app in the Okta Integration Network for your plan, you can use that listing instead of a custom app - the SAML and SCIM values come pre-filled and you skip to authorising them.
Step 2 - Enable SCIM provisioning on the same app
- On the app, open the General tab, edit SAML Settings, and set Provisioning to SCIM.
- Paste the SCIM connector base URL and the OAuth bearer token from the Cyber Aware connection screen.
- Select Test Connector Configuration - you want a success result against the tested endpoints.
- Open the To App tab and enable Create Users, Update User Attributes and Deactivate Users.
Expected result: the connector test passes and Okta is allowed to create, update and deactivate users in Cyber Aware.
Step 3 - Connect Cyber Aware to Okta
- Sign in to your Cyber Aware admin area and open the Auto Enrol sync settings.
- Choose Okta as the directory source and complete the connection using the SAML and SCIM details from steps 1 and 2.
- Run the first sync manually.
Expected result: the learner list populates from your Okta directory within minutes. Cyber Aware's directory sync supports multiple identity sources alongside CSV upload and signup links, so if a field label on screen does not match this guide, use its on-screen equivalent - the Okta-side provisioning test in step 2 is what actually gates everything.
Step 4 - Assign users and set arrival, cadence and leaver rules
- On the app's Assignments tab, assign your test user, then the Okta groups that should join the programme.
- Arrival: new hires picked up by the sync land in the default training schedule automatically, welcome email included.
- Departure: leavers are deactivated on the next sync, so ex-staff stop counting as active learners.
- Cadence: enable auto-add to place a new course in every learner's queue each month, with due and overdue reminders queued on schedule.
- Group-based assignment: use Okta groups to scope who joins - contractors, part-timers and executives do not always need the same schedule.
- Branding: portals, notification emails and certificates carry your brand rather than Cyber Aware's - confirm it before the first learner logs in.
Verify before you roll out
- Check the test user appears in the learner list after the first sync.
- Confirm the welcome email arrived.
- Deactivate the test user in Okta and sync again to confirm removal.
- Sign in to the learner portal as the test user to confirm SAML SSO works.
- Then extend assignment to the full set of Okta groups.
What the Okta connection carries
| Capability | What it does | Who benefits |
|---|---|---|
| SAML SSO | Learners sign in with their Okta credentials | Everyone - one fewer password |
| SCIM provisioning | New hires enrol, leavers are deactivated, automatically | Admins - no spreadsheet |
| Group-based assignment | Scope enrolment by Okta group | Mixed workforces |
| Auto Enrol cadence | Monthly course plus reminders, on schedule | Programme owners |
Standardise on the sync wherever the client runs Okta, Microsoft 365 or Google Workspace; keep CSV for one-off migrations only.
Troubleshooting
- The connector test fails. Re-check the base URL and bearer token - a trailing slash or a revoked token is the usual cause, and the test error names the endpoint that failed.
- Users enrol but never deactivate. Deactivate Users was not enabled on the app's To App tab. Enable it and sync again.
- Learners cannot sign in with SSO. Compare the ACS URL and Audience URI in Okta against the Cyber Aware connection screen character for character, and confirm the user is actually assigned to the app.
- Some users are missing. Check they sit inside the assigned Okta groups, that their Okta profile is active, and that their email attribute is populated.
- Duplicate learners. A stale CSV import plus the live sync list the same person twice. Make Okta the single source of truth and remove imported duplicates.
What to do next
Enrolment is plumbing; the programme itself runs on security awareness training - story-driven courses, quizzes and branded certificates on a monthly cadence. Pair it with phishing simulations so every click becomes a coaching moment, and the reporting turns the whole thing into a defensible monthly read for you and your clients.
FAQ
Does Cyber Aware sync automatically from Okta? Yes. With SCIM provisioning enabled, new hires are created in Cyber Aware from Okta automatically and leavers are deactivated on the next sync, so the learner list always matches your directory.
Do I need SCIM if I only want single sign-on? No - SAML SSO works on its own. But without SCIM there is no automatic enrolment or leaver removal, so you are back to maintaining the learner list by hand.
What is SCIM provisioning? It is the standard protocol Okta uses to create, update and deactivate users in connected applications. It is what makes new hires appear in the training programme without anyone importing a list.
Can we scope enrolment to part of the company? Yes. Assign the app to specific Okta groups, and only members of those groups enter the programme - useful for contractors, part-timers and departments with different schedules.
What happens when an employee leaves? They are deactivated on the next sync, so ex-staff stop appearing as active learners in your reports.
Do I need the Okta Integration Network listing or a custom app? Either works. If Cyber Aware publishes an app in the Okta Integration Network for your plan, the SAML and SCIM values arrive pre-filled; otherwise build a custom SAML app and enable SCIM on it, as this guide describes.
One last thing
Grant and test from an admin account you can name. A provisioning token pasted from a shared password vault is exactly the credential nobody can rotate confidently when a security review asks who has write access to your training data.