Okta + Microsoft Azure

Utilizing both Okta and Azure to create a secure, 100% cloud based infrastructure

Dark Rhiino had successfully implemented Okta in the client’s infrastructure back in 2020 as a new Okta deployment.

The client was looking for a simple, straightforward way to easily leverage identities in their Active Directory (AD) and enable their users to access Software as a Service (SaaS) applications with a single set of credentials; the bread-and-butter Okta use-case a few years ago.

You can see all the hallmarks of a classic Okta deployment pictured in the architecture diagram below, which we prepared for the client during implementation:

Figure 1.

As mentioned previously, this is probably the most common Okta use-case 5 years ago. Dark Rhiino was even able to leverage information from a Human Resources (HR) system, in this case BambooHR, to enrich user profile data and enable dynamic onboarding/updating/offboarding of employees thanks to this data.

Fast-forward to 2023, and the client was looking to modernize their infrastructure. Our old reliance on AD was no longer an option, as the client was looking to eliminate their on-premises IT fingerprint.

So, with the help of Dark Rhiino, we were able to re-tool their setup to a cloud-first deployment and did so with minimal interruption to the userbase.

Take a look at the overhauled architecture:

Figure 2.

So, what really occurred here? Why is the architecture so simplified?

Some backstory on their new approach – the client is now relying on Microsoft Azure as the cornerstone of their corporate identities. They wanted to consolidate management of everything; identity, device management, virtual machines, etc. all in one place for ease of administration. However, they loved working with Okta and relied heavily on the robust automations we had put in place over the years; thus, the decision was made to allow both systems to work in tandem with one another.

Now, Azure AD serves as our master directory and logs users into Okta seamlessly, facilitated by the connection of all devices to Intune. When a user encounters an Okta login prompt during their workday, once they enter their email address, Okta detects they’re an Azure user via Routing Rules and delegates the authentication piece to Azure. Since users are already signed into their device with corporate credentials, a session to Okta is established with almost no friction to the end-user.

We have more strict/unique authentication requirements based on which applications are being accessed in Okta, but this is the most-common login flow for their users.

Azure was configured as a Security Assertions Markup Language (SAML) Identity Provider in Okta’s eyes and because of this, we had a simple changeover when this new setup was implemented. Users had all their credentials synchronized to Office 365 prior to the project and once we turned off the old AD agents and enabled the Routing Rule, they were able to access using their existing credentials. No company-wide password reset was required.

I’ll take you through a few of the benefits of this new approach:

  1. Centralized management interface for almost all IT resources (Azure)
  2. Simplified approach
    • No reliance on legacy on-premises tech
    • Security is more straightforward – all security policies are done in Conditional Access in Azure, since that’s a user’s jumping-off point into all IT systems
    • Inherent ease of administration with fewer systems in place
  3. Cloud-only approach is more flexible & forward thinking for this client

For these reasons, we highly recommend following this client’s example and getting away from primarily on-premise setups. Hopefully, this goes to show that it’s not only possible with Okta, but simple; and, that Microsoft & Okta complement each other quite well in a deployment like we’re describing. Although Azure can do most of what Okta can, Okta is purpose-built to handle corporate identity and in Dark Rhiino’s opinion, is more capable than Microsoft Azure in fulfilling this role for any organization.