Montro

Okta Identity Governance & Compliance

Okta controls who gets into everything else. Without it in your governed inventory, your compliance picture has a gap at the foundation. Montro connects Okta identity data to your full application estate.

01GDPR

GDPR

Okta and GDPR - identity data is personal data

Okta processes personal data on your behalf - user identities, email addresses, authentication events, and access records. Under GDPR, your organisation is the data controller and Okta acts as a processor. A Data Processing Agreement must be in place. Connecting Okta to Montro brings identity data into Montro EU-hosted infrastructure under a separate DPA, with all data remaining within the EU.

Learn more →
02EU AI Act

EU AI Act

Okta and the EU AI Act - AI-driven identity risk in scope

Okta uses AI-driven threat detection and identity risk scoring to flag suspicious authentication events. If your organisation has these features enabled, they qualify as AI systems under the EU AI Act and deployer obligations apply. Montro surfaces Okta in your governed inventory, ensuring AI-powered identity features are documented and assessed alongside your broader EU AI Act compliance programme.

Learn more →
03DORA

DORA

Okta and DORA - identity tools belong in your ICT register

Under DORA, every ICT tool supporting your operations must be registered and assessed. Okta, as your identity provider, is a critical ICT service - one that controls access to every other application in your stack. Connecting Okta to Montro supports ICT Third-Party Register completeness under Article 28.3 and gives you the visibility needed to meet DORA third-party risk obligations.

Learn more →
04NIS2

NIS2

Okta and NIS2 - identity infrastructure is critical supply chain

Okta is identity infrastructure. Under NIS2 Article 21(3)(d), organisations must document and assess the security of direct ICT suppliers. Okta sits at the gateway of your application estate - it controls who accesses what. Montro connects identity data with application discovery, making Okta visible in your supply chain security posture and supporting Article 21(2)(i) access control obligations.

Learn more →
05ISO 27001

ISO 27001

Okta and ISO 27001 - evidence your access controls

ISO 27001 Annex A requires documented access control policies, user provisioning processes, and regular access reviews (A.5.15, A.5.16, A.8.2, A.8.3). Okta data in Montro gives auditors a consolidated, timestamped view of user identities, application assignments, and access relationships - supporting the evidence requirements that ISO 27001 audits demand.

Learn more →

Discovery

What Montro discovers from Okta

When you connect Okta to Montro, identity and access data flows directly into your governed application inventory. IT and security teams gain a consolidated view of users authenticated through Okta, their application assignments, roles, and access relationships - mapped against your EU compliance and regulatory obligations.

Identity visibility

See every user authenticated through Okta - including their application assignments, roles, and access relationships across your governed application estate. Montro combines Okta identity data with its own application discovery to give you a complete picture of who has access to what, and whether that access is governed.

Access governance

Track application assignments and authentication relationships to identify access sprawl and users with access to applications they no longer need. Montro surfaces orphaned accounts, over-provisioned roles, and access patterns that fall outside your expected governance boundaries.

Security intelligence

Understand who has access to which critical applications and maintain a current, governed view of your organisation's access landscape. When auditors or regulators ask for evidence of access controls, Montro gives you a consolidated, timestamped record rather than a manual reconciliation exercise.

Single governed view

Okta identity data sits alongside every SaaS and AI tool Montro has discovered - connecting identity intelligence with EU compliance obligations in one place. Map access relationships to NIS2 supply chain obligations, DORA ICT register requirements, and ISO 27001 access control evidence from a single platform.

Technical details

Authentication Method


Okta authenticates via an Organisation URL and API Token. Administrators provide their Okta Organisation URL and generate an API Token from their Okta admin console to authorise Montro's read-only access. 


How to connect:


  1. Navigate to Integrations in your Montro dashboard.
  2. Select Okta from the integrations catalogue and click Connect.
  3. Enter your Okta Organisation URL.
  4. Provide your Okta API Token.
  5. Click Connect to authorise the integration and start synchronisation.
  6. Montro imports users, applications, roles, and access-related information from Okta.
  7. Review imported data across the Users and Licence Management modules in Montro.

 

Data Synced

Users Module

Okta user identities, including email addresses, authentication status, and profile information.

Applications

Application assignments and access relationships between users and tools managed through Okta.

Roles & Access

Role assignments and access-related information to support governance and audit workflows.

Data Residency


Okta data imported into Montro is stored on AWS Frankfurt (eu-central-1), within the European Union. No customer data is transferred outside the EU. Data residency terms are specified in Montro's Data Processing Agreement.


Permission Scope


Montro uses read-only API access to Okta. The integration retrieves user identities, application assignments, roles, and access-related information only. Montro does not write to, modify, or delete any data within your Okta environment. All access is limited to the minimum required for AI and SaaS governance visibility.


EU Data Storage


Montro's infrastructure runs exclusively on AWS eu-central-1 (Frankfurt), governed by Irish and EU law. There is no FISA 702 exposure and no Schrems II ambiguity. Your data is never replicated outside the EU without your explicit, documented consent. EU data residency is not a configuration option - it is the architecture.

Related

Apps commonly used with Okta

Discover compliance profiles for tools in your stack.

Project & Knowledge Management

Jira External User Discovery & Governance

Jira accounts are where contractors, agencies, and external collaborators often live - outside your identity provider, outside your offboarding process, and outside your compliance picture. Connect Jira to Montro to bring them in.

Learn more →

OpenAI Governance & Compliance Discovery

Most organisations using OpenAI have no visibility into who holds access, how many seats are active, or whether usage is documented against EU AI Act obligations. Montro surfaces all of it.

Learn more →

Slack Workspace Access & AI Governance

Slack is where work happens, and where ungoverned access accumulates. Guest accounts, inactive seats, and users added outside your identity provider all show up when Montro connects to your workspace.

Learn more →

Collaboration & Messaging

Zoom Governance & Compliance Discovery

Zoom accounts grow quietly - provisioned outside your identity provider, renewed without IT review, and rarely audited. Montro discovers every user and licence in your Zoom environment and maps it against your EU compliance obligations.

Learn more →
Ankur Arora

Ankur Arora

Co-founder

Fifteen years of enterprise digital transformation across telecoms, media, consumer goods, and agriculture - and a front-row seat to AI adoption outpacing governance at every organisation he worked in. He built Montro so the next firm doesn't have to learn that lesson the hard way.