Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Automate Identity Threat Response with Okta ITP

Okta
07/09/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


In this video, we are going to remediate a critical identity threat by processing a real-time signal from Okta Identity Threat Protection, i.e. ITP, using an event hook. Firstly, we will build the remediation logic in Okta workflows using an API endpoint to define the automated response when the user's status is high risk. Then we will configure an event hook to link the threat detection to the workflow, ensuring the remediation is invoked automatically to restore a secure state. Post that, we will test this flow. Let's get started. We will create a new flow. You can assign any name to the flow and save all the data that passes through the flow. We begin by adding the API endpoint card as a trigger. This card acts as a webhook listener that receives the incoming data payload from Okta. We will be using the invoke URL later on while creating the event hook. And to set the security level, I am choosing here Secure with Client Token. Next step is to add the object getCard so that we can isolate the specific user from the payload. Drag the body from API endpoint to object getCard and in the path field, enter data.events.0.target.0.id Next, add the date and time card to the flow. The moment workflow reaches this step, it automatically generates a timestamp, which we can use to create an accurate log. Next we will add Okta clear user sessions card. The objective is when the user status risk is high, we want to clear their session. So we need Okta clear user session card. Map the output of object getCard as an id on clear user sessions card and set the revoke OAuth tokens to true. When this card gets executed, this terminates every active web session the user has open in Okta and revokes their access token. Next we want to add the tables createRowCard. It will ask us to choose a table. Since we have not created any table, right in the current folder, we will click on new table. It will create a new table for us, I'm naming it as ITP table and save. I want to record the user ID as well as the date, that is timestamp. Once the table is created, you can go to choose table, go to the respective folder and select the table. You can map the ID and the date. Now the flow is created. The next step is to create the event hook in the admin console. Make sure you save this flow. To create the event hook in Okta admin console, navigate to workflow and select event hooks. You will notice that there is an event hook already created, but its status is inactive. In order to create a new event hook, click create event hook. You can provide any name. You can grab the URL from the API endpoint card. From the workflow, there is a card API endpoint. Click on endpoint settings and you can copy the invoke URL. Once you copy the invoke URL, you can go back to the add event hook endpoint and paste that URL here. The next task is to subscribe to the events. We are selecting here indicates the user risk was detected and indicates a user risk level has changed. Once you have subscribed to these events, save and continue. You will notice that ITP test and event hook has been created and its status is active. To test whether our workflow and event hooks are connected, whether they are working fine or not, we are going to manually increase the risk level of a user so that it fires an event hook. And then we will check the Okta workflows execution history, whether the workflow has executed or not. Go to the user, go to more actions and elevate their entity risk level to elevate their entity risk level. It should trigger the workflow. Make sure that the workflow is activated. Once the user risk level is elevated successfully, the workflow should have triggered automatically. Go to the execution history of the workflow. You will notice that it has returned the status success. You can verify whether it has cleared the session of the same user or not by matching the user ID of clear user sessions with the user ID mentioned on the admin console. You will notice that it should create a row in the table which we have associated with this workflow. To check the table, you can go to the folder and there is one table. You will notice that it has created a user ID and the corresponding date. So we have successfully built a workflow and associated it with Okta Identity Threat Protection. Thank you.

TL;DR

  • Okta Workflows can be configured with an API endpoint trigger to automatically clear user sessions and revoke OAuth tokens the moment Okta ITP flags a high-risk user.
  • An event hook connects Okta Identity Threat Protection signals — specifically risk detected and risk level changed events — directly to the remediation workflow without manual intervention.
  • A built-in table card logs the affected user ID and timestamp at execution time, creating an audit trail for every automated remediation action taken.

Summary

This tutorial from Okta demonstrates how to build an automated identity threat remediation workflow using Okta Identity Threat Protection (ITP) and Okta Workflows. Presented by Shabnam Sharma, the walkthrough covers three core steps: constructing the remediation logic in Okta Workflows via an API endpoint trigger, configuring an event hook to link ITP threat detection signals to that workflow, and validating the end-to-end automation through a live test. The workflow is designed to respond automatically when a user's risk status is flagged as high — immediately clearing all active web sessions and revoking OAuth tokens to eliminate unauthorized access. An object get card isolates the at-risk user from the incoming payload, a date-time card generates an audit timestamp, and a table row card logs the user ID and event time for compliance tracking. The event hook subscribes to two specific ITP events — risk detected and risk level changed — ensuring the remediation fires without manual intervention. The demo concludes with a successful end-to-end test, confirming that elevating a user's entity risk level automatically triggers session termination and creates a corresponding audit log entry. This pattern is directly applicable to security operations teams looking to reduce mean time to respond to identity-based threats.

Chapters

0:00 - Introduction & Overview
0:40 - Building the Workflow
2:03 - Session Clearance & Logging
3:41 - Configuring the Event Hook
5:09 - End-to-End Testing

Key Quotes

0:03 "We are going to remediate a critical identity threat by processing a real-time signal from Okta Identity Threat Protection, i.e. ITP, using an event hook."
2:07 "The objective is when the user status risk is high, we want to clear their session."
2:34 "When this card gets executed, this terminates every active web session the user has open in Okta and revokes their access token."
6:39 "So we have successfully built a workflow and associated it with Okta Identity Threat Protection."

FAQ

What triggers the Okta Workflows remediation flow in this setup?

An event hook configured in the Okta admin console triggers the workflow. It subscribes to two ITP events — 'indicates the user risk was detected' and 'indicates a user risk level has changed' — and fires the workflow automatically when either event occurs.

What actions does the workflow take when a high-risk user is detected?

The workflow clears all active web sessions for the identified user and revokes their OAuth tokens, effectively terminating access across every open session. It also logs the user ID and a timestamp to an ITP audit table for record-keeping.


Categories:
  • » Cybersecurity » Zero Trust
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Identity & Access
  • Security Operations
  • Zero Trust
  • How-To
  • Demo
  • Technical Deep Dive
  • Identity Threat Protection
  • Okta Workflows
  • Event Hooks
  • Session Management
  • Automated Remediation
  • OAuth Token Revocation
  • Risk-Based Access Control
  • Security Automation
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Automate Identity Threat Response with Okta ITP

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                      https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      11:00 AM
                      10/27/2026
                      Maximize Security, Value, and Returns on Your Microsoft Investment
                      https://www.truthinit.com/index.php/channel/2178/maximize-security-value-and-returns-on-your-microsoft-investment/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model in an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-in-an-ai-driven-landscape/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                      https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                    • 11/05/2026
                      02:00 PM
                      11/05/2026
                      HUMAN Dialogue: Embracing the Rise of the Agentic Consumer in AI
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-embracing-the-rise-of-the-agentic-consumer-in-ai/
                    • 11/05/2026
                      02:00 PM
                      11/05/2026
                      Reclaim Your Evenings: Leverage Data Intelligence to Minimize Risk and Boost AI Adoption
                      https://www.truthinit.com/index.php/channel/2172/reclaim-your-evenings-leverage-data-intelligence-to-minimize-risk-and-boost-ai-adoption/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version