<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Access &#8211; JMartinez.tech</title>
	<atom:link href="https://jmartinez.tech/tag/access/feed/" rel="self" type="application/rss+xml" />
	<link>https://jmartinez.tech</link>
	<description>Tech stuff, but chill.</description>
	<lastBuildDate>Thu, 12 Jun 2025 17:50:10 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://jmartinez.tech/wp-content/uploads/2025/04/T027K0ZC9-U03JL4E79KM-bbe3a34946fe-512-150x150.png</url>
	<title>Access &#8211; JMartinez.tech</title>
	<link>https://jmartinez.tech</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Before You Use Okta, Do This: An Essential Guide for Admins</title>
		<link>https://jmartinez.tech/before-you-use-okta-do-this-an-essential-guide-for-admins/</link>
					<comments>https://jmartinez.tech/before-you-use-okta-do-this-an-essential-guide-for-admins/#comments</comments>
		
		<dc:creator><![CDATA[Jordi Martinez-Hidalgo]]></dc:creator>
		<pubDate>Thu, 12 Jun 2025 17:50:10 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Access]]></category>
		<category><![CDATA[amateur]]></category>
		<category><![CDATA[groups]]></category>
		<category><![CDATA[guide]]></category>
		<category><![CDATA[okta]]></category>
		<category><![CDATA[policies]]></category>
		<category><![CDATA[profile]]></category>
		<category><![CDATA[roles]]></category>
		<category><![CDATA[source]]></category>
		<category><![CDATA[SSO]]></category>
		<category><![CDATA[steps]]></category>
		<guid isPermaLink="false">https://jmartinez.tech/?p=337</guid>

					<description><![CDATA[You&#8217;ve just acquired Okta and have no idea where to start. You&#8217;re ready to roll up your sleeves and start integrating applications, but wait! Your tenant is empty. If you don’t lay down solid foundations, you might regret it later. Here’s what I would do if I had to start ... <div><a class="more-link bs-book_btn" href="https://jmartinez.tech/before-you-use-okta-do-this-an-essential-guide-for-admins/">Read More</a></div>]]></description>
										<content:encoded><![CDATA[
<div class="posts-view">



<p style="font-size:16px">You&#8217;ve just acquired Okta and have no idea where to start.</p>



<p style="font-size:16px">You&#8217;re ready to roll up your sleeves and start integrating applications, but wait! Your tenant is empty. If you don’t lay down solid foundations, you might regret it later.</p>



<p style="font-size:16px">Here’s what I would do if I had to start from scratch today:</p>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>



<p style="font-size:24px"><strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f9d1-200d-1f9d1-200d-1f9d2-200d-1f9d2.png" alt="🧑‍🧑‍🧒‍🧒" class="wp-smiley" style="height: 1em; max-height: 1em;" /><strong>Make Sure You Have a Profile Source</strong></strong></p>



<p style="font-size:16px">Okta is a powerful tool, but it’s useless without users.</p>



<p style="font-size:16px">There are many ways to create users in Okta, but in my opinion, the most powerful one is connecting a <strong>Profile Source</strong>.</p>



<p style="font-size:16px">There are tons of available options: <strong>Workday</strong>, <strong>BambooHR</strong>, <strong>Active Directory</strong>, <strong>LDAP</strong>, <strong>UKG</strong>, and more.</p>



<p style="font-size:16px">Connecting a source of truth from your HR systems allows you to sync valuable information automatically. This data can be leveraged later for workflows, group assignments, and more.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p style="font-size:16px"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f9e0.png" alt="🧠" class="wp-smiley" style="height: 1em; max-height: 1em;" /><strong>Tip for smaller companies</strong>: You can also use <em>Okta Direct Input</em>. While it’s not ideal and I wouldn’t recommend it, it can work if you don’t have other options — but treat it as a last resort.</p>
</blockquote>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>



<p style="font-size:24px"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4cd.png" alt="📍" class="wp-smiley" style="height: 1em; max-height: 1em;" /><strong><strong><strong>Map Every Attribute You Can</strong></strong></strong></p>



<p style="font-size:16px">Once your source is connected, it’s time to take full advantage of the incoming data.</p>



<p style="font-size:16px">Map <strong>every attribute you can</strong>, even if some seem irrelevant now. Trust me, you never know when you’ll need them.</p>



<p style="font-size:16px">Start with the essentials:</p>



<ul class="wp-block-list">
<li style="font-size:16px"><code>team</code></li>



<li style="font-size:16px"><code>department</code></li>



<li style="font-size:16px"><code>location</code></li>



<li style="font-size:16px"><code>division</code></li>



<li style="font-size:16px"><code>manager</code></li>



<li style="font-size:16px"><code>office</code></li>
</ul>



<p style="font-size:16px">The more metadata you collect, the more powerful your automations and policies will be.</p>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>



<p style="font-size:24px"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f3d8.png" alt="🏘" class="wp-smiley" style="height: 1em; max-height: 1em;" /><strong><strong><strong>Create Dynamic Groups</strong></strong></strong></p>



<p style="font-size:16px">Now that you have user data, it’s time to put it to use.</p>



<p style="font-size:16px"><strong>Dynamic groups</strong> let you assign users automatically based on attribute-based rules. For example:</p>



<ul class="wp-block-list">
<li style="font-size:16px"><code>HR Department</code></li>



<li style="font-size:16px"><code>Finance Team</code></li>



<li style="font-size:16px"><code>Barcelona Office</code></li>



<li style="font-size:16px"><code>US Employees</code></li>



<li style="font-size:16px"><code>IT Support</code></li>
</ul>



<p style="font-size:16px">You don’t need to manually manage membership. Any changes in your source of truth will be reflected in Okta, and users will move in and out of groups automatically based on the defined logic.</p>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>



<p style="font-size:24px"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f46e-1f3fb.png" alt="👮🏻" class="wp-smiley" style="height: 1em; max-height: 1em;" /><strong>Define Access Roles</strong></p>



<p style="font-size:16px">You won’t be the only one managing Okta.</p>



<p style="font-size:16px">Set up access roles based on each person’s responsibilities:</p>



<ul class="wp-block-list">
<li style="font-size:16px"><strong>Read-only Admin</strong></li>



<li style="font-size:16px"><strong>Group Membership Admin</strong></li>



<li style="font-size:16px"><strong>Application Admin</strong></li>



<li style="font-size:16px"><strong>Super Admin</strong> (only if absolutely necessary)</li>
</ul>



<p style="font-size:16px">This step takes a bit of time, but it&#8217;s worth it. Delegating access properly reduces risk and improves operational efficiency.</p>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>



<p style="font-size:24px"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6aa.png" alt="🚪" class="wp-smiley" style="height: 1em; max-height: 1em;" /><strong>Define Authentication Policies</strong></p>



<p style="font-size:16px">Security should always be a top priority.</p>



<p style="font-size:16px">Set up <strong>authentication policies</strong> tailored to your applications. Not all apps are created equal, accessing <strong>Salesforce</strong> is not the same as accessing <strong>Udemy</strong>.</p>



<p style="font-size:16px">I recommend:</p>



<ul class="wp-block-list">
<li style="font-size:16px">Enforcing <strong>2FA</strong></li>



<li style="font-size:16px">Applying <strong>IP restrictions</strong></li>



<li style="font-size:16px">Restricting access by <strong>device</strong> (if capable)</li>
</ul>



<p style="font-size:16px">Be <strong>strict</strong>, especially with critical systems. Better safe than sorry.</p>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>



<p style="font-size:24px"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4d7.png" alt="📗" class="wp-smiley" style="height: 1em; max-height: 1em;" /><strong>In Summary</strong></p>



<p style="font-size:16px">These five steps will help you build a strong, reliable tenant, ready for growth, app integration, and secure daily operations.</p>



<p style="font-size:16px">As for app integration… we’ll save that for another post. <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>



</div>



<p></p>
]]></content:encoded>
					
					<wfw:commentRss>https://jmartinez.tech/before-you-use-okta-do-this-an-essential-guide-for-admins/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
		<item>
		<title>Implementing Zero Trust with Okta: Mistakes I Made and What I&#8217;d Do Differently</title>
		<link>https://jmartinez.tech/implementing-zero-trust-with-okta-mistakes-i-made-and-what-id-do-differently/</link>
					<comments>https://jmartinez.tech/implementing-zero-trust-with-okta-mistakes-i-made-and-what-id-do-differently/#comments</comments>
		
		<dc:creator><![CDATA[Jordi Martinez-Hidalgo]]></dc:creator>
		<pubDate>Sat, 24 May 2025 19:41:51 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Access]]></category>
		<category><![CDATA[Identity]]></category>
		<category><![CDATA[okta]]></category>
		<category><![CDATA[SSO]]></category>
		<category><![CDATA[ZeroTrust]]></category>
		<guid isPermaLink="false">https://jmartinez.tech/?p=315</guid>

					<description><![CDATA[Let’s be honest — you really can’t trust anything on the network anymore. With remote work and everything moving to SaaS, we just can’t assume anything is safe &#8211; and to be fair, many times, we are the biggest threats to our systems. That’s when the world started turning to ... <div><a class="more-link bs-book_btn" href="https://jmartinez.tech/implementing-zero-trust-with-okta-mistakes-i-made-and-what-id-do-differently/">Read More</a></div>]]></description>
										<content:encoded><![CDATA[
<div class="posts-view">



<p style="font-size:16px">Let’s be honest — you really can’t trust anything on the network anymore.</p>



<p style="font-size:16px">With remote work and everything moving to SaaS, we just can’t assume anything is safe &#8211; and to be fair, many times, <strong>we are the biggest threats</strong> to our systems.</p>



<p style="font-size:16px">That’s when the world started turning to <strong>Zero Trust</strong>.<br>You’ve probably heard the phrase:</p>



<p style="font-size:16px">&#8220;<em>Never trust, always verify.&#8221;</em></p>



<p style="font-size:16px">Sounds great, right? But actually implementing it isn’t easy &#8211; and can be a real pain in the neck.</p>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>



<p style="font-size:24px"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2753.png" alt="❓" class="wp-smiley" style="height: 1em; max-height: 1em;" /><strong>So, what is Zero Trust really?</strong></p>



<p style="font-size:16px">It’s not a piece of software or a configuration setting. It’s more of a <strong>mindset</strong> &#8211; a different way of thinking about access and security. Something like:</p>



<ul class="wp-block-list">
<li style="font-size:16px"><strong>Identity is everything.</strong> Doesn’t matter where you are &#8211; it matters <em>who</em> you are.</li>



<li style="font-size:16px"><strong>Access is earned, not assumed.</strong> Being &#8220;inside&#8221; doesn’t mean you’re in.</li>



<li style="font-size:16px"><strong>You only get what you need.</strong> No more blanket admin rights.</li>



<li style="font-size:16px"><strong>Logs are your best friend.</strong> Because if you’re not watching… someone else might be.</li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>



<p style="font-size:24px"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f9f0.png" alt="🧰" class="wp-smiley" style="height: 1em; max-height: 1em;" /><strong>What tools did we use?</strong></p>



<p style="font-size:16px">Here’s the stack we work with (and personally, it works pretty well for us so far):</p>



<ul class="wp-block-list">
<li style="font-size:16px"><strong>Okta</strong> for SSO, MFA, and everything related to identity</li>



<li style="font-size:16px"><strong>Google Workspace</strong> for team productivity and collaboration</li>



<li style="font-size:16px"><strong>Jamf + Intune</strong> to manage all our devices</li>



<li style="font-size:16px"><strong>Slack and Zoom</strong> for everything communication-related</li>



<li style="font-size:16px"><strong>Confluence</strong> to share knowledge and keep everyone in the loop</li>
</ul>



<p style="font-size:16px">All these tools are great &#8211; but the real challenge is <strong>knowing how to use them properly</strong>, and that, my friends, is not as easy as it sounds.</p>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>



<p style="font-size:24px"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6ab.png" alt="🚫" class="wp-smiley" style="height: 1em; max-height: 1em;" /><strong>Mistakes we’ve made (okay… mostly me)</strong></p>



<ol class="wp-block-list">
<li style="font-size:16px"><strong>Thinking it was “just an IT project”</strong><br>I didn’t involve other teams that were going to be affected. And of course, nobody likes sudden login issues. Better security doesn’t mean people will automatically love the changes. </li>



<li style="font-size:16px"><strong>Being too generous with roles</strong><br>Giving people more access makes onboarding easier, sure. But later, figuring out who had access to what turned into a nightmare.</li>



<li style="font-size:16px"><strong>Believing the official guides would save me<br></strong>Not every Okta integration works as described. I had to contact our CSM, open support tickets, and sometimes just rely on good old trial and error.</li>
</ol>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>



<p style="font-size:24px"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f501.png" alt="🔁" class="wp-smiley" style="height: 1em; max-height: 1em;" /><strong>What I’d do differently now that I know all this</strong></p>



<ul class="wp-block-list">
<li style="font-size:16px"><strong>Talk to the team first.</strong> Explain the “why” before changing how they log in. Make sure everyone’s informed.</li>



<li style="font-size:16px"><strong>Plan roles properly.</strong> No improvisation &#8211; even if it takes more time, it’s worth it in the long run.</li>



<li style="font-size:16px"><strong>Document, document, and document.</strong> You never know who else will need it. That person might be you at 2 AM.</li>



<li style="font-size:16px"><strong>Accept this is a journey.</strong> It’s not a one-and-done. It needs care and maintenance, always.</li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>



<p style="font-size:24px"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /><strong>Was it worth it?</strong></p>



<p style="font-size:16px">Absolutely!</p>



<p style="font-size:16px">We now have <strong>better visibility</strong>, a <strong>more serious onboarding/offboarding process</strong>, <strong>less reliance on VPNs or “internal trust”</strong>, and way <strong>more confidence</strong> when rolling out new tools.</p>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>



<p style="font-size:24px"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6eb.png" alt="🛫" class="wp-smiley" style="height: 1em; max-height: 1em;" /><strong>Thinking of starting this journey yourself?</strong></p>



<p style="font-size:16px">My advice? <strong>Start small.</strong> Focus on identity first. Pick one or two tools &#8211; and get them right.</p>



<p style="font-size:16px"><strong>Zero Trust</strong> sounds big and complicated, but it’s okay to take small steps. And more importantly, it’s okay to make mistakes. If you’re going in the right direction, those small wins will guide you forward.</p>



<p style="font-size:16px">And seriously… <strong>talk to people</strong>.<br>That might just be the most underrated part of doing IT right.</p>



</div>



<p></p>
]]></content:encoded>
					
					<wfw:commentRss>https://jmartinez.tech/implementing-zero-trust-with-okta-mistakes-i-made-and-what-id-do-differently/feed/</wfw:commentRss>
			<slash:comments>4</slash:comments>
		
		
			</item>
	</channel>
</rss>
