{"resources":{"okta":{"id":"okta","name":"okta","fields":{"api":{"name":"api","type":"\u001bokta.api","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"apiServiceIntegration":{"name":"apiServiceIntegration","type":"\u001bokta.apiServiceIntegration","title":"Okta API Service Integration","desc":"Third-party service granted OAuth 2.0 access to the Okta org through the API service integration catalog. Auditing these surfaces machine-to-machine access held by external vendors: `grantedScopes` lists the API scopes the integration can exercise, `type` identifies the catalog integration, and `createdBy` records the actor that installed it. Select an instance by its `id`.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"apiServiceIntegrations":{"name":"apiServiceIntegrations","type":"\u0019\u001bokta.apiServiceIntegration","title":"API service integrations granted OAuth 2.0 access to the org","min_provider_version":"13.3.2","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"apiTokens":{"name":"apiTokens","type":"\u0019\u001bokta.api.token","title":"Okta API tokens","min_provider_version":"13.1.6","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"application":{"name":"application","type":"\u001bokta.application","title":"Okta Application","desc":"Application integration configured in an Okta org, such as a SAML, OIDC, SWA, or bookmark app assigned to users and groups. Useful for auditing how each app authenticates (`signOnMode`), whether it is active (`status`), the sign-on and assertion settings that govern single sign-on, and the credential scheme in use. The `signingKeys` field returns the `okta.application.key` certificates that sign SAML assertions and OIDC tokens, so their status and expiry can be checked for expired or soon-to-expire signing material.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"applications":{"name":"applications","type":"\u0019\u001bokta.application","title":"Okta applications","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"attackProtection":{"name":"attackProtection","type":"\u001bokta.attackProtection","title":"Okta Attack Protection Settings","desc":"Organization-wide protection against brute-force and password-spray attacks. Auditing these confirms account-lockout defenses are enforced: `preventBruteForceLockoutFromUnknownDevices` reports whether lockout protection extends to sign-ins from unrecognized devices, and `verifyKnowledgeSecondWhen2faRequired` reports whether a knowledge factor is verified second when multifactor is required.","provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"authenticator":{"name":"authenticator","type":"\u001bokta.authenticator","title":"Okta Authenticator","desc":"Admin-defined MFA factor catalog entry in Okta that governs which authenticators (password, phone, email, security key, and others) users may enroll to satisfy multifactor requirements. Auditing these entries confirms that only approved authenticators are ACTIVE, that provider integrations match policy, and that user-verification and token-lifetime settings are enforced. The stable key identifies each authenticator, for example okta_password, okta_email, phone_number, or webauthn.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"authenticators":{"name":"authenticators","type":"\u0019\u001bokta.authenticator","title":"Okta authenticators (admin-defined MFA factors)","min_provider_version":"13.1.6","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"authorizationServer":{"name":"authorizationServer","type":"\u001bokta.authorizationServer","title":"Okta Custom Authorization Server","desc":"Custom OAuth 2.0 authorization server that mints access tokens for APIs in your Okta organization. Exposes the issuer configuration and the active signing-key setup, alongside the policies that decide which clients can request which scopes, the scopes and claims that shape issued tokens, and the published keys used to verify access tokens. Auditing these servers reveals token lifetimes, grant types, and consent behavior for every API protected by Okta.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"authorizationServers":{"name":"authorizationServers","type":"\u0019\u001bokta.authorizationServer","title":"Custom OAuth 2.0 authorization servers defined in the Okta org","min_provider_version":"13.2.6","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"behaviorRule":{"name":"behaviorRule","type":"\u001bokta.behaviorRule","title":"Okta Behavior Detection Rule","desc":"Rule that flags anomalous sign-in behavior so sign-on policies can require step-up authentication. Auditing behavior rules surfaces which risk signals the org detects: the `type` field selects the behavior evaluated (new device, new IP, new geolocation, or velocity), `settings` holds the type-specific thresholds, and `status` indicates whether the rule is active. Select a rule by its `name`.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"behaviorRules":{"name":"behaviorRules","type":"\u0019\u001bokta.behaviorRule","title":"Behavior detection rules evaluated during sign-on","min_provider_version":"13.3.2","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"customRole":{"name":"customRole","type":"\u001bokta.customRole","title":"Okta Custom Role","desc":"Custom administrator role defined in an Okta organization, granting a tailored set of administrative privileges beyond the built-in standard roles. Auditing custom roles surfaces which fine-grained permissions each role confers, so you can catch over-privileged roles and enforce least privilege across delegated administration.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"customRoles":{"name":"customRoles","type":"\u0019\u001bokta.customRole","title":"Okta custom roles","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"device":{"name":"device","type":"\u001bokta.device","title":"Okta Device","desc":"Device enrolled in the Okta org, tracked for device-trust and conditional access decisions. Auditing devices surfaces the endpoint population and its security posture: `profile` carries the hardware and OS attributes (platform, OS version, disk encryption, jailbreak state, secure hardware), `status` reflects the device lifecycle, and `users` lists the Okta accounts that use the device. Select a device by its `id`.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"deviceAssurancePolicies":{"name":"deviceAssurancePolicies","type":"\u0019\u001bokta.deviceAssurancePolicy","title":"Device assurance policies enforcing device-trust requirements","min_provider_version":"13.3.2","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"deviceAssurancePolicy":{"name":"deviceAssurancePolicy","type":"\u001bokta.deviceAssurancePolicy","title":"Okta Device Assurance Policy","desc":"Policy that defines the device-trust requirements an endpoint must meet to gain access, evaluated by sign-on policies. Auditing these confirms the minimum device posture the org enforces: the `platform` field selects the operating system the policy applies to, and `settings` holds the required constraints such as minimum OS version, disk encryption, screen lock, and secure-hardware or jailbreak checks. Select a policy by its `name`.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"devices":{"name":"devices","type":"\u0019\u001bokta.device","title":"Devices enrolled in the org","min_provider_version":"13.3.2","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"domain":{"name":"domain","type":"\u001bokta.domain","title":"Okta Domain","desc":"Custom domain configured for an Okta organization so the sign-in and end-user experience is served under a branded hostname instead of the default Okta domain. The validationStatus field reports where the domain sits in the ownership-verification workflow (NOT_STARTED, IN_PROGRESS, VERIFIED, or COMPLETED), dnsRecords holds the DNS entries that must be published to prove control of the hostname, and publicCertificate carries the metadata for the TLS certificate that secures it.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"domains":{"name":"domains","type":"\u0019\u001bokta.domain","title":"Okta domains","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"eventHook":{"name":"eventHook","type":"\u001bokta.eventHook","title":"Okta Event Hook","desc":"Outbound webhook that delivers Okta org events to an external service as they occur. Auditing event hooks surfaces where org activity is being sent and how the destination is trusted: `channelUri` is the endpoint Okta posts to, `channelAuthScheme` describes how Okta authenticates to it, `events` lists the subscribed event types, and `status` and `verificationStatus` indicate whether the hook is active and its endpoint ownership verified. A hook pointing at an untrusted URL is a data-exfiltration and persistence risk. Select a hook by its `name`.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"eventHooks":{"name":"eventHooks","type":"\u0019\u001bokta.eventHook","title":"Event hooks that deliver org events to external endpoints","min_provider_version":"13.3.2","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"group":{"name":"group","type":"\u001bokta.group","title":"Okta Group","desc":"Okta group, the unit of access control that bundles users together to grant applications, administrator roles, and policies. Query groups to audit who has access to what: `members` lists the `okta.user` accounts in the group and `roles` lists the administrator roles assigned to it. The `type` field distinguishes Okta-native groups from app-sourced and built-in groups, and `lastMembershipUpdated` records when membership last changed.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"groupRule":{"name":"groupRule","type":"\u001bokta.groupRule","title":"Okta Group Rule","desc":"Group rule that automatically assigns users to groups based on expression conditions evaluated against user profile attributes. Rules run whenever a matching user is created or updated, so auditing them surfaces dynamic group memberships that grant access without an explicit assignment. Select a rule by its `name`, and check `status` to confirm whether the rule is actively applying memberships.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"groupRules":{"name":"groupRules","type":"\u0019\u001bokta.groupRule","title":"Okta group rules","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"groups":{"name":"groups","type":"\u0019\u001bokta.group","title":"Okta groups","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"hookKey":{"name":"hookKey","type":"\u001bokta.hookKey","title":"Okta Hook Key","desc":"Cryptographic key pair Okta uses to sign outbound hook requests so the receiving service can verify they originate from Okta. Auditing hook keys surfaces stale or unused signing material: `isUsed` reports whether any hook currently references the key, and `publicKey` carries the public JSON Web Key metadata. Select a key by its `name`.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"hookKeys":{"name":"hookKeys","type":"\u0019\u001bokta.hookKey","title":"Cryptographic keys used to sign outbound hook requests","min_provider_version":"13.3.2","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"identityProvider":{"name":"identityProvider","type":"\u001bokta.identityProvider","title":"Okta Identity Provider","desc":"External identity provider federated with your Okta organization for inbound single sign-on. The `type` discriminator (SAML2, OIDC, OAUTH2, GOOGLE, FACEBOOK, LINKEDIN, MICROSOFT, APPLE, X509) selects which protocol, credential, and policy shape applies, while `status` (ACTIVE or INACTIVE) indicates whether the federation is live and `issuerMode` records whether the issuer URL is the Okta org URL, a custom URL domain, or dynamic. Auditing these catches untrusted or misconfigured trust relationships that could let an attacker authenticate into the org. The `protocol` and `policy` configurations expose the endpoints, credentials, algorithms, and account-link/provisioning/subject-matching rules, and `signingKeys` returns the X.509/JWK credentials trusted for assertions or tokens issued by this IdP, where `expiresAt` flags expiring trust anchors.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"identityProviders":{"name":"identityProviders","type":"\u0019\u001bokta.identityProvider","title":"External identity providers federated with the Okta org (SAML2, OIDC, social)","min_provider_version":"13.2.6","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"inlineHook":{"name":"inlineHook","type":"\u001bokta.inlineHook","title":"Okta Inline Hook","desc":"Synchronous callout that lets an external service influence an Okta flow (such as token minting, registration, or password import) while it runs. Auditing inline hooks surfaces external code injected into authentication and provisioning: `channelUri` is the endpoint Okta calls, `channelAuthScheme` describes how Okta authenticates to it, and `type` identifies which flow the hook participates in. Select a hook by its `name`, and check `status` to confirm whether it is active.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"inlineHooks":{"name":"inlineHooks","type":"\u0019\u001bokta.inlineHook","title":"Inline hooks that call out to external logic during Okta flows","min_provider_version":"13.3.2","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"logStream":{"name":"logStream","type":"\u001bokta.logStream","title":"Okta Log Stream","desc":"Connection that exports Okta System Log events to an external destination such as AWS EventBridge or Splunk Cloud. Auditing log streams answers whether the org's audit trail is shipped off-box and to where: `type` selects the destination kind, `settings` carries the destination coordinates (AWS `accountId`, `region`, and `eventSourceName`, or Splunk `host` and `edition`), and `status` indicates whether the stream is active. Select a stream by its `name`.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"logStreams":{"name":"logStreams","type":"\u0019\u001bokta.logStream","title":"Log streams that export System Log events to external destinations","min_provider_version":"13.3.2","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"network":{"name":"network","type":"\u001bokta.network","title":"Okta Network Zone","desc":"Network zone that allows or blocks access based on IP address, ASN, or geolocation. Zones are referenced by policy and sign-on rule conditions to restrict access to known corporate networks, or used as a blocklist to deny traffic from named regions and anonymizing proxies. The `type` field distinguishes an IP zone (explicit gateway and proxy addresses) from a DYNAMIC zone (matched by ASN, geolocation, or proxy classification), and `usage` records whether the zone drives POLICY decisions or acts as a BLOCKLIST.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"networks":{"name":"networks","type":"\u0019\u001bokta.network","title":"Okta networks","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"organization":{"name":"organization","type":"\u001bokta.organization","title":"Okta Organization","desc":"Tenant-level settings for your Okta organization. Covers identity information such as `companyName`, `subdomain`, address, and contact details, along with operational fields like `status`, `created`, and `expiresAt`. The `billingContact` and `technicalContact` resolve to the `okta.user` records responsible for the org, `securityNotificationEmails` reports which end-user security emails the tenant sends, and `threatInsightSettings` exposes the Okta ThreatInsight configuration that blocks requests from suspicious IPs.","provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"policies":{"name":"policies","type":"\u001bokta.policies","title":"Okta Policies","desc":"Policy collections that govern authentication and account security across an Okta organization, grouped by the behavior they control: password complexity and lockout, multifactor enrollment, sign-on and session conditions, OAuth authorization, identity-provider routing, application access, and self-service profile enrollment. Each collection returns `okta.policy` records whose rules define the conditions and actions, making this the entry point for auditing how sign-in, MFA, and password controls are enforced.","provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"policy":{"name":"policy","type":"\u001bokta.policy","title":"Okta Policy","desc":"Policy governing authentication and access behavior in an Okta organization, such as password strength, MFA enrollment, sign-on enforcement, identity-provider routing, and app-level access. The type field selects the policy category (OKTA_SIGN_ON, PASSWORD, MFA_ENROLL, OAUTH_AUTHORIZATION_POLICY, IDP_DISCOVERY, ACCESS_POLICY, or PROFILE_ENROLLMENT), and the type-specific enforcement lives in conditions and settings. The rules field returns the ordered okta.policyRule records that refine when and how the policy applies.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"policyRule":{"name":"policyRule","type":"\u001bokta.policyRule","title":"Okta policy rule","desc":"Rule within an Okta policy, evaluated in `priority` order so that the first rule whose `conditions` match applies its `actions`. Rules carry the enforced decisions behind a policy: required sign-on assurance, MFA enrollment, password constraints, and app-access outcomes. The `system` flag marks built-in rules that cannot be edited, and `status` reports whether the rule is ACTIVE or INACTIVE.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"resourceSet":{"name":"resourceSet","type":"\u001bokta.resourceSet","title":"Okta Resource Set","desc":"Named collection of resources that a custom administrator role can be scoped to. Resource sets are the \"over what\" half of a custom admin grant: a binding ties a custom role to a set of members (users and groups) and the resource set limits the resources those members may administer. Select a set by its `label`. The `resources` field lists the groups, applications, and users the set covers, and `bindings` lists the custom-role grants made through it.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"resourceSets":{"name":"resourceSets","type":"\u0019\u001bokta.resourceSet","title":"Resource sets that scope custom administrator roles","min_provider_version":"13.3.2","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"riskProvider":{"name":"riskProvider","type":"\u001bokta.riskProvider","title":"Okta Risk Provider","desc":"Third-party service that feeds risk signals into Okta sign-on decisions. Auditing risk providers surfaces external inputs to authentication risk: `action` reports how Okta consumes the signal, and `clientId` identifies the OAuth 2.0 client the provider authenticates as. Select a provider by its `name`.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"riskProviders":{"name":"riskProviders","type":"\u0019\u001bokta.riskProvider","title":"Third-party risk signal providers integrated with the org","min_provider_version":"13.3.2","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"role":{"name":"role","type":"\u001bokta.role","title":"Okta administrative role assigned to a user or group","desc":"Administrative role granting elevated privileges within an Okta org, as assigned to an individual user or to a group. Review this to audit who holds admin access and how broad it is: the `type` field names the permission scope (for example SUPER_ADMIN or a CUSTOM role), while `assignmentType` distinguishes a direct user assignment from one inherited through group membership.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"securityEventsProvider":{"name":"securityEventsProvider","type":"\u001bokta.securityEventsProvider","title":"Okta Security Events Provider","desc":"External provider that shares security signals with the Okta org through the Shared Signals Framework (SSF/CAEP), enabling continuous access evaluation. Auditing these surfaces the cross-vendor trust relationships feeding real-time security events: `type` identifies the provider, `settings` carries the signal endpoints (issuer, JWKS URL, and well-known configuration URL), and `status` indicates whether the integration is active. Select a provider by its `name`.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"securityEventsProviders":{"name":"securityEventsProviders","type":"\u0019\u001bokta.securityEventsProvider","title":"Security events providers feeding shared security signals to the org","min_provider_version":"13.3.2","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"threatsConfiguration":{"name":"threatsConfiguration","type":"\u001bokta.threatsConfiguration","title":"Okta ThreatInsight Configuration","desc":"Organization-wide ThreatInsight settings that determine how Okta responds to requests from IP addresses with a known history of malicious activity. The `action` field selects whether such traffic is only logged or actively blocked, and `excludeZones` names the network zones exempt from ThreatInsight evaluation. Query this to confirm that threat detection is enforced and that no sensitive zones are wrongly exempted.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"trustedOrigin":{"name":"trustedOrigin","type":"\u001bokta.trustedOrigin","title":"Okta Trusted Origin","desc":"Cross-origin URL that Okta trusts for browser-based interactions such as CORS requests, post-authentication redirects, and iframe embedding of Okta pages. Trusted origins define which external sites may call Okta APIs or receive redirects, so an overly broad or unexpected entry widens the surface for cross-site request forgery and data exfiltration. The `scopes` field records which interaction types each origin is trusted for.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"trustedOrigins":{"name":"trustedOrigins","type":"\u0019\u001bokta.trustedOrigin","title":"Okta trusted origins","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"user":{"name":"user","type":"\u001bokta.user","title":"Okta User","desc":"Individual account in the Okta identity store. The lifecycle fields (`status`, `activated`, `lastLogin`, `passwordChanged`) reveal dormant, suspended, or never-activated accounts, `roles` exposes privileged administrative grants, and `factors` shows which multi-factor methods the user has enrolled. Auditing users surfaces stale credentials, over-privileged accounts, and gaps in MFA coverage.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"userFactor":{"name":"userFactor","type":"\u001bokta.userFactor","title":"Okta MFA factor enrolled by a user","desc":"Multi-factor authentication method registered against an Okta user account. The `factorType` identifies the method (TOTP, push, SMS, call, WebAuthn, FIDO, email, or security question), `provider` identifies who issues it (OKTA, GOOGLE, RSA, SYMANTEC, DUO, FIDO, CUSTOM), and `status` reflects its enrollment lifecycle. Query these to audit which users have strong MFA enrolled, flag weak or unverified factors (SMS, call, security question, or factors still in PENDING_ACTIVATION), and confirm that privileged accounts carry phishing-resistant WebAuthn or FIDO factors. The `profile` field carries the enrollment data specific to each factor type.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"users":{"name":"users","type":"\u0019\u001bokta.user","title":"Okta users","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta","desc":"Namespace for the users, groups, applications, policies, trusted origins, network zones, authenticators, API tokens, and custom roles configured in your Okta organization. Query `okta.organization` for tenant-level settings such as billing contacts, threat insight configuration, and security notification preferences.","min_provider_version":"9.0.0","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.api":{"id":"okta.api","fields":{"token":{"name":"token","type":"\u001bokta.api.token","title":"Okta API Token","desc":"API token that authenticates a user or service to the Okta REST API. These are long-lived credentials whose compromise grants programmatic access to the org, so auditing them surfaces stale or over-scoped tokens, tokens nearing expiry, and tokens that have gone unused. The `lastUpdated` timestamp doubles as the last-used time, `expiresAt` and `tokenWindow` describe the token's lifetime, and `user` resolves the Okta account the token acts on behalf of.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true}},"is_extension":true},"okta.api.token":{"id":"okta.api.token","name":"okta.api.token","fields":{"clientName":{"name":"clientName","type":"\u0007","is_mandatory":true,"title":"ID of the client the token was created for","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the token was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"expiresAt":{"name":"expiresAt","type":"\t","is_mandatory":true,"title":"Timestamp when the token expires","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the API token","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the token was last updated (also reflects the last time the token was used)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Display name of the token","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"tokenWindow":{"name":"tokenWindow","type":"\u0007","is_mandatory":true,"title":"Token window (lifetime) in ISO 8601 duration format","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"user":{"name":"user","type":"\u001bokta.user","title":"The user the token belongs to","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta API Token","desc":"API token that authenticates a user or service to the Okta REST API. These are long-lived credentials whose compromise grants programmatic access to the org, so auditing them surfaces stale or over-scoped tokens, tokens nearing expiry, and tokens that have gone unused. The `lastUpdated` timestamp doubles as the last-used time, `expiresAt` and `tokenWindow` describe the token's lifetime, and `user` resolves the Okta account the token acts on behalf of.","private":true,"min_provider_version":"13.1.6","defaults":"name","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.apiServiceIntegration":{"id":"okta.apiServiceIntegration","name":"okta.apiServiceIntegration","fields":{"configGuideUrl":{"name":"configGuideUrl","type":"\u0007","is_mandatory":true,"title":"URL of the integration's configuration guide","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Timestamp when the integration instance was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"createdBy":{"name":"createdBy","type":"\u0007","is_mandatory":true,"title":"Actor that created the integration instance","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"grantedScopes":{"name":"grantedScopes","type":"\u0019\u0007","is_mandatory":true,"title":"OAuth 2.0 scopes granted to the integration","desc":"The API scopes the integration is authorized to exercise, for example `okta.users.read` or `okta.logs.read`.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the integration instance","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Display name of the integration","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Catalog integration type","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta API Service Integration","desc":"Third-party service granted OAuth 2.0 access to the Okta org through the API service integration catalog. Auditing these surfaces machine-to-machine access held by external vendors: `grantedScopes` lists the API scopes the integration can exercise, `type` identifies the catalog integration, and `createdBy` records the actor that installed it. Select an instance by its `id`.","private":true,"min_provider_version":"13.3.2","defaults":"name type","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.application":{"id":"okta.application","name":"okta.application","fields":{"adminRoles":{"name":"adminRoles","type":"\u0019\u001bokta.role","title":"Administrator roles assigned to the application's OAuth client","desc":"Admin roles granted to the app as a service (OAuth 2.0) client, for apps that authenticate to the Okta API on their own behalf. Empty for apps that are not API service clients.","min_provider_version":"13.3.2","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"assignedGroups":{"name":"assignedGroups","type":"\u0019\u001bokta.application.groupAssignment","title":"Groups assigned to the application","min_provider_version":"13.3.2","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"assignedUsers":{"name":"assignedUsers","type":"\u0019\u001bokta.application.user","title":"Users assigned to the application","min_provider_version":"13.3.2","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the application was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"credentials":{"name":"credentials","type":"\n","is_mandatory":true,"title":"Credentials for the specified sign-on mode","desc":"Shape varies by `signOnMode`. Common keys include `userNameTemplate` (`template`, `type`, `userSuffix`), which controls the username sent to the app, `signing` (`kid`, `rotationMode`, `lastRotated`, `nextRotation`), which identifies the active signing key, `scheme`, and, for password-based apps, `password` and `revealPassword`.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"features":{"name":"features","type":"\u0019\u0007","is_mandatory":true,"title":"Enabled app features","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"groupAssignment":{"name":"groupAssignment","type":"\u001bokta.application.groupAssignment","title":"Group assigned to an Okta application","desc":"Assignment of an Okta group to an application, granting the app to every member of the group. The `priority` field orders overlapping group assignments when they supply conflicting profile values, `profile` holds the app-specific attributes applied to members, and `group` resolves the underlying Okta group. Auditing these surfaces access granted in bulk rather than per user.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique key for the application","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"key":{"name":"key","type":"\u001bokta.application.key","title":"Okta application signing key","desc":"X.509 signing certificate (JSON Web Key) published for an Okta application and used to sign SAML assertions and OIDC tokens. Auditing `status` and `expiresAt` catches expired or soon-to-expire signing material that would break single sign-on. Each key is selected by its `kid` within the owning application.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"label":{"name":"label","type":"\u0007","is_mandatory":true,"title":"User-defined display name for the application","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the application was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"licensing":{"name":"licensing","type":"\n","is_mandatory":true,"title":"Okta licensing information","desc":"Holds `seatCount`, the number of licensed seats provisioned for the application.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Unique key that defines the application","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"profile":{"name":"profile","type":"\n","is_mandatory":true,"title":"Custom application profile attributes","desc":"Free-form custom attributes defined on the application profile. Keys and values depend on the app and any custom schema properties configured for it.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"scopeConsentGrant":{"name":"scopeConsentGrant","type":"\u001bokta.application.scopeConsentGrant","title":"OAuth 2.0 scope consent grant for an Okta application","desc":"Consent that authorizes an application to act with a specific OAuth 2.0 scope against an Okta authorization server. Auditing grants surfaces the API access an app (or a user through an app) has been permitted: `scopeId` names the granted scope, `issuer` identifies the authorization server, `status` reflects whether the grant is active, and `source` records whether consent was granted by an admin or an end user. The `user` field resolves the account for user-level grants and is null for org-level grants.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"scopeConsentGrants":{"name":"scopeConsentGrants","type":"\u0019\u001bokta.application.scopeConsentGrant","title":"OAuth 2.0 scope consent grants made to the application","min_provider_version":"13.3.2","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"settings":{"name":"settings","type":"\n","is_mandatory":true,"title":"Settings for the application","desc":"Shape varies by app type. For SAML apps the `signOn` key carries the single sign-on configuration (`ssoAcsUrl`, `audience`, `recipient`, `destination`, `idpIssuer`, `subjectNameIdFormat`, `responseSigned`, `assertionSigned`, `signatureAlgorithm`, `digestAlgorithm`, `honorForceAuthn`), while `app`, `notifications`, and `notes` hold app-specific and administrative configuration.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"signOnMode":{"name":"signOnMode","type":"\u0007","is_mandatory":true,"title":"Authentication mode of the application","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"signingKeys":{"name":"signingKeys","type":"\u0019\u001bokta.application.key","title":"Signing keys/certificates published for this application (for SAML/OIDC signing)","min_provider_version":"13.1.6","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the application","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"user":{"name":"user","type":"\u001bokta.application.user","title":"User assigned to an Okta application","desc":"Assignment of a single Okta user to an application, carrying the app-specific view of that account. The `scope` field records whether the assignment is direct (USER) or inherited through a group (GROUP), `status` reflects the app-level provisioning state, and `credentials` and `profile` hold the application username and any app-specific profile attributes. The `user` field resolves the underlying Okta account. Auditing these answers \"who can sign in to this app, and how were they granted access\".","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"visibility":{"name":"visibility","type":"\n","is_mandatory":true,"title":"Visibility settings for the application","desc":"Controls where the app appears. Keys are `autoLaunch`, `autoSubmitToolbar`, `appLinks` (per-link enablement), and `hide` (`iOS` and `web` booleans that suppress the app chiclet).","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Application","desc":"Application integration configured in an Okta org, such as a SAML, OIDC, SWA, or bookmark app assigned to users and groups. Useful for auditing how each app authenticates (`signOnMode`), whether it is active (`status`), the sign-on and assertion settings that govern single sign-on, and the credential scheme in use. The `signingKeys` field returns the `okta.application.key` certificates that sign SAML assertions and OIDC tokens, so their status and expiry can be checked for expired or soon-to-expire signing material.","private":true,"min_provider_version":"9.0.0","defaults":"name","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.application.groupAssignment":{"id":"okta.application.groupAssignment","name":"okta.application.groupAssignment","fields":{"group":{"name":"group","type":"\u001bokta.group","title":"The Okta group this assignment refers to","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the assigned group (the Okta group id)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the assignment was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"priority":{"name":"priority","type":"\u0005","is_mandatory":true,"title":"Assignment priority","desc":"Orders overlapping group assignments; lower numbers win when assignments supply conflicting profile values.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"profile":{"name":"profile","type":"\n","is_mandatory":true,"title":"Application-specific profile attributes applied to group members","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Group assigned to an Okta application","desc":"Assignment of an Okta group to an application, granting the app to every member of the group. The `priority` field orders overlapping group assignments when they supply conflicting profile values, `profile` holds the app-specific attributes applied to members, and `group` resolves the underlying Okta group. Auditing these surfaces access granted in bulk rather than per user.","private":true,"min_provider_version":"13.3.2","defaults":"id priority","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.application.key":{"id":"okta.application.key","name":"okta.application.key","fields":{"alg":{"name":"alg","type":"\u0007","is_mandatory":true,"title":"Algorithm used (e.g., RS256)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"applicationId":{"name":"applicationId","type":"\u0007","is_mandatory":true,"title":"ID of the application this key belongs to (composite with kid for uniqueness)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the key was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"e":{"name":"e","type":"\u0007","is_mandatory":true,"title":"RSA exponent","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"expiresAt":{"name":"expiresAt","type":"\t","is_mandatory":true,"title":"Timestamp when the key/certificate expires","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"keyOps":{"name":"keyOps","type":"\u0019\u0007","is_mandatory":true,"title":"Permitted key operations","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"kid":{"name":"kid","type":"\u0007","is_mandatory":true,"title":"Key ID of the application key","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"kty":{"name":"kty","type":"\u0007","is_mandatory":true,"title":"Key type (e.g., RSA)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the key was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"n":{"name":"n","type":"\u0007","is_mandatory":true,"title":"RSA modulus","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the key (e.g., ACTIVE, INACTIVE, EXPIRED)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"use":{"name":"use","type":"\u0007","is_mandatory":true,"title":"Public key use (e.g., sig, enc)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"x5c":{"name":"x5c","type":"\u0019\u0007","is_mandatory":true,"title":"X.509 certificate chain (PEM/DER without headers, base64-encoded)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"x5t":{"name":"x5t","type":"\u0007","is_mandatory":true,"title":"SHA-1 thumbprint of the X.509 certificate","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"x5tS256":{"name":"x5tS256","type":"\u0007","is_mandatory":true,"title":"SHA-256 thumbprint of the X.509 certificate","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta application signing key","desc":"X.509 signing certificate (JSON Web Key) published for an Okta application and used to sign SAML assertions and OIDC tokens. Auditing `status` and `expiresAt` catches expired or soon-to-expire signing material that would break single sign-on. Each key is selected by its `kid` within the owning application.","private":true,"min_provider_version":"13.1.6","defaults":"kid status expiresAt","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.application.scopeConsentGrant":{"id":"okta.application.scopeConsentGrant","name":"okta.application.scopeConsentGrant","fields":{"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the grant was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the grant","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"issuer":{"name":"issuer","type":"\u0007","is_mandatory":true,"title":"Authorization server that issued the grant","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the grant was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"scopeId":{"name":"scopeId","type":"\u0007","is_mandatory":true,"title":"Granted OAuth 2.0 scope","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"source":{"name":"source","type":"\u0007","is_mandatory":true,"title":"Consent source","desc":"Records how consent was obtained, for example ADMIN for an administrator grant or END_USER for user consent.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the grant: ACTIVE or INACTIVE","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"user":{"name":"user","type":"\u001bokta.user","title":"The user for a user-level grant","desc":"Resolves the Okta account when the grant was made on behalf of a specific user. Null for org-level grants.","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"OAuth 2.0 scope consent grant for an Okta application","desc":"Consent that authorizes an application to act with a specific OAuth 2.0 scope against an Okta authorization server. Auditing grants surfaces the API access an app (or a user through an app) has been permitted: `scopeId` names the granted scope, `issuer` identifies the authorization server, `status` reflects whether the grant is active, and `source` records whether consent was granted by an admin or an end user. The `user` field resolves the account for user-level grants and is null for org-level grants.","private":true,"min_provider_version":"13.3.2","defaults":"scopeId status","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.application.user":{"id":"okta.application.user","name":"okta.application.user","fields":{"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the assignment was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"credentials":{"name":"credentials","type":"\n","is_mandatory":true,"title":"Application credentials for the user","desc":"Holds the app-specific `userName` (and, for schemes that store it, password metadata) used when signing the user in to the application.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the assigned user (the Okta user id)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastSync":{"name":"lastSync","type":"\t","is_mandatory":true,"title":"Timestamp of the last provisioning sync","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the assignment was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"profile":{"name":"profile","type":"\n","is_mandatory":true,"title":"Application-specific profile attributes for the user","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"scope":{"name":"scope","type":"\u0007","is_mandatory":true,"title":"How the assignment was granted","desc":"Either USER for a direct assignment or GROUP for access inherited through group membership.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Application-level provisioning status of the user","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"syncState":{"name":"syncState","type":"\u0007","is_mandatory":true,"title":"Provisioning sync state of the assignment","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"user":{"name":"user","type":"\u001bokta.user","title":"The Okta user account this assignment refers to","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"User assigned to an Okta application","desc":"Assignment of a single Okta user to an application, carrying the app-specific view of that account. The `scope` field records whether the assignment is direct (USER) or inherited through a group (GROUP), `status` reflects the app-level provisioning state, and `credentials` and `profile` hold the application username and any app-specific profile attributes. The `user` field resolves the underlying Okta account. Auditing these answers \"who can sign in to this app, and how were they granted access\".","private":true,"min_provider_version":"13.3.2","defaults":"scope status","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.attackProtection":{"id":"okta.attackProtection","name":"okta.attackProtection","fields":{"preventBruteForceLockoutFromUnknownDevices":{"name":"preventBruteForceLockoutFromUnknownDevices","type":"\u0004","is_mandatory":true,"title":"Whether brute-force lockout protection applies to unknown devices","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"verifyKnowledgeSecondWhen2faRequired":{"name":"verifyKnowledgeSecondWhen2faRequired","type":"\u0004","is_mandatory":true,"title":"Whether a knowledge factor is verified second when 2FA is required","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Attack Protection Settings","desc":"Organization-wide protection against brute-force and password-spray attacks. Auditing these confirms account-lockout defenses are enforced: `preventBruteForceLockoutFromUnknownDevices` reports whether lockout protection extends to sign-ins from unrecognized devices, and `verifyKnowledgeSecondWhen2faRequired` reports whether a knowledge factor is verified second when multifactor is required.","min_provider_version":"13.3.2","defaults":"preventBruteForceLockoutFromUnknownDevices","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.authenticator":{"id":"okta.authenticator","name":"okta.authenticator","fields":{"allowedFor":{"name":"allowedFor","type":"\u0007","title":"Policy scope the authenticator is allowed for","desc":"One of \"any\", \"recovery\", \"sso\", or \"none\".","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the authenticator was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the authenticator","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"key":{"name":"key","type":"\u0007","is_mandatory":true,"title":"Stable key for the authenticator (e.g., okta_password, okta_email, phone_number, webauthn)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the authenticator was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Display name of the authenticator","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"providerConfiguration":{"name":"providerConfiguration","type":"\n","title":"Provider-specific configuration","desc":"Configuration for the authenticator's provider. The available keys depend on providerType, since an OKTA provider and a third-party provider such as DUO expose different settings.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"providerType":{"name":"providerType","type":"\u0007","title":"Provider type for this authenticator (e.g., OKTA, DUO)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"settings":{"name":"settings","type":"\n","is_mandatory":true,"title":"Authenticator settings (allowedFor, tokenLifetimeInMinutes, userVerification, etc.)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the authenticator: ACTIVE or INACTIVE","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"tokenLifetimeInMinutes":{"name":"tokenLifetimeInMinutes","type":"\u0005","title":"Token lifetime in minutes (for email, OTP-style authenticators)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Type of authenticator (e.g., password, security_key, phone, email, app)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"userVerification":{"name":"userVerification","type":"\u0007","title":"User verification setting (e.g., REQUIRED, PREFERRED, DISCOURAGED)","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Authenticator","desc":"Admin-defined MFA factor catalog entry in Okta that governs which authenticators (password, phone, email, security key, and others) users may enroll to satisfy multifactor requirements. Auditing these entries confirms that only approved authenticators are ACTIVE, that provider integrations match policy, and that user-verification and token-lifetime settings are enforced. The stable key identifies each authenticator, for example okta_password, okta_email, phone_number, or webauthn.","private":true,"min_provider_version":"13.1.6","defaults":"name key status","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.authorizationServer":{"id":"okta.authorizationServer","name":"okta.authorizationServer","fields":{"audiences":{"name":"audiences","type":"\u0019\u0007","is_mandatory":true,"title":"Acceptable audiences for access tokens minted by this server","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"claim":{"name":"claim","type":"\u001bokta.authorizationServer.claim","title":"Okta Authorization Server Claim","desc":"Claim included in access or ID tokens issued by a custom authorization server. claimType distinguishes RESOURCE claims (access tokens) from IDENTITY claims (ID tokens), valueType selects how value is interpreted, and alwaysIncludeInToken controls whether the claim appears regardless of which scopes were granted. The value holds either an Okta Expression Language source or a group filter pattern.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"claims":{"name":"claims","type":"\u0019\u001bokta.authorizationServer.claim","title":"Claims included in access or ID tokens issued by this server","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the authorization server was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"default":{"name":"default","type":"\u0004","is_mandatory":true,"title":"Whether this is the default authorization server for the org","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the authorization server","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the authorization server","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"issuer":{"name":"issuer","type":"\u0007","is_mandatory":true,"title":"Issuer URL advertised in the OIDC discovery document","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"issuerMode":{"name":"issuerMode","type":"\u0007","is_mandatory":true,"title":"Issuer mode for tokens","desc":"One of ORG_URL, CUSTOM_URL, or DYNAMIC.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"key":{"name":"key","type":"\u001bokta.authorizationServer.key","title":"Okta Authorization Server signing key (JsonWebKey)","desc":"JsonWebKey published by a custom authorization server for verifying access tokens. status distinguishes the ACTIVE key from the NEXT key (staged for rotation) and EXPIRED keys, while the X.509 certificate chain, SHA-1 and SHA-256 thumbprints, and RSA modulus and exponent let you validate token signatures independently.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"keys":{"name":"keys","type":"\u0019\u001bokta.authorizationServer.key","title":"Published signing keys for access tokens issued by this server","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the authorization server was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Display name of the authorization server","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"policies":{"name":"policies","type":"\u0019\u001bokta.authorizationServer.policy","title":"Policies controlling which clients can request which scopes","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"policy":{"name":"policy","type":"\u001bokta.authorizationServer.policy","title":"Okta Authorization Server Policy","desc":"Policy on a custom authorization server that grants specific OAuth 2.0 clients access to specific scopes under specific conditions. The conditions dict carries the client allowlist the policy applies to, rules returns the ordered rules that hold the actual grant logic, and system marks policies that Okta manages and administrators cannot edit.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"policyRule":{"name":"policyRule","type":"\u001bokta.authorizationServer.policyRule","title":"Okta Authorization Server Policy Rule","desc":"Rule on an authorization-server policy that governs which OAuth 2.0 grant types and scopes are permitted, the access-token and refresh-token lifetimes, and the inline hook (if any) invoked when access tokens are minted. The actions dict holds the enforced token settings and the conditions dict holds the grant types, scopes, and people the rule matches.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"scope":{"name":"scope","type":"\u001bokta.authorizationServer.scope","title":"Okta Authorization Server Scope","desc":"OAuth 2.0 scope defined on a custom authorization server. The name is the programmatic value sent in `scope=` requests, consent controls whether the user is prompted to approve it, default marks scopes granted without being requested, and metadataPublish controls whether the scope appears in the `.well-known` discovery document.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"scopes":{"name":"scopes","type":"\u0019\u001bokta.authorizationServer.scope","title":"OAuth 2.0 scopes defined on this authorization server","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"signingKid":{"name":"signingKid","type":"\u0007","is_mandatory":true,"title":"Key ID of the active signing key","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"signingLastRotated":{"name":"signingLastRotated","type":"\t","is_mandatory":true,"title":"Timestamp when the signing key was last rotated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"signingNextRotation":{"name":"signingNextRotation","type":"\t","is_mandatory":true,"title":"Timestamp of the next scheduled signing key rotation","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"signingRotationMode":{"name":"signingRotationMode","type":"\u0007","is_mandatory":true,"title":"Signing key rotation mode: AUTO or MANUAL","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"signingUse":{"name":"signingUse","type":"\u0007","is_mandatory":true,"title":"Intended use of the signing key (e.g., sig)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the authorization server: ACTIVE or INACTIVE","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Custom Authorization Server","desc":"Custom OAuth 2.0 authorization server that mints access tokens for APIs in your Okta organization. Exposes the issuer configuration and the active signing-key setup, alongside the policies that decide which clients can request which scopes, the scopes and claims that shape issued tokens, and the published keys used to verify access tokens. Auditing these servers reveals token lifetimes, grant types, and consent behavior for every API protected by Okta.","private":true,"min_provider_version":"13.2.6","defaults":"name status issuer","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.authorizationServer.claim":{"id":"okta.authorizationServer.claim","name":"okta.authorizationServer.claim","fields":{"alwaysIncludeInToken":{"name":"alwaysIncludeInToken","type":"\u0004","is_mandatory":true,"title":"Whether the claim is included in tokens regardless of granted scopes","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"authorizationServerId":{"name":"authorizationServerId","type":"\u0007","is_mandatory":true,"title":"ID of the authorization server this claim belongs to","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"claimType":{"name":"claimType","type":"\u0007","is_mandatory":true,"title":"Claim type","desc":"RESOURCE claims appear in access tokens; IDENTITY claims appear in ID tokens.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"groupFilterType":{"name":"groupFilterType","type":"\u0007","is_mandatory":true,"title":"For groups claims: STARTS_WITH, EQUALS, CONTAINS, or REGEX","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Identifier of the claim","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the claim","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"scopes":{"name":"scopes","type":"\u0019\u0007","is_mandatory":true,"title":"Scopes that must be granted for this claim to be included","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the claim: ACTIVE or INACTIVE","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"system":{"name":"system","type":"\u0004","is_mandatory":true,"title":"Whether the claim is system-managed","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"value":{"name":"value","type":"\u0007","is_mandatory":true,"title":"The Okta Expression Language source or group filter pattern","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"valueType":{"name":"valueType","type":"\u0007","is_mandatory":true,"title":"Value type","desc":"One of EXPRESSION, GROUPS, or SYSTEM.","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Authorization Server Claim","desc":"Claim included in access or ID tokens issued by a custom authorization server. claimType distinguishes RESOURCE claims (access tokens) from IDENTITY claims (ID tokens), valueType selects how value is interpreted, and alwaysIncludeInToken controls whether the claim appears regardless of which scopes were granted. The value holds either an Okta Expression Language source or a group filter pattern.","private":true,"min_provider_version":"13.2.6","defaults":"name status claimType","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.authorizationServer.key":{"id":"okta.authorizationServer.key","name":"okta.authorizationServer.key","fields":{"alg":{"name":"alg","type":"\u0007","is_mandatory":true,"title":"Algorithm used (e.g., RS256)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"authorizationServerId":{"name":"authorizationServerId","type":"\u0007","is_mandatory":true,"title":"ID of the authorization server this key belongs to","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the key was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"e":{"name":"e","type":"\u0007","is_mandatory":true,"title":"RSA exponent","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"expiresAt":{"name":"expiresAt","type":"\t","is_mandatory":true,"title":"Timestamp when the key/certificate expires","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"keyOps":{"name":"keyOps","type":"\u0019\u0007","is_mandatory":true,"title":"Permitted key operations","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"kid":{"name":"kid","type":"\u0007","is_mandatory":true,"title":"Key ID","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"kty":{"name":"kty","type":"\u0007","is_mandatory":true,"title":"Key type (e.g., RSA)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the key was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"n":{"name":"n","type":"\u0007","is_mandatory":true,"title":"RSA modulus","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the key (e.g., ACTIVE, NEXT, EXPIRED)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"use":{"name":"use","type":"\u0007","is_mandatory":true,"title":"Public key use (e.g., sig)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"x5c":{"name":"x5c","type":"\u0019\u0007","is_mandatory":true,"title":"X.509 certificate chain (PEM/DER without headers, base64-encoded)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"x5t":{"name":"x5t","type":"\u0007","is_mandatory":true,"title":"SHA-1 thumbprint of the X.509 certificate","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"x5tS256":{"name":"x5tS256","type":"\u0007","is_mandatory":true,"title":"SHA-256 thumbprint of the X.509 certificate","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Authorization Server signing key (JsonWebKey)","desc":"JsonWebKey published by a custom authorization server for verifying access tokens. status distinguishes the ACTIVE key from the NEXT key (staged for rotation) and EXPIRED keys, while the X.509 certificate chain, SHA-1 and SHA-256 thumbprints, and RSA modulus and exponent let you validate token signatures independently.","private":true,"min_provider_version":"13.2.6","defaults":"kid status","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.authorizationServer.policy":{"id":"okta.authorizationServer.policy","name":"okta.authorizationServer.policy","fields":{"authorizationServerId":{"name":"authorizationServerId","type":"\u0007","is_mandatory":true,"title":"ID of the authorization server this policy belongs to","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"conditions":{"name":"conditions","type":"\n","is_mandatory":true,"title":"Client allowlist the policy applies to","desc":"Dict with a `clients` key whose `include` list holds either the literal `ALL_CLIENTS` or the specific OAuth 2.0 client IDs the policy governs.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the policy was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the policy","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Identifier of the policy","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the policy was last modified","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the policy","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"priority":{"name":"priority","type":"\u0005","is_mandatory":true,"title":"Priority of the policy","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"rules":{"name":"rules","type":"\u0019\u001bokta.authorizationServer.policyRule","title":"Rules attached to the policy","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the policy: ACTIVE or INACTIVE","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"system":{"name":"system","type":"\u0004","is_mandatory":true,"title":"Whether the policy is system-managed","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Policy type (typically OAUTH_AUTHORIZATION_POLICY)","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Authorization Server Policy","desc":"Policy on a custom authorization server that grants specific OAuth 2.0 clients access to specific scopes under specific conditions. The conditions dict carries the client allowlist the policy applies to, rules returns the ordered rules that hold the actual grant logic, and system marks policies that Okta manages and administrators cannot edit.","private":true,"min_provider_version":"13.2.6","defaults":"name status priority","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.authorizationServer.policyRule":{"id":"okta.authorizationServer.policyRule","name":"okta.authorizationServer.policyRule","fields":{"actions":{"name":"actions","type":"\n","is_mandatory":true,"title":"Token lifetimes and inline hook applied when tokens are minted","desc":"Dict with a `token` key holding `accessTokenLifetimeMinutes`, `refreshTokenLifetimeMinutes`, and `refreshTokenWindowMinutes`, plus an optional `inlineHook` reference invoked during token minting.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"authorizationServerId":{"name":"authorizationServerId","type":"\u0007","is_mandatory":true,"title":"ID of the authorization server this rule's policy belongs to","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"conditions":{"name":"conditions","type":"\n","is_mandatory":true,"title":"Grant types, scopes, and people the rule applies to","desc":"Dict with `grantTypes` and `scopes` keys (each carrying an `include` list) and a `people` key selecting the users or groups the rule matches.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the rule was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Identifier of the rule","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the rule was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the rule","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"policyId":{"name":"policyId","type":"\u0007","is_mandatory":true,"title":"ID of the policy this rule belongs to","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"priority":{"name":"priority","type":"\u0005","is_mandatory":true,"title":"Priority of the rule","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the rule: ACTIVE or INACTIVE","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"system":{"name":"system","type":"\u0004","is_mandatory":true,"title":"Whether the rule is system-managed","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Rule type (typically RESOURCE_ACCESS)","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Authorization Server Policy Rule","desc":"Rule on an authorization-server policy that governs which OAuth 2.0 grant types and scopes are permitted, the access-token and refresh-token lifetimes, and the inline hook (if any) invoked when access tokens are minted. The actions dict holds the enforced token settings and the conditions dict holds the grant types, scopes, and people the rule matches.","private":true,"min_provider_version":"13.2.6","defaults":"name status priority","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.authorizationServer.scope":{"id":"okta.authorizationServer.scope","name":"okta.authorizationServer.scope","fields":{"authorizationServerId":{"name":"authorizationServerId","type":"\u0007","is_mandatory":true,"title":"ID of the authorization server this scope belongs to","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"consent":{"name":"consent","type":"\u0007","is_mandatory":true,"title":"Consent requirement","desc":"One of REQUIRED, IMPLICIT, or FLEXIBLE.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"default":{"name":"default","type":"\u0004","is_mandatory":true,"title":"Whether the scope is granted by default","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description shown on the consent prompt","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"displayName":{"name":"displayName","type":"\u0007","is_mandatory":true,"title":"Display name shown on the consent prompt","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Identifier of the scope","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"metadataPublish":{"name":"metadataPublish","type":"\u0007","is_mandatory":true,"title":"Whether the scope is published in discovery metadata","desc":"One of ALL_CLIENTS or NO_CLIENTS.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Programmatic name (e.g., openid, email, profile, custom:read)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"system":{"name":"system","type":"\u0004","is_mandatory":true,"title":"Whether the scope is system-managed","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Authorization Server Scope","desc":"OAuth 2.0 scope defined on a custom authorization server. The name is the programmatic value sent in `scope=` requests, consent controls whether the user is prompted to approve it, default marks scopes granted without being requested, and metadataPublish controls whether the scope appears in the `.well-known` discovery document.","private":true,"min_provider_version":"13.2.6","defaults":"name consent","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.behaviorRule":{"id":"okta.behaviorRule","name":"okta.behaviorRule","fields":{"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the rule was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the behavior rule","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the rule was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Display name of the behavior rule","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"settings":{"name":"settings","type":"\n","is_mandatory":true,"title":"Type-specific detection settings","desc":"Shape varies by `type`. Holds the thresholds and evaluation parameters for the behavior, such as the number of recent authentications retained for a location or device rule, or the velocity distance and time.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the rule: ACTIVE or INACTIVE","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Behavior rule type","desc":"The behavior evaluated, such as ANOMALOUS_DEVICE, ANOMALOUS_IP, ANOMALOUS_LOCATION, VELOCITY, or a new-factor rule like NEW_ASN, NEW_DEVICE, NEW_IP, NEW_CITY, NEW_STATE, NEW_COUNTRY, or NEW_GEO_LOCATION.","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Behavior Detection Rule","desc":"Rule that flags anomalous sign-in behavior so sign-on policies can require step-up authentication. Auditing behavior rules surfaces which risk signals the org detects: the `type` field selects the behavior evaluated (new device, new IP, new geolocation, or velocity), `settings` holds the type-specific thresholds, and `status` indicates whether the rule is active. Select a rule by its `name`.","private":true,"min_provider_version":"13.3.2","defaults":"name type status","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.customRole":{"id":"okta.customRole","name":"okta.customRole","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the custom role","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Identifier for the custom role","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"label":{"name":"label","type":"\u0007","is_mandatory":true,"title":"Name of the custom role","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"permissions":{"name":"permissions","type":"\u0019\u0007","title":"Permissions granted by the role","desc":"List of Okta permission identifiers this role confers, for example `okta.users.read`, `okta.users.manage`, `okta.apps.manage`, or `okta.groups.manage`. Permissions are a sub-resource of the role, fetched per role rather than returned with the role listing.","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Custom Role","desc":"Custom administrator role defined in an Okta organization, granting a tailored set of administrative privileges beyond the built-in standard roles. Auditing custom roles surfaces which fine-grained permissions each role confers, so you can catch over-privileged roles and enforce least privilege across delegated administration.","private":true,"min_provider_version":"9.1.1","defaults":"label","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.device":{"id":"okta.device","name":"okta.device","fields":{"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the device was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the device","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the device was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"profile":{"name":"profile","type":"\n","is_mandatory":true,"title":"Device hardware and OS attributes","desc":"Profile object with keys including `displayName`, `platform`, `manufacturer`, `model`, `osVersion`, `serialNumber`, `registered`, `secureHardwarePresent`, `diskEncryptionType`, and `integrityJailbreak`.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"resourceType":{"name":"resourceType","type":"\u0007","is_mandatory":true,"title":"Resource type of the device record","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Current lifecycle status of the device","desc":"One of CREATED, ACTIVE, SUSPENDED, DEACTIVATED, or UNENROLLED.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"users":{"name":"users","type":"\u0019\u001bokta.user","title":"Okta users that use this device","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Device","desc":"Device enrolled in the Okta org, tracked for device-trust and conditional access decisions. Auditing devices surfaces the endpoint population and its security posture: `profile` carries the hardware and OS attributes (platform, OS version, disk encryption, jailbreak state, secure hardware), `status` reflects the device lifecycle, and `users` lists the Okta accounts that use the device. Select a device by its `id`.","private":true,"min_provider_version":"13.3.2","defaults":"status","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.deviceAssurancePolicy":{"id":"okta.deviceAssurancePolicy","name":"okta.deviceAssurancePolicy","fields":{"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the policy was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the device assurance policy","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the policy was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Display name of the policy","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"platform":{"name":"platform","type":"\u0007","is_mandatory":true,"title":"Platform the policy applies to","desc":"One of ANDROID, IOS, MACOS, WINDOWS, or CHROMEOS.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"settings":{"name":"settings","type":"\n","is_mandatory":true,"title":"Required device-trust constraints","desc":"Shape varies by `platform`. Holds the enforced requirements such as `osVersion` (minimum version), `diskEncryptionType`, `screenLockType`, `jailbreak`, and `secureHardwarePresent`.","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Device Assurance Policy","desc":"Policy that defines the device-trust requirements an endpoint must meet to gain access, evaluated by sign-on policies. Auditing these confirms the minimum device posture the org enforces: the `platform` field selects the operating system the policy applies to, and `settings` holds the required constraints such as minimum OS version, disk encryption, screen lock, and secure-hardware or jailbreak checks. Select a policy by its `name`.","private":true,"min_provider_version":"13.3.2","defaults":"name platform","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.domain":{"id":"okta.domain","name":"okta.domain","fields":{"dnsRecords":{"name":"dnsRecords","type":"\u0019\n","is_mandatory":true,"title":"DNS records to publish for domain verification","desc":"One entry per required DNS record, each a dict with keys `fqdn` (the record name), `recordType` (TXT or CNAME), `values` (the values to set on the record), and `expiration` (when a TXT verification record expires).","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"domain":{"name":"domain","type":"\u0007","is_mandatory":true,"title":"Domain name","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Domain ID","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"publicCertificate":{"name":"publicCertificate","type":"\n","is_mandatory":true,"title":"TLS certificate metadata for the domain","desc":"Dict with keys `subject` (the certificate subject), `fingerprint` (the certificate fingerprint), and `expiration` (when the certificate expires).","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"validationStatus":{"name":"validationStatus","type":"\u0007","is_mandatory":true,"title":"Status of the domain: NOT_STARTED, IN_PROGRESS, VERIFIED, or COMPLETED","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Domain","desc":"Custom domain configured for an Okta organization so the sign-in and end-user experience is served under a branded hostname instead of the default Okta domain. The validationStatus field reports where the domain sits in the ownership-verification workflow (NOT_STARTED, IN_PROGRESS, VERIFIED, or COMPLETED), dnsRecords holds the DNS entries that must be published to prove control of the hostname, and publicCertificate carries the metadata for the TLS certificate that secures it.","private":true,"min_provider_version":"9.0.0","defaults":"domain","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.eventHook":{"id":"okta.eventHook","name":"okta.eventHook","fields":{"channelAuthScheme":{"name":"channelAuthScheme","type":"\n","is_mandatory":true,"title":"Authentication scheme for the destination","desc":"How Okta authenticates to the endpoint, as a dict with keys `type` (for example HEADER) and `key`. Secret values are not exposed.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"channelType":{"name":"channelType","type":"\u0007","is_mandatory":true,"title":"Delivery channel type (for example HTTP)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"channelUri":{"name":"channelUri","type":"\u0007","is_mandatory":true,"title":"Destination URL Okta posts events to","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the event hook was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the event hook","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"events":{"name":"events","type":"\u0019\u0007","is_mandatory":true,"title":"Subscribed event types","desc":"The Okta event types this hook fires on, for example `user.lifecycle.create` or `user.session.start`.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"headers":{"name":"headers","type":"\u0019\n","is_mandatory":true,"title":"Custom headers sent with each delivery","desc":"One entry per header, each a dict with keys `key` and `value`.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the event hook","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the event hook was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Display name of the event hook","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the event hook: ACTIVE or INACTIVE","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"verificationStatus":{"name":"verificationStatus","type":"\u0007","is_mandatory":true,"title":"Endpoint ownership verification status","desc":"Whether Okta has verified control of the destination endpoint, for example VERIFIED or UNVERIFIED.","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Event Hook","desc":"Outbound webhook that delivers Okta org events to an external service as they occur. Auditing event hooks surfaces where org activity is being sent and how the destination is trusted: `channelUri` is the endpoint Okta posts to, `channelAuthScheme` describes how Okta authenticates to it, `events` lists the subscribed event types, and `status` and `verificationStatus` indicate whether the hook is active and its endpoint ownership verified. A hook pointing at an untrusted URL is a data-exfiltration and persistence risk. Select a hook by its `name`.","private":true,"min_provider_version":"13.3.2","defaults":"name status","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.group":{"id":"okta.group","name":"okta.group","fields":{"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when group was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Group description","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique key for the group","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastMembershipUpdated":{"name":"lastMembershipUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when group's memberships were last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when group's profile was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"members":{"name":"members","type":"\u0019\u001bokta.user","title":"Group members","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Group name","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"profile":{"name":"profile","type":"\n","is_mandatory":true,"title":"Group profile properties","desc":"Profile object for the group with the keys `name` (the group's display name) and `description` (its free-form description). These same values are also surfaced directly as the `name` and `description` fields.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"roles":{"name":"roles","type":"\u0019\u001bokta.role","title":"Group roles","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"type":{"name":"type","type":"\n","is_mandatory":true,"title":"Group type","desc":"How the group's profile and memberships are managed. One of OKTA_GROUP (native Okta group with editable membership), APP_GROUP (sourced from and managed by an external application), or BUILT_IN (a group created and maintained by Okta, such as Everyone).","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Group","desc":"Okta group, the unit of access control that bundles users together to grant applications, administrator roles, and policies. Query groups to audit who has access to what: `members` lists the `okta.user` accounts in the group and `roles` lists the administrator roles assigned to it. The `type` field distinguishes Okta-native groups from app-sourced and built-in groups, and `lastMembershipUpdated` records when membership last changed.","private":true,"min_provider_version":"9.0.0","defaults":"name","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.groupRule":{"id":"okta.groupRule","name":"okta.groupRule","fields":{"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique key for the group rule","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Group rule name","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Group rule status","desc":"One of ACTIVE (the rule is running and applying memberships), INACTIVE (the rule is disabled), or INVALID.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Group rule type","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Group Rule","desc":"Group rule that automatically assigns users to groups based on expression conditions evaluated against user profile attributes. Rules run whenever a matching user is created or updated, so auditing them surfaces dynamic group memberships that grant access without an explicit assignment. Select a rule by its `name`, and check `status` to confirm whether the rule is actively applying memberships.","private":true,"min_provider_version":"9.1.1","defaults":"name","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.hookKey":{"id":"okta.hookKey","name":"okta.hookKey","fields":{"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the hook key was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the hook key","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"isUsed":{"name":"isUsed","type":"\u0004","is_mandatory":true,"title":"Whether the key is currently referenced by a hook","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"keyId":{"name":"keyId","type":"\u0007","is_mandatory":true,"title":"Public key identifier","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the hook key was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Display name of the hook key","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"publicKey":{"name":"publicKey","type":"\n","is_mandatory":true,"title":"Public key material","desc":"The public JSON Web Key as a dict, with keys such as `kty`, `kid`, `use`, `alg`, and the key parameters. The private key is never exposed.","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Hook Key","desc":"Cryptographic key pair Okta uses to sign outbound hook requests so the receiving service can verify they originate from Okta. Auditing hook keys surfaces stale or unused signing material: `isUsed` reports whether any hook currently references the key, and `publicKey` carries the public JSON Web Key metadata. Select a key by its `name`.","private":true,"min_provider_version":"13.3.2","defaults":"name isUsed","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.identityProvider":{"id":"okta.identityProvider","name":"okta.identityProvider","fields":{"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the identity provider was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the identity provider","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"issuerMode":{"name":"issuerMode","type":"\u0007","is_mandatory":true,"title":"Issuer mode for OIDC/SAML responses","desc":"One of ORG_URL, CUSTOM_URL_DOMAIN, or DYNAMIC.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"key":{"name":"key","type":"\u001bokta.identityProvider.key","title":"Okta Identity Provider signing key (JsonWebKey)","desc":"JsonWebKey trusted by Okta for verifying assertions or tokens from a federated identity provider. The `kid` selects the key, signing algorithm metadata (`alg`, `kty`, `use`, `keyOps`) describes how it is applied, and the embedded X.509 certificate chain (`x5c`) with SHA-1/SHA-256 thumbprints (`x5t`, `x5tS256`) plus the RSA modulus and exponent (`n`, `e`) carry the public credential. The `expiresAt` timestamp marks when the certificate must be rotated to keep federation working.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the identity provider was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Display name of the identity provider","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"policy":{"name":"policy","type":"\n","is_mandatory":true,"title":"Policy configuration","desc":"Includes account link policy (filter, action), provisioning policy (action, profile master, group assignments, conditions), subject matching (matchType, matchAttribute, filter), and maxClockSkew.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"protocol":{"name":"protocol","type":"\n","is_mandatory":true,"title":"Protocol configuration","desc":"Shape varies by `type`. Typical keys include: - type: SAML2, OIDC, OAUTH2, MTLS - endpoints: { authorization, token, userInfo, jwks, acs, sso, sloRedirect } - credentials: { client, signing, trust } - algorithms: { request, response } signing/encryption settings - scopes: requested OAuth/OIDC scopes - relayState: SAML relay-state format - settings: protocol-specific settings (nameFormat, honorForce, etc.)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"signingKeys":{"name":"signingKeys","type":"\u0019\u001bokta.identityProvider.key","title":"Signing key credentials trusted for assertions or tokens issued by this IdP","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the identity provider: ACTIVE or INACTIVE","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Type of identity provider","desc":"One of SAML2, OIDC, OAUTH2, GOOGLE, FACEBOOK, LINKEDIN, MICROSOFT, APPLE, X509, or other social/federation types Okta exposes.","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Identity Provider","desc":"External identity provider federated with your Okta organization for inbound single sign-on. The `type` discriminator (SAML2, OIDC, OAUTH2, GOOGLE, FACEBOOK, LINKEDIN, MICROSOFT, APPLE, X509) selects which protocol, credential, and policy shape applies, while `status` (ACTIVE or INACTIVE) indicates whether the federation is live and `issuerMode` records whether the issuer URL is the Okta org URL, a custom URL domain, or dynamic. Auditing these catches untrusted or misconfigured trust relationships that could let an attacker authenticate into the org. The `protocol` and `policy` configurations expose the endpoints, credentials, algorithms, and account-link/provisioning/subject-matching rules, and `signingKeys` returns the X.509/JWK credentials trusted for assertions or tokens issued by this IdP, where `expiresAt` flags expiring trust anchors.","private":true,"min_provider_version":"13.2.6","defaults":"name type status","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.identityProvider.key":{"id":"okta.identityProvider.key","name":"okta.identityProvider.key","fields":{"alg":{"name":"alg","type":"\u0007","is_mandatory":true,"title":"Algorithm used (e.g., RS256)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the key was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"e":{"name":"e","type":"\u0007","is_mandatory":true,"title":"RSA exponent","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"expiresAt":{"name":"expiresAt","type":"\t","is_mandatory":true,"title":"Timestamp when the key/certificate expires","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"identityProviderId":{"name":"identityProviderId","type":"\u0007","is_mandatory":true,"title":"ID of the identity provider this key belongs to","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"keyOps":{"name":"keyOps","type":"\u0019\u0007","is_mandatory":true,"title":"Permitted key operations","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"kid":{"name":"kid","type":"\u0007","is_mandatory":true,"title":"Key ID","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"kty":{"name":"kty","type":"\u0007","is_mandatory":true,"title":"Key type (e.g., RSA)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the key was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"n":{"name":"n","type":"\u0007","is_mandatory":true,"title":"RSA modulus","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the key (e.g., ACTIVE, INACTIVE, EXPIRED)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"use":{"name":"use","type":"\u0007","is_mandatory":true,"title":"Public key use (e.g., sig)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"x5c":{"name":"x5c","type":"\u0019\u0007","is_mandatory":true,"title":"X.509 certificate chain (PEM/DER without headers, base64-encoded)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"x5t":{"name":"x5t","type":"\u0007","is_mandatory":true,"title":"SHA-1 thumbprint of the X.509 certificate","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"x5tS256":{"name":"x5tS256","type":"\u0007","is_mandatory":true,"title":"SHA-256 thumbprint of the X.509 certificate","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Identity Provider signing key (JsonWebKey)","desc":"JsonWebKey trusted by Okta for verifying assertions or tokens from a federated identity provider. The `kid` selects the key, signing algorithm metadata (`alg`, `kty`, `use`, `keyOps`) describes how it is applied, and the embedded X.509 certificate chain (`x5c`) with SHA-1/SHA-256 thumbprints (`x5t`, `x5tS256`) plus the RSA modulus and exponent (`n`, `e`) carry the public credential. The `expiresAt` timestamp marks when the certificate must be rotated to keep federation working.","private":true,"min_provider_version":"13.2.6","defaults":"kid status expiresAt","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.inlineHook":{"id":"okta.inlineHook","name":"okta.inlineHook","fields":{"channelAuthScheme":{"name":"channelAuthScheme","type":"\n","is_mandatory":true,"title":"Authentication scheme for the endpoint","desc":"How Okta authenticates to the endpoint, as a dict with keys `type` (for example HEADER) and `key`. Secret values are not exposed.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"channelType":{"name":"channelType","type":"\u0007","is_mandatory":true,"title":"Delivery channel type (for example HTTP)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"channelUri":{"name":"channelUri","type":"\u0007","is_mandatory":true,"title":"Endpoint URL Okta calls during the flow","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the inline hook was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the inline hook","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the inline hook was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"metadata":{"name":"metadata","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Free-form metadata attached to the hook","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Display name of the inline hook","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the inline hook: ACTIVE or INACTIVE","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Inline hook type","desc":"The flow the hook participates in, for example `com.okta.oauth2.tokens.transform`, `com.okta.import.transform`, or `com.okta.user.pre-registration`.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"version":{"name":"version","type":"\u0007","is_mandatory":true,"title":"Version of the inline hook contract","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Inline Hook","desc":"Synchronous callout that lets an external service influence an Okta flow (such as token minting, registration, or password import) while it runs. Auditing inline hooks surfaces external code injected into authentication and provisioning: `channelUri` is the endpoint Okta calls, `channelAuthScheme` describes how Okta authenticates to it, and `type` identifies which flow the hook participates in. Select a hook by its `name`, and check `status` to confirm whether it is active.","private":true,"min_provider_version":"13.3.2","defaults":"name type status","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.logStream":{"id":"okta.logStream","name":"okta.logStream","fields":{"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the log stream was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the log stream","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the log stream was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Display name of the log stream","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"settings":{"name":"settings","type":"\n","is_mandatory":true,"title":"Destination settings","desc":"Shape varies by `type`. For AWS EventBridge the keys are `accountId`, `region`, and `eventSourceName`. For Splunk the keys are `host` and `edition`. Secret values such as the Splunk token are not exposed.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the log stream: ACTIVE or INACTIVE","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Log stream destination type","desc":"One of `aws_eventbridge` or `splunk_cloud_logstreaming`.","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Log Stream","desc":"Connection that exports Okta System Log events to an external destination such as AWS EventBridge or Splunk Cloud. Auditing log streams answers whether the org's audit trail is shipped off-box and to where: `type` selects the destination kind, `settings` carries the destination coordinates (AWS `accountId`, `region`, and `eventSourceName`, or Splunk `host` and `edition`), and `status` indicates whether the stream is active. Select a stream by its `name`.","private":true,"min_provider_version":"13.3.2","defaults":"name type status","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.network":{"id":"okta.network","name":"okta.network","fields":{"asns":{"name":"asns","type":"\u0019\u0007","is_mandatory":true,"title":"ISP ASNs for the network zone","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the network zone was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"gateways":{"name":"gateways","type":"\u0019\n","is_mandatory":true,"title":"IP address ranges that define this zone","desc":"Each entry has a `type` (CIDR or RANGE) and a `value` holding the IP address block or range.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier for the network zone","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the network zone was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"locations":{"name":"locations","type":"\u0019\n","is_mandatory":true,"title":"Geolocations that define a DYNAMIC zone","desc":"Each entry has a `country` (ISO-3166-1 alpha-2 code) and an optional `region` (ISO-3166-2 code) narrowing to a state or province.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name for the network zone","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"proxies":{"name":"proxies","type":"\u0019\n","is_mandatory":true,"title":"Trusted proxy addresses that may forward requests into this zone","desc":"Each entry has a `type` (CIDR or RANGE) and a `value` holding the IP address block or range.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"proxyType":{"name":"proxyType","type":"\u0007","is_mandatory":true,"title":"Proxy classification for a DYNAMIC zone","desc":"Category of anonymizing proxy the zone matches. One of Any, Tor, or NotTorAnonymizer. Empty for IP zones.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the network zone","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"system":{"name":"system","type":"\u0004","is_mandatory":true,"title":"Whether the network zone is system-managed (built-in and not user-editable)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Type of the network zone","desc":"One of IP (explicit gateway and proxy addresses) or DYNAMIC (matched by ASN, geolocation, or proxy classification).","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"usage":{"name":"usage","type":"\u0007","is_mandatory":true,"title":"Usage of zone: POLICY or BLOCKLIST","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Network Zone","desc":"Network zone that allows or blocks access based on IP address, ASN, or geolocation. Zones are referenced by policy and sign-on rule conditions to restrict access to known corporate networks, or used as a blocklist to deny traffic from named regions and anonymizing proxies. The `type` field distinguishes an IP zone (explicit gateway and proxy addresses) from a DYNAMIC zone (matched by ASN, geolocation, or proxy classification), and `usage` records whether the zone drives POLICY decisions or acts as a BLOCKLIST.","private":true,"min_provider_version":"9.0.0","defaults":"name type","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.organization":{"id":"okta.organization","name":"okta.organization","fields":{"address1":{"name":"address1","type":"\u0007","is_mandatory":true,"title":"Primary address of organization","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"address2":{"name":"address2","type":"\u0007","is_mandatory":true,"title":"Secondary address of organization","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"billingContact":{"name":"billingContact","type":"\u001bokta.user","title":"Billing contact of organization","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"city":{"name":"city","type":"\u0007","is_mandatory":true,"title":"City of organization","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"companyName":{"name":"companyName","type":"\u0007","is_mandatory":true,"title":"Name of the company","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"country":{"name":"country","type":"\u0007","is_mandatory":true,"title":"Country code of organization","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when organization was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"endUserSupportHelpURL":{"name":"endUserSupportHelpURL","type":"\u0007","is_mandatory":true,"title":"Support link of organization","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"expiresAt":{"name":"expiresAt","type":"\t","is_mandatory":true,"title":"Expiration of organization","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"ID of organization","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when org was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"optOutCommunicationEmails":{"name":"optOutCommunicationEmails","type":"\u0004","title":"Whether the organization's users receive Okta communication email","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"phoneNumber":{"name":"phoneNumber","type":"\u0007","is_mandatory":true,"title":"Phone number of organization","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"postalCode":{"name":"postalCode","type":"\u0007","is_mandatory":true,"title":"Postal code of organization","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"reportSuspiciousActivityEnabled":{"name":"reportSuspiciousActivityEnabled","type":"\u0004","title":"Whether users can report suspicious activity via email","min_provider_version":"13.2.9","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"securityNotificationEmails":{"name":"securityNotificationEmails","type":"\n","title":"Security notification email settings","desc":"Which end-user security notification emails the org sends, as a dict of booleans keyed by `sendEmailForNewDeviceEnabled`, `sendEmailForPasswordChangedEnabled`, `sendEmailForFactorEnrollmentEnabled`, `sendEmailForFactorResetEnabled`, and `reportSuspiciousActivityEnabled`. The same flags are also exposed as boolean fields of the same name on this resource.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"sendEmailForFactorEnrollmentEnabled":{"name":"sendEmailForFactorEnrollmentEnabled","type":"\u0004","title":"Whether a notification email is sent when a user enrolls a new MFA factor","min_provider_version":"13.2.9","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"sendEmailForFactorResetEnabled":{"name":"sendEmailForFactorResetEnabled","type":"\u0004","title":"Whether a notification email is sent when a user resets an MFA factor","min_provider_version":"13.2.9","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"sendEmailForNewDeviceEnabled":{"name":"sendEmailForNewDeviceEnabled","type":"\u0004","title":"Whether a notification email is sent when a user signs in from a new device","min_provider_version":"13.2.9","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"sendEmailForPasswordChangedEnabled":{"name":"sendEmailForPasswordChangedEnabled","type":"\u0004","title":"Whether a notification email is sent when a user's password is changed","min_provider_version":"13.2.9","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"State of organization","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of organization. Accepted values: ACTIVE, INACTIVE","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"subdomain":{"name":"subdomain","type":"\u0007","is_mandatory":true,"title":"Subdomain of organization","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"supportPhoneNumber":{"name":"supportPhoneNumber","type":"\u0007","is_mandatory":true,"title":"Support help phone of organization","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"technicalContact":{"name":"technicalContact","type":"\u001bokta.user","title":"Technical contact of organization","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"threatInsightSettings":{"name":"threatInsightSettings","type":"\u001bokta.threatsConfiguration","title":"Okta ThreatInsight settings","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"website":{"name":"website","type":"\u0007","is_mandatory":true,"title":"The organization's website","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Organization","desc":"Tenant-level settings for your Okta organization. Covers identity information such as `companyName`, `subdomain`, address, and contact details, along with operational fields like `status`, `created`, and `expiresAt`. The `billingContact` and `technicalContact` resolve to the `okta.user` records responsible for the org, `securityNotificationEmails` reports which end-user security emails the tenant sends, and `threatInsightSettings` exposes the Okta ThreatInsight configuration that blocks requests from suspicious IPs.","min_provider_version":"9.0.0","defaults":"companyName","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.policies":{"id":"okta.policies","name":"okta.policies","fields":{"accessPolicy":{"name":"accessPolicy","type":"\u0019\u001bokta.policy","title":"Access policies","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"idpDiscovery":{"name":"idpDiscovery","type":"\u0019\u001bokta.policy","title":"IDP discovery policies","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"mfaEnroll":{"name":"mfaEnroll","type":"\u0019\u001bokta.policy","title":"MFA policies","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"oauthAuthorizationPolicy":{"name":"oauthAuthorizationPolicy","type":"\u0019\u001bokta.policy","title":"OAuth authorization policies","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"password":{"name":"password","type":"\u0019\u001bokta.policy","title":"Password policies","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"profileEnrollment":{"name":"profileEnrollment","type":"\u0019\u001bokta.policy","title":"Profile enrollment policies","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"signOn":{"name":"signOn","type":"\u0019\u001bokta.policy","title":"Sign-on policies","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Policies","desc":"Policy collections that govern authentication and account security across an Okta organization, grouped by the behavior they control: password complexity and lockout, multifactor enrollment, sign-on and session conditions, OAuth authorization, identity-provider routing, application access, and self-service profile enrollment. Each collection returns `okta.policy` records whose rules define the conditions and actions, making this the entry point for auditing how sign-in, MFA, and password controls are enforced.","min_provider_version":"9.0.0","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.policy":{"id":"okta.policy","name":"okta.policy","fields":{"conditions":{"name":"conditions","type":"\n","is_mandatory":true,"title":"Policy conditions","desc":"Raw JSON describing when the policy applies, with keys that vary by policy type. Common keys include people (the groups and users the policy includes or excludes), network (the network zones the policy is scoped to), and authProvider.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the policy was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the policy","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Identifier of the policy","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the policy was last modified","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the policy","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"priority":{"name":"priority","type":"\u0005","is_mandatory":true,"title":"Priority of the policy","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"rules":{"name":"rules","type":"\u0019\u001bokta.policyRule","title":"Rules attached to the policy","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"settings":{"name":"settings","type":"\n","is_mandatory":true,"title":"Policy settings","desc":"Raw JSON holding the type-specific enforcement configuration, with keys that vary by policy type. For a PASSWORD policy the keys include password, recovery, and delegation; other types (MFA_ENROLL, ACCESS_POLICY, and so on) expose their own settings structure.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the policy: ACTIVE or INACTIVE","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"system":{"name":"system","type":"\u0004","is_mandatory":true,"title":"Whether the policy is system-managed (built-in and not user-editable)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Policy type","desc":"One of OKTA_SIGN_ON, PASSWORD, MFA_ENROLL, OAUTH_AUTHORIZATION_POLICY, IDP_DISCOVERY, ACCESS_POLICY, or PROFILE_ENROLLMENT.","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Policy","desc":"Policy governing authentication and access behavior in an Okta organization, such as password strength, MFA enrollment, sign-on enforcement, identity-provider routing, and app-level access. The type field selects the policy category (OKTA_SIGN_ON, PASSWORD, MFA_ENROLL, OAUTH_AUTHORIZATION_POLICY, IDP_DISCOVERY, ACCESS_POLICY, or PROFILE_ENROLLMENT), and the type-specific enforcement lives in conditions and settings. The rules field returns the ordered okta.policyRule records that refine when and how the policy applies.","private":true,"min_provider_version":"9.0.0","defaults":"name","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.policyRule":{"id":"okta.policyRule","name":"okta.policyRule","fields":{"actions":{"name":"actions","type":"\n","is_mandatory":true,"title":"Rule actions","desc":"Enforcement applied when the rule matches, as returned by Okta. The shape varies with `type`: sign-on rules carry a `signon` object (access ALLOW/DENY, factor requirements, and session limits), password rules carry `passwordChange`, `selfServicePasswordReset`, and `selfServiceUnlock`, MFA-enrollment rules carry `enroll`, and access policies carry an `appSignOn` object with the verification method.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"conditions":{"name":"conditions","type":"\n","is_mandatory":true,"title":"Rule conditions","desc":"Match criteria Okta evaluates for the rule, as returned by the API. The shape varies with `type`: common members include `people` (users and groups included or excluded), `network` (connection or zone constraints), `authContext` (authentication type), `platform` (device operating system and type), and `elCondition` (an Okta Expression Language expression).","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the rule was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Identifier of the rule","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the rule was last modified","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name of the rule","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"priority":{"name":"priority","type":"\u0005","is_mandatory":true,"title":"Priority of the rule","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the rule: ACTIVE or INACTIVE","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"system":{"name":"system","type":"\u0004","is_mandatory":true,"title":"Whether the rule is system-managed (built-in and not user-editable)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Rule type","desc":"Mirrors the type of the policy the rule belongs to. One of OKTA_SIGN_ON, PASSWORD, MFA_ENROLL, OAUTH_AUTHORIZATION_POLICY, IDP_DISCOVERY, ACCESS_POLICY, or PROFILE_ENROLLMENT.","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta policy rule","desc":"Rule within an Okta policy, evaluated in `priority` order so that the first rule whose `conditions` match applies its `actions`. Rules carry the enforced decisions behind a policy: required sign-on assurance, MFA enrollment, password constraints, and app-access outcomes. The `system` flag marks built-in rules that cannot be edited, and `status` reports whether the rule is ACTIVE or INACTIVE.","private":true,"min_provider_version":"9.0.0","defaults":"name","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.resourceSet":{"id":"okta.resourceSet","name":"okta.resourceSet","fields":{"binding":{"name":"binding","type":"\u001bokta.resourceSet.binding","title":"Okta resource set binding","desc":"Grant of a single custom administrator role to a set of members (users and groups), scoped to the parent resource set. Auditing bindings answers \"who was granted which custom admin role, and over which resources\": the `customRole` field resolves the granted role and its permissions, while `users` and `groups` list the members who hold it.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"bindings":{"name":"bindings","type":"\u0019\u001bokta.resourceSet.binding","title":"Custom-role grants (bindings) made through this set","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the resource set was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the resource set","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the resource set","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"label":{"name":"label","type":"\u0007","is_mandatory":true,"title":"Human-readable label of the resource set","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the resource set was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"resource":{"name":"resource","type":"\u001bokta.resourceSet.resource","title":"Resource covered by an Okta resource set","desc":"A single resource that a resource set grants administrative access over. The `href` field is the raw self-link identifying the target, `orn` is the parsed Okta Resource Name when available, and `group`, `application`, and `user` resolve the target to a modeled resource when its type is one of those. At most one typed reference is populated per resource; the others are null.","is_private":true,"provider":"go.mondoo.com/cnquery/v9/providers/okta","is_implicit_resource":true},"resources":{"name":"resources","type":"\u0019\u001bokta.resourceSet.resource","title":"Resources this set grants administrative access over","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Resource Set","desc":"Named collection of resources that a custom administrator role can be scoped to. Resource sets are the \"over what\" half of a custom admin grant: a binding ties a custom role to a set of members (users and groups) and the resource set limits the resources those members may administer. Select a set by its `label`. The `resources` field lists the groups, applications, and users the set covers, and `bindings` lists the custom-role grants made through it.","private":true,"min_provider_version":"13.3.2","defaults":"label","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.resourceSet.binding":{"id":"okta.resourceSet.binding","name":"okta.resourceSet.binding","fields":{"customRole":{"name":"customRole","type":"\u001bokta.customRole","title":"The custom role granted by this binding","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"groups":{"name":"groups","type":"\u0019\u001bokta.group","title":"Member groups granted the role over the resource set","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the binding (the granted role id within the set)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"users":{"name":"users","type":"\u0019\u001bokta.user","title":"Member users granted the role over the resource set","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta resource set binding","desc":"Grant of a single custom administrator role to a set of members (users and groups), scoped to the parent resource set. Auditing bindings answers \"who was granted which custom admin role, and over which resources\": the `customRole` field resolves the granted role and its permissions, while `users` and `groups` list the members who hold it.","private":true,"min_provider_version":"13.3.2","defaults":"id","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.resourceSet.resource":{"id":"okta.resourceSet.resource","name":"okta.resourceSet.resource","fields":{"application":{"name":"application","type":"\u001bokta.application","title":"Target application, when the resource is an application","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description of the resource","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"group":{"name":"group","type":"\u001bokta.group","title":"Target group, when the resource is a group","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"href":{"name":"href","type":"\u0007","is_mandatory":true,"title":"Raw self-link URL identifying the target resource","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the resource-set resource entry","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"orn":{"name":"orn","type":"\u0007","is_mandatory":true,"title":"Parsed Okta Resource Name (ORN) of the target, when available","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"user":{"name":"user","type":"\u001bokta.user","title":"Target user, when the resource is a user","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Resource covered by an Okta resource set","desc":"A single resource that a resource set grants administrative access over. The `href` field is the raw self-link identifying the target, `orn` is the parsed Okta Resource Name when available, and `group`, `application`, and `user` resolve the target to a modeled resource when its type is one of those. At most one typed reference is populated per resource; the others are null.","private":true,"min_provider_version":"13.3.2","defaults":"orn href","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.riskProvider":{"id":"okta.riskProvider","name":"okta.riskProvider","fields":{"action":{"name":"action","type":"\u0007","is_mandatory":true,"title":"How Okta consumes the provider's risk signal","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"clientId":{"name":"clientId","type":"\u0007","is_mandatory":true,"title":"OAuth 2.0 client identifier the provider authenticates as","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the risk provider was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the risk provider","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the risk provider was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Display name of the risk provider","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Risk Provider","desc":"Third-party service that feeds risk signals into Okta sign-on decisions. Auditing risk providers surfaces external inputs to authentication risk: `action` reports how Okta consumes the signal, and `clientId` identifies the OAuth 2.0 client the provider authenticates as. Select a provider by its `name`.","private":true,"min_provider_version":"13.3.2","defaults":"name action","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.role":{"id":"okta.role","name":"okta.role","fields":{"assignmentType":{"name":"assignmentType","type":"\u0007","is_mandatory":true,"title":"How the role is assigned","desc":"Either USER for a role assigned directly to a user, or GROUP for a role granted through group membership.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the role was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"customRole":{"name":"customRole","type":"\u001bokta.customRole","title":"Custom role definition","desc":"The custom role granting this assignment's permissions, resolved when `type` is CUSTOM_ROLE. Null for standard administrator roles.","min_provider_version":"13.3.2","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"group":{"name":"group","type":"\u001bokta.group","title":"Group the role was assigned to","desc":"The group this assignment was read from, set when the role is listed for a group. Null when the assignment was read from a user.","min_provider_version":"13.3.2","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"The identifier of the role","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"label":{"name":"label","type":"\u0007","is_mandatory":true,"title":"The label of the role","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the role was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"resourceSet":{"name":"resourceSet","type":"\u001bokta.resourceSet","title":"Resource set scoping this assignment","desc":"The set of resources a custom-role assignment is limited to. Null for standard administrator roles and for org-wide custom-role assignments.","min_provider_version":"13.3.2","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Activation status of the role assignment","desc":"Either ACTIVE or INACTIVE.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Permission scope of the role","desc":"Identifies the standard administrator role granting the privileges, such as SUPER_ADMIN, ORG_ADMIN, API_ADMIN, APP_ADMIN, USER_ADMIN, GROUP_MEMBERSHIP_ADMIN, MOBILE_ADMIN, HELP_DESK_ADMIN, REPORT_ADMIN, or READ_ONLY_ADMIN. A value of CUSTOM_ROLE indicates a custom role whose permissions are defined by the org.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"user":{"name":"user","type":"\u001bokta.user","title":"User the role was assigned to","desc":"The account this assignment was read from, set when the role is listed for a user. Null when the assignment was read from a group.","min_provider_version":"13.3.2","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta administrative role assigned to a user or group","desc":"Administrative role granting elevated privileges within an Okta org, as assigned to an individual user or to a group. Review this to audit who holds admin access and how broad it is: the `type` field names the permission scope (for example SUPER_ADMIN or a CUSTOM role), while `assignmentType` distinguishes a direct user assignment from one inherited through group membership.","private":true,"min_provider_version":"9.0.0","defaults":"label status","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.securityEventsProvider":{"id":"okta.securityEventsProvider","name":"okta.securityEventsProvider","fields":{"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the security events provider","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Display name of the provider","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"settings":{"name":"settings","type":"\n","is_mandatory":true,"title":"Signal endpoint settings","desc":"Dict with keys `issuer`, `jwks_url`, and `well_known_url` identifying the provider's security event stream and its signing keys.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the provider: ACTIVE or INACTIVE","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Provider type","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Security Events Provider","desc":"External provider that shares security signals with the Okta org through the Shared Signals Framework (SSF/CAEP), enabling continuous access evaluation. Auditing these surfaces the cross-vendor trust relationships feeding real-time security events: `type` identifies the provider, `settings` carries the signal endpoints (issuer, JWKS URL, and well-known configuration URL), and `status` indicates whether the integration is active. Select a provider by its `name`.","private":true,"min_provider_version":"13.3.2","defaults":"name type status","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.threatsConfiguration":{"id":"okta.threatsConfiguration","name":"okta.threatsConfiguration","fields":{"action":{"name":"action","type":"\u0007","is_mandatory":true,"title":"Action taken on requests from malicious IPs","desc":"One of none (ThreatInsight disabled), audit (log the request), or block (log and block the request).","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the ThreatInsight configuration was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"excludeZones":{"name":"excludeZones","type":"\u0019\u001bokta.network","is_mandatory":true,"title":"Exempt zones","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the ThreatInsight configuration was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta ThreatInsight Configuration","desc":"Organization-wide ThreatInsight settings that determine how Okta responds to requests from IP addresses with a known history of malicious activity. The `action` field selects whether such traffic is only logged or actively blocked, and `excludeZones` names the network zones exempt from ThreatInsight evaluation. Query this to confirm that threat detection is enforced and that no sensitive zones are wrongly exempted.","private":true,"min_provider_version":"9.0.0","defaults":"action","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.trustedOrigin":{"id":"okta.trustedOrigin","name":"okta.trustedOrigin","fields":{"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the trusted origin was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"createdBy":{"name":"createdBy","type":"\u0007","is_mandatory":true,"title":"ID of the entity that created the trusted origin","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier for the trusted origin","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the trusted origin was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdatedBy":{"name":"lastUpdatedBy","type":"\u0007","is_mandatory":true,"title":"ID of entity that last updated the trusted origin","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name for the trusted origin","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"origin":{"name":"origin","type":"\u0007","is_mandatory":true,"title":"Unique origin URL for the trusted origin","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"scopes":{"name":"scopes","type":"\u0019\n","is_mandatory":true,"title":"Interaction types this origin is trusted for","desc":"Each entry has `type` (the scope type: CORS, REDIRECT, or IFRAME_EMBED) and `allowedOktaApps` (for IFRAME_EMBED, the Okta apps permitted to embed Okta pages, for example OKTA_ENDUSER).","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the trusted origin","desc":"Either ACTIVE or INACTIVE.","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta Trusted Origin","desc":"Cross-origin URL that Okta trusts for browser-based interactions such as CORS requests, post-authentication redirects, and iframe embedding of Okta pages. Trusted origins define which external sites may call Okta APIs or receive redirects, so an overly broad or unexpected entry widens the surface for cross-site request forgery and data exfiltration. The `scopes` field records which interaction types each origin is trusted for.","private":true,"min_provider_version":"9.0.0","defaults":"name","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.user":{"id":"okta.user","name":"okta.user","fields":{"activated":{"name":"activated","type":"\t","is_mandatory":true,"title":"Timestamp when the user was activated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when user was created","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"credentials":{"name":"credentials","type":"\n","is_mandatory":true,"title":"User credential summary","desc":"Keys: provider ({ type, name } where type is one of OKTA, ACTIVE_DIRECTORY, LDAP, FEDERATION, SOCIAL, or IMPORT, indicating where the account is mastered), recovery_question ({ question }), and password (metadata such as hash or hook only, never the plaintext). Read provider.type to distinguish Okta-mastered accounts from externally sourced ones.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"factors":{"name":"factors","type":"\u0019\u001bokta.userFactor","title":"MFA factors enrolled by the user","min_provider_version":"13.1.6","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique key for user","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastLogin":{"name":"lastLogin","type":"\t","is_mandatory":true,"title":"Timestamp of last login","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when user was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"passwordChanged":{"name":"passwordChanged","type":"\t","is_mandatory":true,"title":"Timestamp when password last changed","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"profile":{"name":"profile","type":"\n","is_mandatory":true,"title":"User profile attributes","desc":"Standard Okta profile keys include login, email, firstName, lastName, and optionally secondEmail, mobilePhone, displayName, department, manager, and title, plus any custom attributes defined in the org's user schema. Select individual values with profile['email'] or profile['login'].","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"roles":{"name":"roles","type":"\u0019\u001bokta.role","title":"The roles assigned to the user","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Current lifecycle status of the user","desc":"One of STAGED, PROVISIONED, ACTIVE, RECOVERY, PASSWORD_EXPIRED, LOCKED_OUT, SUSPENDED, or DEPROVISIONED.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"statusChanged":{"name":"statusChanged","type":"\t","is_mandatory":true,"title":"Timestamp when status last changed","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"transitioningToStatus":{"name":"transitioningToStatus","type":"\u0007","is_mandatory":true,"title":"Target status of an in-progress asynchronous status transition","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"type":{"name":"type","type":"\n","is_mandatory":true,"title":"User type object","desc":"Carries the user-type `id`, plus any additional attributes the API returns for that type (name, displayName, description). The `typeId` field exposes the id value on its own.","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"typeId":{"name":"typeId","type":"\u0007","is_mandatory":true,"title":"User's type identifier","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta User","desc":"Individual account in the Okta identity store. The lifecycle fields (`status`, `activated`, `lastLogin`, `passwordChanged`) reveal dormant, suspended, or never-activated accounts, `roles` exposes privileged administrative grants, and `factors` shows which multi-factor methods the user has enrolled. Auditing users surfaces stale credentials, over-privileged accounts, and gaps in MFA coverage.","private":true,"min_provider_version":"9.0.0","defaults":"profile['email']","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"okta.userFactor":{"id":"okta.userFactor","name":"okta.userFactor","fields":{"created":{"name":"created","type":"\t","is_mandatory":true,"title":"Timestamp when the factor was enrolled","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"factorType":{"name":"factorType","type":"\u0007","is_mandatory":true,"title":"Type of factor (e.g., token:software:totp, push, sms, webauthn, email)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Unique identifier of the factor","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"lastUpdated":{"name":"lastUpdated","type":"\t","is_mandatory":true,"title":"Timestamp when the factor was last updated","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"profile":{"name":"profile","type":"\n","is_mandatory":true,"title":"Provider- and factor-type-specific profile data","desc":"Shape depends on factorType: - sms/call: { phoneNumber } - push: { name, platform, version, deviceType, ... } - webauthn: { credentialId, authenticatorName, ... } - token:software:totp: { credentialId } - question: { question, questionText }","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"provider":{"name":"provider","type":"\u0007","is_mandatory":true,"title":"Provider of the factor (e.g., OKTA, GOOGLE, RSA, SYMANTEC, DUO, FIDO, CUSTOM)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the factor (e.g., NOT_SETUP, ACTIVE, PENDING_ACTIVATION, DISABLED, EXPIRED)","provider":"go.mondoo.com/cnquery/v9/providers/okta"},"user":{"name":"user","type":"\u001bokta.user","title":"The user this factor belongs to","provider":"go.mondoo.com/cnquery/v9/providers/okta"}},"title":"Okta MFA factor enrolled by a user","desc":"Multi-factor authentication method registered against an Okta user account. The `factorType` identifies the method (TOTP, push, SMS, call, WebAuthn, FIDO, email, or security question), `provider` identifies who issues it (OKTA, GOOGLE, RSA, SYMANTEC, DUO, FIDO, CUSTOM), and `status` reflects its enrollment lifecycle. Query these to audit which users have strong MFA enrolled, flag weak or unverified factors (SMS, call, security question, or factors still in PENDING_ACTIVATION), and confirm that privileged accounts carry phishing-resistant WebAuthn or FIDO factors. The `profile` field carries the enrollment data specific to each factor type.","private":true,"min_provider_version":"13.1.6","defaults":"factorType status","provider":"go.mondoo.com/cnquery/v9/providers/okta"}}}