Skip to main content

Help us improve the Digital Marketplace - send your feedback

BECHTLE LIMITED

Okta Workforce Identity and Access Management

Okta Workforce Identity provides secure access for employees, contractors, and partners to internal applications and resources. Enabling seamless SSO, lifecycle management, and adaptive multifactor authentication. The platform integrates with existing directories and over 7,000 applications, ensuring high availability and compliance with UK government security standards for hybrid and remote work.

Features

  • AI-driven real-time detection and automated response to session hijacking
  • Continuous risk scanning and remediation of identity-related security vulnerabilities
  • Ephemeral, just-in-time infrastructure access without permanent standing privileges
  • Risk-based authentication using signals like location, device, and behavior
  • No-code automation for complex identity processes and logic-based tasks
  • Automated user provisioning via SCIM and HR system integrations
  • Unified login protection for macOS and Windows with passwordless sync
  • Secure remote access to legacy on-premises applications without VPN
  • Centralised access using 7,000+ pre-built SAML and OIDC integrations
  • Automated access requests, certifications, and comprehensive audit reporting

Benefits

  • Neutralises active threats across multi-vendor stacks during a session
  • Prevents breaches by identifying misconfigurations before attackers exploit them
  • Reduces attack surface by eliminating static credentials for critical servers
  • Balances high security with low friction for public sector workers
  • Customises complex joiner-mover-leaver processes without expensive custom coding
  • Ensures immediate deprovisioning to prevent unauthorized access by former staff
  • Extends Zero Trust security to the physical workstation login layer
  • Facilitates legacy system modernisation and cloud migration at lower cost
  • Eliminates vendor lock-in by supporting any app, not just Microsoft
  • Meets stringent UK government compliance and regulatory audit requirements

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at publicsector.uk@bechtle.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 7 0 8 7 9 8 1 3 6 5 5 8 8 9

Contact

BECHTLE LIMITED Public Sector
Telephone: 01249 467900
Email: publicsector.uk@bechtle.com

About your service

Service categories

Systems Infrastructure Software

Security

  • Security analytics
  • Governance, risk and compliance

Identity and access management

  • Access
  • Privilege
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Integration catalogue: https://www.okta.com/integrations/
Supporting standards based single sign-on and user provisioning
Non-exhaustive examples:
HCM/HR - Workday, SAP Successfactors
Collaboration software - MS Office 365, Google Workspace, Zoom, Slack
Zero Trust - Proofpoint, Crowdstrike, Zscaler
ITSM - ServiceNow, Remedy, Jira
CRM - Salesforce, Dynamics, Zoho
Platforms - AWS, GCP, Azure, VMWare
Cloud deployment model
Public cloud
Service constraints
N/A
System requirements
Appropriate Licensing and access for integration configurations

User support

Email or online ticketing support
Yes
Support response times
The Premier Success Plans offer varying response times based on priority level and plan:
Basic (24/5 Support): P1 (Critical) issues receive a response within 2 hours. P2 (Urgent) is 12 hours, while P3 (High) and P4 (Low) are both 24 hours.
Silver (24/7 Support): This plan guarantees a P1 response time of 1 hour. P2 (Urgent) is 2 hours, P3 (High) is 8 hours, and P4 (Low) remains 24 hours.
Gold (24/7 Support): The fastest service level, providing a P1 response within 30 minutes. P2 (Urgent) response time is 1 hour, P3 (High) is 4hours, and P4 (Low) is 24hours
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AAA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
Okta Premier Success Plans
Okta offers three tiers of Premier Success Plans:

Basic (Included for less than $20K ARR) : Provides access to public training and the Support Center. Support is available 24/5 online. The fastest response time (P1/Critical) is 2 hours.

Silver (15% of ARR, $20K–$200K spend) : Offers 24/7 support and includes customized recommendations and self-guided resources. It features one Expert Learning Pass and 10% off training , plus one Oktane pass. P1 response time is 1 hour.

Gold (25% of ARR, required for $200K+ spend) : Focuses on personalized engagements with success planning and roadmap alignment. It provides business and technical guidance from specialized experts. The plan includes six Expert Learning Passes (20% off additional training) and two Oktane passes. It features the fastest support , with a P1 response time of 30 minutes.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
OKta has a video series dedicated to getting started and learning identity. In addition, OKta has documentation and quickstarts to help get started with the product. If on-site training is required, professional services can be available as a package. Okta customers depending on level of service will also have Customer Success Managers or Technical Account Managers assigned to ensure success. Okta also has a comprehensive learning certification portfolio.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
APIs can be ustilised to extract any data required at any time.
End-of-contract process
At the end-of-contract the plan automatically gets converted into Free plan with limited features and support.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The Okta web portal is browser based for both types of devices so only differences will be between the device display properties. The Okta mobile application is available at no extra cost.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Okta has many ways to interact, including a web dashboard. The web dashboard is utilised by users to open assigned applications using Okta initiated single sign on (including multi factor). Administrators will use the web interface to do CRUD (Create, Read, Update, Deactivate) of users and groups as well as setup application connections and configure authentication and multifactor policies.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Not Applicable.
API
Yes
What users can and can't do using the API
OKta implements an API first strategy across the platform to provide extensive APIs for authentication and the management of the tenant. The Authentication API exposes Okta identity functionality, as well as those of supported identity protocols (such as OpenID Connect, OAuth, and SAML).
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Okta offers a very customizable & extensible solution where customers can bring their own business logic and branding.
To name a few points, OKta allows you to customize the look & feel of the Login; Pick and choose MFA factors; Integrate with any Identity Provider that leverages open standards like OIDC, OAuth2.0, SAML, WSFED; Customize the authentication and authorization pipeline.

Scaling

Independence of resources
Being able to scale is only one part of the equation. Today’s users expect a seamless experience while IT adapts to an increasing demand. Interruptions and downtime can severely hurt organization’s productivity. Okta is built to handle this challenge with a guaranteed 99.9% uptime, and zero planned downtime. Furthermore, Okta has maintained a 100% global uptime in the last 2 years, with no major service disruption, as it scaled 640% in the amount of authentications per month it needed to handle. Okta is never taken offline for updates or maintenance.

Analytics

Service usage metrics
Yes
Metrics types
Okta’s Enterprise Workforce Suite delivers factual, real-time usage metrics essential for UK Government reporting:

Identity Threat Protection: AI-driven logs track session-based risk signals, authentication events, and automated remediation actions (e.g., universal logout).

Identity Security Posture: Reports identify misconfigurations, over-privileged admins, and "orphan" accounts, mapping risks to NIST/ISO standards.

Privileged Access: Detailed audit trails capture just-in-time session activity, vault access, and SSH/RDP session recordings via the pam namespace in the System Log.

Workflows: Provides real-time execution log streaming (SIEM integration) and 30-day historical analysis of flow status, latency, and resource consumption.

Lifecycle Management: Audits automated provisioning/deprovisioning velocity and SCIM-driven account changes.
Reporting types
API access
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Okta Workforce Identity and Access Management

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Other
Other data at rest protection approach
Stored data are encrypted using AES and a 256-bit encryption key specifically created for the customer tenant (with each customer assigned their own). The tenant master keys are themselves encrypted with a master key stored within Amazon's Key Management Service (KMS).
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
Users can export data in CSV or JSON
Data export formats
  • CSV
  • Other
Other data export formats
JSON
Data import formats
  • CSV
  • Other
Other data import formats
JSON

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
99.99%
Approach to resilience
Okta leverages Amazon Web Services (AWS) for our infrastructure-as-a-service (IaaS) and hosting environment. By utilizing AWS' EC2 and S3 environments, Okta has access to virtually unlimited capacity, which enables utilization of multiple AWS availability zones , with each zone being equivalent to one or more physical, tier-4 data centers , across multiple distinct geographical compute regions. Okta maintains high availability among virtual instances within each availability zone, as well as across zones. Operational details of how Okta leverages AWS for hot standby are included in our SOC2 Type II report.
 
Amazon information on regions and availability zones:  https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-regions-availability-zones.html

How Okta Builds and Runs Scalable Architecture: https://www.okta.com/resources/whitepaper/how-okta-builds-and-runs-scalable-infrastructure/

Okta's High Availability Architecture Whitepaper: 
https://www.okta.com/sites/default/files/2022-09/Okta%20High%20Availability%20Architecture_Whitepaper.pdf
Outage reporting
The service is designed to be highly available with zero down time. When outages are experienced, customer are notified and updated via email and through help desk announcements until the service is back up and running. If there is a workaround available to reduce the outage risk, Okta's Customer Support team will proactively inform customers about such options. Information is always available at https://status.okta.com/

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Only Okta’s technical operations team can access the production environment. This is secured via IP allow-lists, encrypted VPNs, and SSH key pairs, with mandatory hardware MFA (e.g., YubiKey).

Customer support has exclusive access to a limited impersonation tool for troubleshooting. This feature allows support to navigate administrative dashboards but prohibits authenticating into downstream applications. Usage requires customer initiation, ensuring they maintain data control. All actions are logged and audited. For details on granting access, refer to Okta’s documentation.
Access restriction testing frequency
At least once a year
Management access authentication
Multi-Factor Authentication (MFA)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
Between 1 month and 6 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
Between 1 month and 6 months
How long system logs are stored for
Between 1 month and 6 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Okta's current security certifications and policies are always available on Okta's Security Trust Center at https://security.okta.com 
This resource provides comprehensive information and documents detailing Okta and Auth0's security, compliance, and robust security framework.
Information security policies and processes
Okta's information security policy is based on best practices, such as AICPA Trust Services Principles and Criteria, ISO 27001:2022, ISO 27017:2015, ISO 27018:2019, and NIST's Cloud Computing Matrix. The policy covers key areas, such as information classification policy, data handling, encryption, acceptable use, change management, and network security. This policy document can be provided to prospects under NDA. The fidelity and efficacy of the policies outlined in this document are audited and attested to in Okta and Auth0 SOC2 Type II reports, which can also be provided to prospects under NDA.

Okta's information security policies and procedures are available in our internal wiki pages, accessible to all employees. Employees are required to sign an agreement to acknowledge having received and reviewed the information security policy. Security and privacy awareness training is conducted annually and is mandatory for all employees.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
The Service maintains documented application and infrastructure change management policies and procedures to communicate company’s expectations regarding the change management process to Okta personnel, and to ensure any unauthorized changes are not made to production systems. Engineering teams meet in weekly planning and daily stand-ups to discuss and communicate current and upcoming changes and their effects on the system. The change management process adds oversight, visibility, and control of changes to the Okta environment.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
If a potential vulnerability is identified, it is triaged among the security, engineering, and technical operations teams. Okta Security employs a risk ranking system for technical vulnerabilities which accounts for published risk rankings within the Okta environment. Critical- and high-risk issues are addressed as quickly as possible within the context of business feasibility. Okta has formal vulnerability management procedures that detail how Okta identifies, manages and remediates vulnerabilities. This document is available to prospects under NDA and current customers under contract via our Security Trust Center at security.okta.com
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
As a normal course of business, Okta monitors for and responds to broad attacks that impact Okta's services. Okta utilizes a number of monitoring tools with centralised logging and SIEM using our own correlation rules for security monitoring, analysis, and alerting. Okta monitors all outbound traffic from our production environment for anomalies using both proprietary and commercial traffic monitoring and intrusion detection systems.
Incident management type
Supplier-defined controls
Incident management approach
Okta has a formally documented Cyber Security Incident Response Plan that describes the processes and procedures that Okta follows to respond to, remediate and resolve a security incident involving a potential or actual compromise of Company Information or Okta system. It includes discovery, investigation, escalation, containment, notification, documentation and evidence chain-of-custody controls.

Okta's IRP is tested at least annually and is available to prospects under NDA.

Security breach and/or incident notifications go out to impacted customers via email. Notifications are delivered to customers in accordance with their MSA.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
The Integrator Free Plan provides a non-production sandbox for development and testing. It includes access to SSO, MFA, Universal Directory, and Lifecycle Management for up to 10 active users and 5 Workflows. It excludes technical support, custom email templates, and production SLAs. Access expires after 180 days of inactivity.
Link to free trial
https://www.okta.com/uk/free-trial/

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0.01%
Between £250,000 and £500,000
0.01%
Between £500,001 and £1,000,000
0.5%
Between £1,000,001 and £2,500,000
0.5%
Between £2,500,001 and £5,000,000
1%
Over £5,000,001
2%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Assessment Bureau
ISO/IEC 27001 accreditation date
Tuesday 4 February 2025
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
British Assessment Bureau
ISO 9001 accreditation date
Tuesday 4 February 2025
What the ISO 9001 doesn’t cover
N/A
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
1558ec47-32b1-40ed-b801-d45188947349
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
96b7d157-8818-433b-b7f5-60dfc598a1ec
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at publicsector.uk@bechtle.com. Tell them what format you need. It will help if you say what assistive technology you use.