Oktaã®å°å ¥äºä¾ãã¦ã¼ã¹ã±ã¼ã¹å¥ã«ãç´¹ä»
Okta Japanæ ªå¼ä¼ç¤¾ãã·ãã¢ã½ãªã¥ã¼ã·ã§ã³ã¨ã³ã¸ãã¢ ç³æ© ç¦å²
Oktaã®5ã¤ã®å°å ¥äºä¾ãéãã¦ããããããã©ã®ãããªèª²é¡ããã£ãã®ãããOktaã課é¡è§£æ±ºã«ã©ãå½¹ç«ã£ãããã«ã¤ãã¦ãç´¹ä»ããã¦é ãã¾ããã¦ã¼ã¹ã±ã¼ã¹ã§è¦ãOktaã®æ´»ç¨æ¹æ³ãã覧ãã ããã
å°å ¥äºä¾1ï¼å ¼åã¢ã«ã¦ã³ãã®ç®¡ç
ãã®ã¦ã¼ã¶ä¼æ¥ã§ã¯é¢é£ä¼ç¤¾ã¨ã®éã§åºåçãããã主åã¨å ¼åãããç°å¢ã§ãããæ¥åã¢ããªã±ã¼ã·ã§ã³ãèªåãæ¬æ¥æå±ããä¼ç¤¾ã®ã¡ã¼ã«ã¢ãã¬ã¹çãå©ç¨ãã¦ã·ã³ã°ã«ãµã¤ã³ãªã³ï¼SSOï¼ã§å©ç¨ãã䏿¹ãåºåå ã®é¢é£ä¼ç¤¾ã§ãã¢ããªã±ã¼ã·ã§ã³ãå©ç¨ãããã¨ãããããã®å ´åã¯é¢é£ä¼ç¤¾ã®ã¡ã¼ã«ã¢ãã¬ã¹ã§ã·ã¹ãã ã«ãã°ã¤ã³ãããã¨ã«ãªãã¾ããã¤ã¾ããä¸äººã®ã¦ã¼ã¶ãè¤æ°ã®IDã使ãåããå¿ è¦ãããç°å¢ã§ããã
Oktaã§ã¯Application Username Formatã¨å¼ãã§ãã¾ãããã¦ã¼ã¶ã®ã屿§å¤ããèªç±ã«æ¸ãæãï¼å å·¥ãããã¨ã§ç¹å®ã®ã¢ããªã±ã¼ã·ã§ã³ã«ãã°ã¤ã³ããéã®ã¦ã¼ã¶åã使ãåãããã¨ãã§ãã¾ããå å·¥ã®ããã®è¨èªã§ããExpression Languageãæ´»ç¨ãããåºåå ã®ã¢ããªã±ã¼ã·ã§ã³ã使ãéã«ã¯Oktaã«æ ¼ç´ããã¦ãã屿§å¤ãå å·¥ãã¦åºåå ã®å½¢å¼ã«åãããã¦ã¼ã¶åã«æ¸ãæãã¦ãã°ã¤ã³ãããã¨ããå¦çãå®ç¾ã§ãã¾ãã
ããã«ãOktaã§ã¯ã¦ã¼ã¶ã®å±æ§ã«åºã¥ãã¦èªåçã«ã°ã«ã¼ããå²ãå½ã¦ããã¨ãã§ããã®ã§ãå ¼åã«é¢ãã屿§å¤ã®æ å ±ããåºåå ã®ã¢ããªã±ã¼ã·ã§ã³ãå©ç¨ããããã®ã°ã«ã¼ããèªåçã«å²ãå½ã¦ããã¾ãã
å©ç¨ãã¦ããã©ã¤ã»ã³ã¹ã¯Single Sign-Onã¨Universal Directoryã§ãããã³ãã¬ã¼ããå©ç¨ããSSOæ¥ç¶ãããExpression Languageã§å©ç¨ã¢ããªã®ã¦ã¼ã¶åãå å·¥ããã屿§å¤ãå ã«ããèªåã°ã«ã¼ãå²ãå½ã¦ãããCustom Attributeã§ç¬èªã®å±æ§ã使ãã¨ãã£ãæ©è½ãæ´»ç¨ãã¦ãã¾ãã
å°å ¥äºä¾2ï¼ç¤¾å¤ã¦ã¼ã¶ç®¡ç
ãã®äºä¾ã¯ITã§ã¯ãªãéçºã«æºããäºæ¥é¨éãç¬èªã«ã¦ã¼ã¶ç®¡çãå®è¡ããä¾ã§ããéçºæ¥åã®é½åä¸ã社å¤ã®ååä¼ç¤¾ããã¼ããã¼ä¼æ¥ã®äººæãå«ãããã¼ã ãæ§æããå½¢ã«ãªãã¾ãããITé¨éã管çãã社å¡ãã¼ã¿ãã¼ã¹ï¼Active Directoryï¼ã«ã¯ç¤¾å¤ã®äººæãå«ãããã¨ãã§ããªãã®ã§ã代ããã«éçºäºæ¥é¨ãç¬èªã«Oktaãæ´»ç¨ããITé¨éãæã¤ç¤¾å¡ãã¼ã¿ãã¼ã¹ãã社å¡ã«é¢ããæ å ±ãèªååæããããã«ååä¼ç¤¾çããã®ããã¸ã§ã¯ãåå ã¡ã³ãã¼ã®ãªã¹ããOktaã«ç»é²ãããã¨ã§ããã¸ã§ã¯ãæéä¸ã®ã¢ã¯ã»ã¹ç®¡çãå®ç¾ãã¦ãã¾ãã
ã¡ã¼ã«ã¢ãã¬ã¹ã®ãã¡ã¤ã³çããã©ãã©ãªç¤¾å¤ã®ã¹ã¿ããã¨ç¤¾å¡ã1ã¤ã®èªè¨¼åºç¤ã«ã¾ã¨ãã社å¡ã¨ç¤¾å¤ã¹ã¿ãããããããå¥ã®ã°ã«ã¼ãã«ããã¨ãã£ãå½¢ã«ãã¦ãã¾ããããã¸ã§ã¯ãæéä¸ã¯éçºã«ä½¿ç¨ããã¢ããªã±ã¼ã·ã§ã³ã®ã¢ã«ã¦ã³ããèªåãããã¸ã§ãã³ã°ãã¦å©ç¨æ¨©ãä»ä¸ãã䏿¹ãããã¸ã§ã¯ãæéãçµäºãããå³ã¢ã¯ã»ã¹æ¨©ã忢ããã»ãã¥ãªãã£ãªã¹ã¯ãçããªãããã«ç®¡çãã¦ãã¾ãã
使ç¨ã©ã¤ã»ã³ã¹ã¯ãSingle Sign-OnãUniversal DirectoryãLifecycle ManagementãAdvanced Lifecycle Managementã§ãActive Directoryããã®èªåã¦ã¼ã¶ã¼åæããããã¸ã§ãã³ã°ï¼ããããã¸ã§ãã³ã°ã®èªååã¨ãã£ãæ©è½ãæ´»ç¨ããã¦ããä¾ã§ãã
å°å ¥äºä¾3ï¼IDã®éç´
ããè¤éãªç°å¢ãéç¨ããã¦ã¼ã¶ä¼æ¥ã®äºä¾ã§ãä¸çä¸ã«æ ç¹ãå±éããã¦ãããè²·å伿¥ãªã©ãããããã«è¤æ°ã®IDæ å ±ãæ£å¨ããå½¢ã«ãªã£ã¦ãã¾ããã人äºãã¹ã¿ã¼ã¨ãã¦SaaSï¼Workdayï¼ã«æ å ±ã®éç´ãè¡ãªã£ã¦ããã¨ããã§ããããè²·åç´å¾ã®ä¼æ¥ã«é¢ãã¦ã¯åãè¾¼ãã¦ããªããªã©ãIDã®ãã¹ã¿ç®¡çã¯ãã©ãã©ã§ããã
Oktaã§ã¯äººäºã·ã¹ãã ã§ããWorkdayã¨ç´æ¥é£æºãå¯è½ãªã®ã§ãActive Directoryãªã©ãä»ãããã¨ãªã人äºã·ã¹ãã ããç´æ¥æ å ±ãOktaã«åãè¾¼ãã§ãã¾ããã¾ã 人äºã·ã¹ãã ã«å·»ãåãã¦ããªãæ£å¨ããäººäºæ å ±ã¯ãåæ ç¹ã®Active Directoryãªã©ããåãè¾¼ãå½¢ã§ãã
ãã®ã¦ã¼ã¶ä¼æ¥ã§ã¯ãªã³ãã¬ãã¹ã®Active Directoryã¯å»æ¢ãã¦Workdayã«ä¸æ¬åãããã¨ãã叿ããã£ãã®ã§ãWorkdayããOktaã«åãè¾¼ãã ã¢ã¤ãã³ãã£ãã£æ å ±ãå ã«ã¯ã©ã¦ãã¨ãªã³ãã¬ãã¹ã®ãã¤ããªããç°å¢ã§ã·ã³ã°ã«ãµã¤ã³ãªã³ãå¤è¦ç´ èªè¨¼ãå®ç¾ãããã«Oktaã®Workflowsãæ´»ç¨ãã¦æå®ãããæ¥æã§ã®ãªã³ãã¼ãã£ã³ã°ï¼ãªããã¼ãã£ã³ã°ã宿½ãã¦ãããå ¥ç¤¾ã®æç¹ã§å種ã¢ããªã±ã¼ã·ã§ã³ã®ã¢ã«ã¦ã³ããæºåããéè·ããéã«ã¯ã¢ã«ã¦ã³ãã®åé¤ãèªååãã¦ãã¾ãã
使ç¨ã©ã¤ã»ã³ã¹ã¯ãSingle Sign-OnãMulti-factor AuthenticationãAccess GatewayãUniversal DirectoryãLifecycle ManagementãLifecycle Management Advanced Sourcingã§ãå¤è¦ç´ èªè¨¼ã¨ãã¦FIDO2ã«åºã¥ãçä½èªè¨¼ãæ´»ç¨ãã¾ããã§ãã¬ã¼ã·ã§ã³ã«å¯¾å¿ãã¦ããªããªã³ãã¬ãã¹ã»ã¢ããªã±ã¼ã·ã§ã³ã«å¯¾ããSSOã®ããã«Access Gatewayãæ´»ç¨ããã¦ãã¾ãã
å°å ¥äºä¾4ï¼Azure ADã¨ã®ä½µç¨
ãã®äºä¾ã¯ãæ¢ã«Azure ADãéç¨ãã¦ããã¦ã¼ã¶ä¼æ¥ã§ãAzure ADã¨Oktaã飿ºãããä¾ã§ããæ¢åã®Azure ADãèªè¨¼åºç¤ã¨ãã¦ãã®ã¾ã¾æ´»ç¨ããã·ã³ã°ã«ãµã¤ã³ãªã³ãå¤è¦ç´ èªè¨¼ãIDï¼ãã¹ã¯ã¼ããªã©ãç¾ç¶ã®ã¦ã¼ã¶ä½é¨ã¯å¤æ´ãããã®ã¾ã¾Azure ADã§å®è¡ãã䏿¹ãã¢ã«ã¦ã³ãã®åæãæå®æ¥æã§ã®ãããã¸ã§ãã³ã°ã屿§å¤ã®ãããã³ã°ãIDã®æ£å¸ããªã©ãã¢ã¤ãã³ãã£ãã£ã«é¢é£ããç´°ããæä½ã«é¢ãã¦ã¯Oktaãåªãã¦ããã¨ãããã¨ã§ãOktaã¨Azure ADãä½µç¨ããå½¢ã¨ãã¦ãã¾ãã
ã¦ã¼ã¶ãããã¾ã§éãã«åã¢ããªã±ã¼ã·ã§ã³ã«å¯¾ãã¦ã¢ã¯ã»ã¹ãè¡ãªãã¨Oktaãã¦ã¼ã¶ã®IDã屿§æ å ±ããã§ãã¯ããèªè¨¼ãè¡ãªãAzure ADãæ±ºå®ãã¦ã«ã¼ãã£ã³ã°ãã¾ããèªè¨¼ã®ããã¨ãã¦Oktaãæ´»ç¨ããã¦ããå½¢ã§ããã¦ã¼ã¶ããã¯ããã¾ã§éãã®UXã§ã¢ããªã±ã¼ã·ã§ã³ãå©ç¨ã§ããéç¨ç®¡çè ã¯Oktaã®ããç´°ããªã¢ã¤ãã³ãã£ãã£ç®¡çæ©è½ãæ´»ç¨ã§ããããã«ãªãã¾ãã
使ç¨ã©ã¤ã»ã³ã¹ã¯ãSingle Sign-OnãUniversal DirectoryãLifecycle ManagementãWorkflowsã§ãæ©è½é¢ã§ã¯IdP Discoveryãæ´»ç¨ãã¦ã¦ã¼ã¶ã®ãã¡ã¤ã³ã屿§å¤ãªã©ã«åºã¥ãã¦è»¢éå ã®Azure ADãæ±ºå®ããããDirectory Integrationã§Active Directoryããèªåã§ã¦ã¼ã¶åæãè¡ãªããªã©ã®AD飿ºããProvisioningã«ããã¢ã«ã¦ã³ãã®èªå使ï¼å¤æ´ï¼åæ¢ãWorkflowsã§åæ¢ãããã¢ã«ã¦ã³ãã®å®å ¨åé¤ããOktaå´ã§ä¿æãã¦ããåã¢ããªã±ã¼ã·ã§ã³æ¯ã®ã¢ã¯ã»ã¹ãã°æ å ±ãå ã«ä¸å®æéã¢ããªã±ã¼ã·ã§ã³ã®å©ç¨å®ç¸¾ããªãã¦ã¼ã¶ãæ½åºãã¦ã¢ã«ã¦ã³ãã®åé¤ããããªããªã©ã®èªååãå®è£ ãã¦ãã¾ãã
å°å ¥äºä¾5ï¼ã°ãã¼ãã«IDçµ±å
æå¾ã®äºä¾ã¯ã°ãã¼ãã«å±éãã¦ããå¤§è¦æ¨¡ãªã¦ã¼ã¶ä¼æ¥ã§ãåæ ç¹æ¯ã«ç¬èªã«å¥ç´ãã¦ããã¢ããªã±ã¼ã·ã§ã³ãå©ç¨ãã¤ã¤ãå ¨ç¤¾å ±éã§å¥ç´ãã¦ããã°ãã¼ãã«å ±éã¢ããªã±ã¼ã·ã§ã³ã使ãããã«èªè¨¼åºç¤ããã¾ã使ãåããã¨ãããã¼ãºãããHub & Spokeãæ´»ç¨ããä¾ã¨ãªãã¾ãã
åæ ç¹ã§å©ç¨ããã¦ããOktaï¼Spokeï¼ã¨å ¨ç¤¾å ±éã®Oktaï¼Hubï¼ã®éã¯ç°¡åã«ã¦ã¼ã¶åæãã§ããä»çµã¿ã«ãªã£ã¦ãã¾ãããªããå¤ãã®æ ç¹ã§ã¯Active Directoryãã¦ã¼ã¶æ å ±ã®ãã¹ã¿ã¨ãªã£ã¦ãã¾ãããä¸é¨æ ç¹ã§ã¯ç¬èªã®ã¦ã¼ã¶æ å ±ãã¹ã¿ãéç¨ãã¦ãããããããããæ å ±ãCSVã§æ½åºãã¦Spokeã®Oktaã«èªåã§åãè¾¼ãä»çµã¿ãæ§ç¯ãã¦ãã¾ãã
ãªããå¤§è¦æ¨¡ç°å¢ãªãã§ã¯ã®æ¸å¿µã¨ãã¦ãåããããªååã®äººã®IDãéè¤ãã¦ãã¾ãå¯è½æ§ããã£ããããHubã§ã®å ±éã¢ããªã±ã¼ã·ã§ã³ã®ã¢ã«ã¦ã³ãã®ãããã¸ã§ãã³ã°ã®éã«IDã®éè¤ãæ¤åºãããå ´åã¯Workflowsã使ã£ã¦éè¤ããªãIDã«ä»ãæ¿ããã¨ããå¦çãçµã¿è¾¼ãã§ãã¾ããã¾ãã管çè æ¨©éã«é¢ãã¦ã¯åæ ç¹ã«Spokeã®ç®¡çãä»»ãã䏿¹ãå ¨æ ç¹å ±éã§ã¯ãªãæ ç¹æ¯ã®ç¶æ³ãè¸ã¾ãã¦ä¸é¨ç®¡çè æ¨©éã«ã¤ãã¦ã¯å¶éãããªã©ã®ããç´°ããªæ¨©é管çãä½µç¨ãã¦ãã¾ãã
使ç¨ã©ã¤ã»ã³ã¹ã¯ãSingle Sign-OnãMulti-factor AuthenticationãUniversal DirectoryãLifecycle ManagementãLifecycle Management Advanced SourcingãWorkflowsã§ãå¤è¦ç´ èªè¨¼ã§ã¯ã¹ãã¼ããã©ã³ã¢ããªã«ããããã·ã¥èªè¨¼ãæ´»ç¨ãHub & Spokeæ©è½ãæ´»ç¨ããã»ããCustom Administration Rolesã§ç®¡çè ã®æä½ç¯å²ãå®ç¾©ãWorkflowsã§ã¦ãã¼ã¯ãªIDãçæãã¦éè¤æé¤ãè¡ãªã£ã¦ãã¾ãã
ã¦ã¼ã¹ã±ã¼ã¹å¥ã«ã¿ãOktaã®å°å ¥äºä¾ã¾ã¨ã
ã¢ã¤ãã³ãã£ãã£ç®¡çã«é¢ãã¦ã¯ãã¦ã¼ã¶ä¼æ¥å社ããããããã¾ãã¾ãªå½¢ã§æ¢ã«éç¨ãã¦ãããã®ããããããæ°ãã«Oktaãå°å ¥ããéã«æ¢åã®ç°å¢ã¨ã©ãæºãåãããã°è¯ãã®ãæ©ã¾ãããã¨ãããããããã¾ãããããããæ¢ã«è±å¯ãªã¦ã¼ã¶äºä¾ãæãã¦ããOktaã§ã¯ãã¾ãã¾ãªç°å¢ã¨ã®çµã¿åãããäºä¾ã¨ãã¦åç §ã§ãããããèªç¤¾ã®ç¶æ³ã«å³ããOktaã®å°å ¥ã®å½¢ãè¦ã¤ãããã¨ãåºæ¥ãã®ã§ã¯ãªãã§ããããã