---
title: Okta MFA Integration
slug: kronpam-reference-guide-3-5-0/okta-mfa-integration
description: Learn how to seamlessly integrate Okta and Kron PAM with this comprehensive document. Discover how users can log in to Okta using email addresses from Kron PAM, and verify their tokens through Okta Verify or Google Authenticator. Get step-by-step instruct
docTags: 
createdAt: 2022-07-31T18:30:26.000Z
---

For Okta integration, users should log in to Okta with the email addresses defined in Kron PAM. After logging in to the Okta portal, token verification can be done through different verification methods.

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/9XVPhw2M6ivBPQWHU2A5f_image.png" size="42" width="399" height="292" caption="Okta Verification Methods" position="center" showCaption="true"}

- To use the Okta verification method, users must download the **Okta Verify** mobile app. Okta Verify should be activated from the user portal settings area, followed by a scan of the barcode that appears on the portal’s mobile application section.
-  Users should also download the Google Authenticator mobile app if they wish to use the **Google Authenticator** method. The Google Authenticator should be activated from the user portal settings area, followed by a scan of the barcode that appears on the portal’s mobile application section.

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/tjX1JTfQ8s6strblJxP6L_image.png" size="38" width="350" height="401" position="center" caption="Okta Verify Barcode Viewer	" showCaption="true"}

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/8tgb-PIQUhUfWbrHfWpMP_image.png" size="30" width="327" height="392" position="center" caption="Google Authenticator Barcode Viewer" showCaption="true"}

Kron PAM integrates with Okta via API, as long as certain parameters are defined in Kron PAM:

-  API key (the API key is created by Okta for each customer environment)
-  URL (the URL is unique for each customer environment)

To adjust the Okta Integration Settings:

1. Navigate to **Administration&#x20;**> **System Configuration Manager**.
2. Set the following parameters:
   mfa.provider=okta (default: internal)
   mfa.external.provider.okta.apikey=xxx (encrypted)
   mfa.external.provider.okta.hostname
   mfa.external.provider.okta.factor=\{token\:software\:totp, sms, push} (default: token\:software\:totp)
   mfa.external.provider.okta.totpprovider=\{google, okta} (default: google)

- With Okta enabled, the token can be sent in different ways:

| **token\:software\:totp** | Token in the mobile app is used. (Okta Verify or Google Authenticator) |
| ------------------------- | ---------------------------------------------------------------------- |
| **SMS**                   | The token is sent by SMS.                                              |
| **Push**                  | Verification is confirmed from the mobile application. (Okta Verify)   |

