<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Itse Isaac Azi</title>
    <description>The latest articles on DEV Community by Itse Isaac Azi (@isaacgato).</description>
    <link>https://dev.to/isaacgato</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1490173%2Fc9de85e5-9da5-4c06-97b6-82c272bbe101.jpg</url>
      <title>DEV Community: Itse Isaac Azi</title>
      <link>https://dev.to/isaacgato</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/isaacgato"/>
    <language>en</language>
    <item>
      <title>How to Onboard a New User on Okta</title>
      <dc:creator>Itse Isaac Azi</dc:creator>
      <pubDate>Wed, 19 Aug 2026 20:26:32 +0000</pubDate>
      <link>https://dev.to/isaacgato/how-to-onboard-a-new-user-on-okta-40k3</link>
      <guid>https://dev.to/isaacgato/how-to-onboard-a-new-user-on-okta-40k3</guid>
      <description>&lt;p&gt;Prerequisite&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Okta Account: You can register on &lt;div class="crayons-card c-embed text-styles text-styles--secondary"&gt;
    &lt;div class="c-embed__content"&gt;
        &lt;div class="c-embed__cover"&gt;
          &lt;a href="https://www.okta.com/" class="c-link align-middle" rel="noopener noreferrer"&gt;
            &lt;img alt="" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fwww.okta.com%2Fcontent%2Fdam%2Fokta---digital%2Fen_us%2Fimages%2Fgraphics%2Fokta-homepage-thumbnail.jpg" height="420" class="m-0" width="800"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="c-embed__body"&gt;
        &lt;h2 class="fs-xl lh-tight"&gt;
          &lt;a href="https://www.okta.com/" rel="noopener noreferrer" class="c-link"&gt;
            Secure Identity for Employees, Customers, and AI | Okta
          &lt;/a&gt;
        &lt;/h2&gt;
          &lt;p class="truncate-at-3"&gt;
            The Okta and Auth0 Platforms enable secure access, authentication, and automation — putting Identity at the heart of business security and growth.
          &lt;/p&gt;
        &lt;div class="color-secondary fs-s flex items-center"&gt;
          okta.com
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;
. Make sure to create a free account and log in.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;Step One: Log in to your account with your details&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8zcv091tupr2fjzag977.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8zcv091tupr2fjzag977.png" alt=" " width="800" height="371"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step Two: Click on Directory&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Flxyxi255be5alfifum89.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Flxyxi255be5alfifum89.png" alt=" " width="800" height="371"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step Three: Click on People&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fgok8xkhv0tq28ni0ovuj.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fgok8xkhv0tq28ni0ovuj.png" alt=" " width="800" height="371"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step Four: Filling in the details of the new member&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F19e29vz9r5pzxtup3n06.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F19e29vz9r5pzxtup3n06.png" alt=" " width="800" height="371"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvw7n7kc1lqm42vmy1gcz.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fvw7n7kc1lqm42vmy1gcz.png" alt=" " width="800" height="371"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fmsukmaoq2oqiw6q37wo4.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fmsukmaoq2oqiw6q37wo4.png" alt=" " width="800" height="371"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step Five: Go back to the people tabs and refresh to see the new account that has been created.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fdhk4k06tjw69xac1uln3.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fdhk4k06tjw69xac1uln3.png" alt=" " width="800" height="371"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step Six: Click on the newly created user to view more options&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fao70wqao8cauiw96j851.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fao70wqao8cauiw96j851.png" alt=" " width="800" height="371"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step Seven: Log in to your email to access the activation link&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fa51cpih4m8wkv6ejdil4.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fa51cpih4m8wkv6ejdil4.png" alt=" " width="800" height="371"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fyktpil5xcrmlym1xao80.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fyktpil5xcrmlym1xao80.png" alt=" " width="800" height="371"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;After clicking the activation link in your desired email, you will be prompted to set a password and MFA to protect your account.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>iam</category>
      <category>programming</category>
      <category>security</category>
    </item>
    <item>
      <title>WordPress (WP) and Okta Single Sign-On</title>
      <dc:creator>Itse Isaac Azi</dc:creator>
      <pubDate>Wed, 05 Aug 2026 22:26:15 +0000</pubDate>
      <link>https://dev.to/isaacgato/wordpress-wp-and-okta-single-sign-on-i5c</link>
      <guid>https://dev.to/isaacgato/wordpress-wp-and-okta-single-sign-on-i5c</guid>
      <description>&lt;p&gt;  &lt;iframe src="https://www.youtube.com/embed/C3WkmeSORmA"&gt;
  &lt;/iframe&gt;
&lt;/p&gt;

&lt;p&gt;&lt;u&gt;&lt;strong&gt;Prerequisite&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Okta Account&lt;/li&gt;
&lt;li&gt;WordPress website &lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;WordPress does not independently authenticate users when Okta and WordPress use Single Sign-On (SSO). Instead, it uses Okta to verify a user's identity.&lt;/p&gt;

&lt;p&gt;Consider it like this:&lt;br&gt;
The program that the user wants to use is called WordPress.&lt;/p&gt;

&lt;p&gt;The trusted identity provider (IdP) that confirms the identity of the user is Okta.&lt;/p&gt;

&lt;p&gt;SAML 2.0 is the protocol that securely sends the authentication result from Okta to WordPress.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fatazn3sat4cqtcbvw844.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fatazn3sat4cqtcbvw844.png" alt=" " width="800" height="371"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;u&gt;&lt;strong&gt;Before SSO&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;

&lt;p&gt;Without SSO, the login flow looks like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;              The user
                │
        WordPress Login Page
                │
        Username + Password
                │
    WordPress checks credentials.
                │
            Database
                │
           Login Success
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;u&gt;&lt;strong&gt;Problems with this approach include:&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Users must remember separate passwords.&lt;/li&gt;
&lt;li&gt;Passwords are stored and managed by WordPress.&lt;/li&gt;
&lt;li&gt;MFA may not be consistently enforced.&lt;/li&gt;
&lt;li&gt;User accounts have to be managed separately in WordPress.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;After SSO&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;With Okta SSO:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;

           User
            │
            ▼
     WordPress Website
            │
            ▼
     "Login with Okta"
            │
            ▼
           Okta
            │
    Username + Password
            │
            ▼
      MFA Challenge
            │
            ▼
     Identity Verified
            │
            ▼
     SAML Response Sent
            │
            ▼
         WordPress
            │
            ▼
       User Logged In
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Observe that the password is never checked by WordPress. It just acknowledges Okta's reliable response.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fq7pl6hpnq0j07a8zpbdc.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fq7pl6hpnq0j07a8zpbdc.png" alt=" " width="800" height="371"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;u&gt;&lt;strong&gt;The Components&lt;/strong&gt;&lt;/u&gt;&lt;br&gt;
&lt;strong&gt;1. User&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The employee, administrator, editor, or customer trying to log in.&lt;br&gt;
Example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;John
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;John wants to access:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;https://company.com/wp-admin
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;2. WordPress (Service Provider)&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;In SAML, WordPress acts as the Service Provider (SP).&lt;/p&gt;

&lt;p&gt;Its job is to:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Request authentication.&lt;/li&gt;
&lt;li&gt;Trust Okta's response.&lt;/li&gt;
&lt;li&gt;Create a local session.&lt;/li&gt;
&lt;li&gt;Assign the appropriate WordPress role.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;WordPress does not verify the password.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3. Okta (Identity Provider)&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Okta is the Identity Provider (IdP).&lt;br&gt;
It:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Stores user identities.&lt;/li&gt;
&lt;li&gt;Verifies passwords.&lt;/li&gt;
&lt;li&gt;Enforces MFA.&lt;/li&gt;
&lt;li&gt;Applies sign-in policies.&lt;/li&gt;
&lt;li&gt;Sends a signed SAML response back to WordPress.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;4. SAML&lt;/strong&gt;&lt;br&gt;
SAML (Security Assertion Markup Language) is an XML-based standard for exchanging authentication information.&lt;/p&gt;

&lt;p&gt;WordPress sends a request like&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Please authenticate this user.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Okta replies:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight email"&gt;&lt;code&gt;&lt;span class="nt"&gt;This user has been authenticated.

Email&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;
&lt;span class="nt"&gt;john@company.com

First Name&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;
&lt;span class="nt"&gt;John

Last Name&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;
&lt;span class="nt"&gt;Smith

Groups&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;
&lt;span class="nt"&gt;Administrators
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The response is digitally signed so WordPress can verify it hasn't been altered.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;A Real Login Walkthrough&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Suppose:&lt;br&gt;
WordPress site:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;https://company.com
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Okta organisation:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;https://company.okta.com
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The login sequence is&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 1&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;John opens:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;https://company.com/wp-admin
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;WordPress sees no active session.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 2&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Instead of showing the standard login form, WordPress redirects John to Okta.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;company.okta.com
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Step 3&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Okta displays its login page.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Email:

Password
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Step 4&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Okta prompts for MFA if required.&lt;br&gt;
For example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Approve on Okta Verify
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;or&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Enter 6-digit code
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Step 5&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Okta verifies:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Password&lt;/li&gt;
&lt;li&gt;MFA&lt;/li&gt;
&lt;li&gt;Device policies&lt;/li&gt;
&lt;li&gt;Location policies&lt;/li&gt;
&lt;li&gt;Time-based policies
If everything meets policy, authentication succeeds.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;Step 6&lt;/strong&gt;&lt;br&gt;
Okta generates a SAML assertion.&lt;br&gt;
This contains information such as:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;NameID

john@company.com
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;First Name

John
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Last Name

Smith
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Department

IT
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Groups

Administrators
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The assertion is digitally signed with Okta's private key.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 7&lt;/strong&gt;&lt;br&gt;
WordPress validates:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;The signature.&lt;/li&gt;
&lt;li&gt;The certificate.&lt;/li&gt;
&lt;li&gt;The issuer.&lt;/li&gt;
&lt;li&gt;The audience.&lt;/li&gt;
&lt;li&gt;The assertion's expiration time.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;If all checks pass, WordPress trusts the response.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 8&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;WordPress creates a local session and, if configured, maps the user to a role.&lt;/p&gt;

&lt;p&gt;&lt;u&gt;&lt;strong&gt;What Happens the First Time a User Logs In?&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;

&lt;p&gt;If Just-In-Time (JIT) provisioning is enabled:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;The user authenticates with Okta.&lt;/li&gt;
&lt;li&gt;WordPress doesn't find a matching account.&lt;/li&gt;
&lt;li&gt;WordPress automatically creates the account.&lt;/li&gt;
&lt;li&gt;The user is logged in.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;This avoids manually creating WordPress accounts.&lt;/p&gt;

&lt;p&gt;&lt;u&gt;&lt;strong&gt;What Happens on Later Logins?&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;

&lt;p&gt;WordPress finds the existing account by email or another mapped identifier and signs the user in immediately after Okta authenticates them.&lt;/p&gt;

&lt;p&gt;&lt;u&gt;&lt;strong&gt;Why This Is More Secure&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;

&lt;p&gt;Instead of storing passwords in WordPress:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;100 Passwords

↓

WordPress Database
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;You centralise authentication in Okta:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;100 Users

↓

Okta

↓

WordPress trusts Okta
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;u&gt;&lt;strong&gt;Benefits include:&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;One password per user across applications.&lt;/li&gt;
&lt;li&gt;Centralised MFA enforcement.&lt;/li&gt;
&lt;li&gt;Faster onboarding and offboarding.&lt;/li&gt;
&lt;li&gt;Centralised audit logs.&lt;/li&gt;
&lt;li&gt;Reduced password reuse.&lt;/li&gt;
&lt;li&gt;Consistent access policies.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;&lt;u&gt;Common Security Policies You Can Enforce in Okta&lt;/u&gt;&lt;/strong&gt;&lt;br&gt;
Examples include:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Require MFA for WordPress administrators.&lt;/li&gt;
&lt;li&gt;Block sign-ins from countries your organisation doesn't operate in.&lt;/li&gt;
&lt;li&gt;Require managed or compliant devices.&lt;/li&gt;
&lt;li&gt;Deny access from anonymous proxies or VPNs (if licensed features are available).&lt;/li&gt;
&lt;li&gt;Block legacy authentication methods.&lt;/li&gt;
&lt;li&gt;Set session timeout and re-authentication requirements.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;These policies are enforced before WordPress grants access.&lt;/p&gt;

</description>
      <category>security</category>
      <category>wordpress</category>
      <category>tutorial</category>
      <category>opensource</category>
    </item>
    <item>
      <title>Multi-Factor Authentication(MFA)</title>
      <dc:creator>Itse Isaac Azi</dc:creator>
      <pubDate>Fri, 09 Aug 2024 14:00:30 +0000</pubDate>
      <link>https://dev.to/isaacgato/multi-factor-authenticationmfa-4h7b</link>
      <guid>https://dev.to/isaacgato/multi-factor-authenticationmfa-4h7b</guid>
      <description>&lt;p&gt;able to be called a Two-factor authentication, also known as 2FA, is an electronic authentication technique that limits access to a specific website or application by requiring the user to provide two or more forms of identification. A primary goal of multifactor authentication is to prevent unauthorised access to any network, application, system, or website.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;HOW AUTHENTICATION WORKS&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Generally, in order to gain access to a specific website, system, network, or application, the user must authenticate themselves. Usually, in order to gain access, the user must supply a password or pin (personal identification number); however, if these details are entered incorrectly, the user will not be allowed to access the system. Usually, in order to gain access, the user must supply a password or pin (personal identification number); however, if these details are entered incorrectly, the user will not be allowed to access the system. Furthermore, the user is required to furnish proof in multiple ways, such as through the utilisation of biometrics, OTPs (one-time passwords), facial recognition, and pin security questions. I will go over the various popular forms of authentication in the following section.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;METHODS OF AUTHENTICATION&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;1.Something the user has&lt;/p&gt;

&lt;p&gt;2.Something the user knows&lt;/p&gt;

&lt;p&gt;3.Something the user is&lt;/p&gt;

&lt;p&gt;1.&lt;strong&gt;Something the user possesses:&lt;/strong&gt; this can be any tangible object the user owns, such as badges, smart cards, USB drives, and security tokens.&lt;/p&gt;

&lt;p&gt;2.&lt;strong&gt;Something the user knows:&lt;/strong&gt; This can be answers to security questions about passwords, pins, and OTPs.&lt;/p&gt;

&lt;p&gt;3.&lt;strong&gt;Something the user  is:&lt;/strong&gt; instances of facial recognition, fingerprint, retinal scanning, and biometric&lt;/p&gt;

&lt;p&gt;Taking money out of an ATM is the most typical application of multi-factor authentication (MFA). The user must enter their unique pin combination in order to access the system; if the combination is entered incorrectly, the user's attempt to access the system is unsuccessful. Occasionally, the unauthorised user is actually a hacker or scammer rather than the person who is trying to access the system at all. Using multi-factor authentication (MFA) and a strong password combination are recommended measures to safeguard your account and prevent unauthorised access.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;ADVANTAGES OF AUTHENTICATION APPs&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;The application is typically linked to the user's phone, making it inaccessible unless the user's phone is stolen.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;This technique generates OTPs more quickly and is independent of the network and any provider.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Mobile data is not needed in order to access the code.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;It is simple to set up.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;5.You will not lose your code if you switch devices because it will be backed up online.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;HOW TO CONNECT GOOGLE AUTHENTICATION APP TO YOUR GREY ACCOUNT&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This method is simple and it can be achieved by following this simple steps written by &lt;strong&gt;Chioma Mmeje&lt;/strong&gt; Click on the link below&lt;/p&gt;

&lt;blockquote&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;a href="https://community.grey.co/c/general-c86478/have-you-ever-experienced-difficulty-in-getting-otp-via-sms" rel="noopener noreferrer"&gt;Have you ever experienced difficulty in getting OTP via SMS?&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;When it comes to security and preventing unauthorised access, there are a number of methods to choose from. Based on my experience and years of use, authentication apps offer our systems greater protection.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>mfa</category>
      <category>safety</category>
    </item>
    <item>
      <title>What is a data breach?</title>
      <dc:creator>Itse Isaac Azi</dc:creator>
      <pubDate>Wed, 12 Jun 2024 19:47:41 +0000</pubDate>
      <link>https://dev.to/isaacgato/what-is-a-data-breach-41h7</link>
      <guid>https://dev.to/isaacgato/what-is-a-data-breach-41h7</guid>
      <description>&lt;div&gt;
  &lt;iframe src="https://loom.com/embed/bd00ea6813334c8b8f8c9db470e297dc"&gt;
  &lt;/iframe&gt;
&lt;/div&gt;


&lt;ol&gt;
&lt;li&gt;Go to your browser and click on the address.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fzv10xz5v6k8mzl7j7001.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fzv10xz5v6k8mzl7j7001.png" alt="Image description" width="800" height="356"&gt;&lt;/a&gt;&lt;br&gt;
&lt;strong&gt;2. Look up Nordpass.com on the internet.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fkx0ir262p71jnb01ntzf.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fkx0ir262p71jnb01ntzf.png" alt="Image description" width="800" height="356"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Enter your information to register and log in.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fxw77yd0niodl41we7qi4.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fxw77yd0niodl41we7qi4.png" alt="Image description" width="800" height="356"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fxxnud1ck9giymobjfj0b.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fxxnud1ck9giymobjfj0b.png" alt="Image description" width="800" height="356"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fyw98x0k6rfbhpes10r7v.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fyw98x0k6rfbhpes10r7v.png" alt="Image description" width="800" height="356"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;4. Click Data Breach Scanner in the tools section.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fd0aieppfevdutploqcho.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fd0aieppfevdutploqcho.png" alt="Image description" width="800" height="356"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F313j63qao61fjzxj869l.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F313j63qao61fjzxj869l.png" alt="Image description" width="800" height="356"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;**5. This is where you can configure your credit or debit card, email, or both.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fcz20fi1qwmlk34tycujt.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fcz20fi1qwmlk34tycujt.png" alt="Image description" width="800" height="356"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;After this, you can scan your information to see the outcomes. You will find out at this point whether or not any of your personal information has been compromised.**&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fie3ehgqwf6s659ywc7m6.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fie3ehgqwf6s659ywc7m6.png" alt="Image description" width="800" height="356"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fibg9yjcyzkkb5h2n76hd.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fibg9yjcyzkkb5h2n76hd.png" alt="Image description" width="800" height="356"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F5pnlup07qpvksmi14dtv.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F5pnlup07qpvksmi14dtv.png" alt="Image description" width="769" height="386"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Ffr1fq84d0ev1q5kvlwmu.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Ffr1fq84d0ev1q5kvlwmu.png" alt="Image description" width="800" height="384"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;*&lt;strong&gt;*In addition to having a password manager for all your passwords, &lt;a href="//www.nordpass.com"&gt;Nordpass.com&lt;/a&gt; can generate strong passwords that are hard for hackers to decipher. a sample of the password that you can obtain is this:. **Y8m3BF5xpH%r5t7E3&amp;amp;$Ga&amp;amp;QduBfMr6UdsU9&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>nordpass</category>
      <category>security</category>
    </item>
  </channel>
</rss>
