Overview
User objects (AKA People) represent individuals who have access to the Okta organization. Each user has a unique identifier, username in the email address format, and various attributes such as email, first name, last name, and status. Users are represented as Okta_User nodes in BloodHound.Edges
The tables below list edges defined by the Okta extension only. Additional edges to or from this node may be created by other extensions.
Inbound Edges
Outbound Edges
Properties
Sample Property Values
User Status
User status can have multiple values, as illustrated below:
To simplify analysis in BloodHound, the collector maps the Status attribute to the virtual boolean Enabled attribute as follows:
Synchronization with External Directories
Users can be synchronized from external directories such as Active Directory (AD) or LDAP. When synchronized, certain attributes may be mapped from the external directory to the Okta user profile.