Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers Connect Okta application access. Read application assignments and directory identities without assuming paid downstream licenses. Current availability: Read adapter implemented; company authorization and successful live sync required. Before you start. An authorized company administrator with Vendor licenses management permission and an approved provider data-use scope. The company’s protected integration vault. Use a dedicated provider application; never put credentials in a KB, video, chat or source file. Step 1. In the correct Okta organization, create a dedicated read-only administrator with access to the intended apps and user directory. Generate its API token and record its rotation owner. Okta tokens inherit the issuer’s permissions. Step 2. Enter the organization URL and token in the Okta form. Supported organization hosts end in okta.com, okta-emea.com or oktapreview.com; arbitrary custom hosts and redirects are rejected. Step 3. Optionally enter up to twenty immutable app IDs. With no selection, all returned apps are included only when there are twenty or fewer. Step 4. Save the encrypted connection in Companies > company > Vendor licenses. Choose Sync now in production after provider authorization. Dev and QA isolate external operations. Review the recorded sync result and compare the snapshot with the provider console. Step 5. Review each application’s assignments, direct or group origin when returned, and directory account status. Missing directory users remain explicitly unavailable; an app assignment does not prove downstream provisioning or purchased capacity. Now verify the result. Compare an app assigned directly and an app assigned through a group. Their returned assignment origin must match Okta. Capacity and available seats remain unknown. Okta administrator permissions and downstream vendor licenses are outside this adapter. A successful company sync is required before describing the connection as healthy; an available adapter alone is not a connected account. Check a second company and a view-only account: neither can change this company’s credentials or lifecycle state. Pause, Resume and Trash affect only the local connection. Resume waits for a separate Sync action; no vendor user or license is modified. If you get stuck. 401 or 403: check credential expiry, the selected provider organization and the exact required permissions. Do not grant broad write access merely to bypass a failed read. A failed or incomplete provider response preserves the last complete snapshot. Review the error, correct the connection and explicitly retry. On a 429 rate-limit response, wait for the provider’s retry window before another manual sync. Large inventories can require a separately designed scheduled export; the current bounded sync does not commit partial results. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.