ExtraHop Okta in Reveal(x) 360
This guide provides the procedures for basic setup and administration of users through the legacy ExtraHop Okta user management system.
Activate your Okta administrator account
The Okta administrator role is granted to the email address that you provided during sign up.
Note: | The ExtraHop Okta implementation includes a subset of Okta features. Some features, such as removing users, are not available. |
Configure your firewall rules
If your ExtraHop system is deployed in an environment with a firewall, you must open access to ExtraHop Cloud Services. For Reveal(x) 360 systems that are connected to self-managed sensors, you must also open access to the ExtraHop Cloud Recordstore.
Open access to Cloud Services
For access to ExtraHop Cloud Services, your sensors must be able to resolve DNS queries for *.extrahop.com and access TCP 443 (HTTPS) from the IP address that corresponds to your sensor license:
- 35.161.154.247 (Portland, U.S.A.)
- 54.66.242.25 (Sydney, Australia)
- 52.59.110.168 (Frankfurt, Germany)
Open access to Cloud Recordstore
For access to the ExtraHop Cloud Recordstore, your sensors must be able to access outbound TCP 443 (HTTPS) to these fully-qualified domain names:
- bigquery.googleapis.com
- oauth2.googleapis.com
- www.googleapis.com
- www.mtls.googleapis.com
- iamcredentials.googleapis.com
You can also review the public guidance from Google about computing possible IP address ranges for googleapis.com.
In addition to configuring access to these domains, you must also configure the global proxy server settings.
Manage Users in ExtraHop Okta
Before users can log in to Reveal(x) 360, the Okta administrator must create users and assign them to groups that determine their privileges.
Here are some important considerations about users and user groups:
- You cannot remove a user. Deactivate the user to remove their ability to access the Reveal(x) 360 system.
- You cannot create your own user groups. You must assign users to the built-in ExtraHop groups.
- You cannot modify the built-in groups.
Note: | Optionally, you can configure Reveal(x) 360 to manage users through an existing supported SAML 2.0 identity provider. |
Deactivate a user
You cannot remove a user, but you can deactivate a user to remove their ability to access the Reveal(x) system.
- In the Okta Admin Console, from the Directory drop-down menu, select People.
- From the More Actions drop-down menu, click Deactivate.
- Select the checkbox next to the name of the user or users you want to deactivate.
- Click Deactivate Selected.
- In the Deactivate Person dialog box, click Deactivate.
Thank you for your feedback. Can we contact you to ask follow up questions?