Okta
Cloud-based identity and access management (IAM) platform providing SSO, MFA, and lifecycle management for enterprise organizations
Hosting & Jurisdiction
Cloud-only. EU cell available for data residency. 2022 security breach raised concerns. US jurisdiction applies to all identity data.
⚠️ Jurisdiction Risk
This product is subject to foreign jurisdiction (US), which may allow foreign authorities to compel data disclosure.
Key Concerns
- Subject to US CLOUD Act - identity data particularly sensitive
- 2022 security breach by Lapsus$ group
- Single point of failure for authentication
- Cloud-only with no self-hosting option
NDSI Assessment
Norwegian Digital Sovereignty Index v1.0 - Assessed 2025-12-19
EU data residency available, but identity data critical
Cloud operations
Subject to CLOUD Act. Identity data is highly sensitive.
Partners available, no Norwegian office
Identity provider = keys to the kingdom. US jurisdiction concerning
Cloud-only. Single point of failure for authentication
2022 Lapsus$ breach affected reputation. Strong security features
US company, dominant in enterprise IAM market
Auth0 acquisition. Complex integration dependencies
SAML/OIDC standards, but proprietary platform
What You Can Do
Enable EU data residency
Configure tenant for EU data storage
Implement phishing-resistant MFA
Use FIDO2/WebAuthn instead of SMS/TOTP
Configure privileged access management
Limit admin access and implement session controls