r/okta
Question: Is brokering Graph API token possible?
- upvotes
- 1
- comments
- 2
Post
Highlighted: the lines this signal was extracted from
We have many application servers that email through an on-prem SMTP relay. My CISO wants apps to move to Microsoft Graph API using Mail.Send. Easy, Entra Id App with RBAC controls authenticated using a certificate. Set those up for folks plenty of times, no problem. But no. My CISO insists, everything that can, must authenticate through Okta, and is pushing this. I tell him it can’t in the way he wants, Okta is meant for user interactive login, not server to server. He sends a link to setup Graph API connection with Okta Workflows. Doesn’t look right to me, it looks like it just sets up Workflows ability to do things in MS, not external apps…but maybe I’m mistaken. We don’t have any workflows. actually I don’t even know if we have Workflows license. Looking into it. My question to any experts out there who has dealt with Workflows. Is my CISOs ask even possible with Workflows? Can Okta be the broker to authenticate on behalf of the application server so it can get a proper token from Graph API so the external server can act? Or is direct to Entra Id App the only way? This just feels silly to me, but the CISO and is really going at this and I need hard facts that this doesn’t do what he thinks it does. Or if I’m just simply wrong, that might be true too. Help me out!