Skip to main content
OktaCustomer feedback

A customer is investigating if they can and are licensed to use Okta Workflows to broker Microsoft Graph API tokens for server-to-server authentication, a use case their CISO is insisting on which...

What happened

A customer is investigating if they can and are licensed to use Okta Workflows to broker Microsoft Graph API tokens for server-to-server authentication, a use case their CISO is insisting on which they believe is outside the product's intended function.

Source

RedditOct 3, 2026By u/reevesjeremy

r/okta

Question: Is brokering Graph API token possible?

upvotes
1
comments
2

Post

Highlighted: the lines this signal was extracted from

We have many application servers that email through an on-prem SMTP relay. My CISO wants apps to move to Microsoft Graph API using Mail.Send. Easy, Entra Id App with RBAC controls authenticated using a certificate. Set those up for folks plenty of times, no problem. But no. My CISO insists, everything that can, must authenticate through Okta, and is pushing this. I tell him it can’t in the way he wants, Okta is meant for user interactive login, not server to server. He sends a link to setup Graph API connection with Okta Workflows. Doesn’t look right to me, it looks like it just sets up Workflows ability to do things in MS, not external apps…but maybe I’m mistaken. We don’t have any workflows. actually I don’t even know if we have Workflows license. Looking into it. My question to any experts out there who has dealt with Workflows. Is my CISOs ask even possible with Workflows? Can Okta be the broker to authenticate on behalf of the application server so it can get a proper token from Graph API so the external server can act? Or is direct to Entra Id App the only way? This just feels silly to me, but the CISO and is really going at this and I need hard facts that this doesn’t do what he thinks it does. Or if I’m just simply wrong, that might be true too. Help me out!

reddit.com/r/okta/comments/1wwedky/question_is_brokering_graph_api_to...Read the full source

Comments on the post

  • “Okta Workflows is basically Okta’s version of Azure Logic Apps, or n8n. It’s low code automation workflow tooling. The MS Graph connector they are referring to is to enable you to call the graph API from within a workflow itself as a step of the workflow. It is not brokering auth. You could have app servers call an okta workflow webhook and trigger an email to be sent somewhere, but that Mail.Se”

    u/tjobarow4 points · Oct 3, 2026View

  • “Graph only accepts access tokens issued and signed by Microsoft. You can use Workflows to make Graph calls but the authentication is always performed by Entra. Workflows would be the client in this situation, not the authorization server.”

    u/raip2 points · Oct 3, 2026View

Extracted by Autobound

From the Signal API record
Signal
Customer feedback

What this signalsUser posts often show product pain before it reaches reviews or churn.

Subreddit
r/okta
Stage
Considering
Event date
Oct 2026

Companies

  • MicrosoftAlso named

The full record

From the Signal API record

Numbers

Mentions
2

Details

Timing
In progress
Category
Features
Virality
Very low
Post kind
Text
Prominence
Core
Company's role
Vendor

Topics and mentions

Topics

  • server-to-server
  • api authentication
  • workflows
  • licensing
  • iam

Flair

  • Okta/Workforce Identity

Products named

  • Okta Workflows

Extraction

Sentiment
Neutral
Detected
Oct 3, 2026
signal_type
reddit-company
signal_subtype
customerFeedback

Use this data

Get every Reddit signal for Okta and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Okta this week?”

  2. Send it to your own tools

    The Signal API returns Reddit signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full reddit-company record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/eaec90ac-a26a-50e8-a142-944af54831e9 returns this record as JSON. POST /v1/companies/enrich returns every signal for okta.com.

{
  "signal_id": "eaec90ac-a26a-50e8-a142-944af54831e9",
  "signal_type": "reddit-company",
  "signal_subtype": "customerFeedback",
  "detected_at": "2026-10-03T04:44:30+00:00",
  "company": {
    "name": "Okta",
    "domain": "okta.com"
  },
  "data": {
    "nsfw": false,
    "stage": "considering",
    "awards": 0,
    "timing": "in_progress",
    "topics": [
      "iam",
      "server-to-server",
      "api authentication",
      "workflows",
      "licensing"
    ],
    "post_id": "1wwedky",
    "summary": "A customer is investigating if they can and are licensed to use Okta Workflows to broker Microsoft Graph API tokens for server-to-server authentication, a use case their CISO is insisting on which they believe is outside the product's intended function.",
    "category": "features",
    "comments": [
      {
        "url": "https://www.reddit.com/r/okta/comments/1wwedky/comment/pdk4yzo/",
        "depth": 0,
        "score": 4,
        "author": "tjobarow",
        "excerpt": "Okta Workflows is basically Okta’s version of Azure Logic Apps, or n8n. It’s low code automation workflow tooling. The MS Graph connector they are referring to is to enable you to call the graph API from within a workflow itself as a step of the workflow. It is not brokering auth.\n\n You could have app servers call an okta workflow webhook and trigger an email to be sent somewhere, but that Mail.Se",
        "posted_at": "2026-10-03T05:48:34.000Z",
        "author_url": "https://www.reddit.com/user/tjobarow/"
      },
      {
        "url": "https://www.reddit.com/r/okta/comments/1wwedky/comment/pdkdyn2/",
        "depth": 0,
        "score": 2,
        "author": "raip",
        "excerpt": "Graph only accepts access tokens issued and signed by Microsoft. You can use Workflows to make Graph calls but the authentication is always performed by Entra. Workflows would be the client in this situation, not the authorization server.",
        "posted_at": "2026-10-03T06:59:16.000Z",
        "author_url": "https://www.reddit.com/user/raip/"
      }
    ],
    "evidence": [
      "[post] My CISO insists, everything that can, must authenticate through Okta, and is pushing this.",
      "[post] My question to any experts out there who has dealt with Workflows. Is my CISOs ask even possible with Workflows? Can Okta be the broker to authenticate on behalf of the application server so it can get a proper token from Graph API so the external server can act?",
      "[post] We don’t have any workflows. actually I don’t even know if we have Workflows license. Looking into it."
    ],
    "virality": "very_low",
    "post_date": "2026-10-03T04:44:30.000Z",
    "post_kind": "text",
    "post_text": "We have many application servers that email through an on-prem SMTP relay. My CISO wants apps to move to Microsoft Graph API using Mail.Send. Easy, Entra Id App with RBAC controls authenticated using a certificate. Set those up for folks plenty of times, no problem.\n\nBut no. My CISO insists, everything that can, must authenticate through Okta, and is pushing this.\n\nI tell him it can’t in the way he wants, Okta is meant for user interactive login, not server to server.\n\nHe sends a link to setup Graph API connection with Okta Workflows. Doesn’t look right to me, it looks like it just sets up Workflows ability to do things in MS, not external apps…but maybe I’m mistaken. We don’t have any workflows. actually I don’t even know if we have Workflows license. Looking into it.\n\nMy question to any experts out there who has dealt with Workflows. Is my CISOs ask even possible with Workflows? Can Okta be the broker to authenticate on behalf of the application server so it can get a proper token from Graph API so the external server can act? Or is direct to Entra Id App the only way?\n\nThis just feels silly to me, but the CISO and is really going at this and I need hard facts that this doesn’t do what he thinks it does. Or if I’m just simply wrong, that might be true too. Help me out!",
    "sentiment": "neutral",
    "subreddit": "okta",
    "event_date": "2026-10",
    "post_flair": [
      "Okta/Workforce Identity"
    ],
    "post_title": "Question: Is brokering Graph API token possible?",
    "prominence": "core",
    "source_url": "https://www.reddit.com/r/okta/comments/1wwedky/question_is_brokering_graph_api_token_possible/",
    "entity_role": "vendor",
    "post_author": "reevesjeremy",
    "upvote_ratio": 1,
    "mention_count": 2,
    "mention_surge": false,
    "subreddit_url": "https://www.reddit.com/r/okta/",
    "total_upvotes": 1,
    "comments_total": 2,
    "total_comments": 2,
    "other_companies": [
      {
        "name": "Microsoft",
        "role": "partner",
        "domain": "microsoft.com"
      }
    ],
    "post_author_url": "https://www.reddit.com/user/reevesjeremy/",
    "signal_category": "feedback",
    "comments_included": 2,
    "products_mentioned": [
      "Okta Workflows"
    ]
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.