> For the complete documentation index, see [llms.txt](https://documentation.immuta.com/saas/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://documentation.immuta.com/saas/~/changes/l3NnvynMHxi6VvqRtJhK/people/section-contents/how-to-guides/okta/okta-ldap.md).

# Okta LDAP Interface

Okta LDAP Interface is a built-in Okta integration that enables you to expose your Okta directory over standard LDAP wire. The Okta LDAP Interface exposes the entire Okta directory.

{% hint style="warning" %}
**LDAP interface is not an isolated application**

You cannot manage the assignment of users and groups to the LDAP Interface the same way you would in a web application. Instead, you should be able to leverage LDAP filters to moderate access to applications that call the LDAP Interface (i.e., filtering user attributes and groups.)
{% endhint %}

## 1 - Enable LDAP Interface in Your Okta Account

1. Go to the **Admin Console** in your Okta account.
2. Select **Directory**, and then click **Directory Integrations**.
3. Select **Add Directory** and **Add LDAP Interface**. You will be presented with the details required to make a successful LDAP connection.

{% hint style="info" %}
Create a service account to use as your LDAP bind user; any Okta admin with the "view users" permission can serve the role. Choose the Read-Only Admin to grant the least privilege.
{% endhint %}

## 2 - Set Up Authentication with the LDAP Interface in Immuta

1. Navigate to the **App Settings** page in Immuta.
2. Click the **Add IAM** button.
3. Complete the **Display Name** field and select your IAM type from the **Identity Provider Type** dropdown: **LDAP/Active Directory**, **SAML**, or **OpenID**.

*For a tutorial on setting up an Okta IAM see the* [*App Settings page*](/saas/~/changes/l3NnvynMHxi6VvqRtJhK/application-configuration/how-to-guides/config-builder-guide.md#use-existing-identity-access-manager)*.*

## 3 - Configure MFA in Okta

To enforce directory-wide MFA, create an authentication policy in Okta (if you do not yet have MFA policies in place).

1. Navigate to **Security** in the Okta Admin console.
2. Select **Authentication**, and then click **Sign On**.

   *Note: If you enforce MFA on the user that’s configured as your LDAP bind user, the integration won’t work. You will therefore need to make that user exempt in your MFA policies.*


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://documentation.immuta.com/saas/~/changes/l3NnvynMHxi6VvqRtJhK/people/section-contents/how-to-guides/okta/okta-ldap.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
