Connect it yourselfCan we check presence before a sensitive identity change?

Okta

An inline hook on sensitive identity actions — password reset, privilege grant, factor enrollment — that acts on the verdict before the change applies.

Inline, before the change

The connector registers as an inline hook and is called with the pending identity action. Requests carry a connector signature verified before anything is evaluated.

The verdict decides whether the change proceeds, needs a second check, or is refused.

The artifacts behind this page

One next step

Privileged reset use case