182/182 feeds/APIs · 190/193 docs · synced 04:09 UTC Customize Public mode

Okta sign-in

Reach your Okta org for sign-in, the dashboard and Okta Verify, with the Okta CDN and the region-specific Okta domains.

Admin workstation · reviewed 6 Oct 2026 · Microsoft 365 endpoints version 2026081400

Okta marks every domain in its list as required; region and government domains are optional here only because they apply to orgs in those cells. Okta says to use port 443 unless noted otherwise. IP ranges aren't copied: use the Okta-published JSON in References.

Cited pages since the review

0 of 2 cited pages read

None of the pages this bundle cites has been read yet, so whether they changed since 6 Oct 2026 isn't known.

2 cited pages aren't monitored, so changes there go unnoticed

Downloads

Built from this bundle and the live endpoint data

Entries with {yourOktaDomain} are left out of downloads until you fill in your value.

FormatDestinationsLeft outDownload
Plain list, one per line191 Open
GSA V1 domain list191 Open
GSA V1 Graph request body191 Download
GSA V2 rules (review JSON)191 Download
GSA V2 rules (CSV)191 Download

"Left out" counts entries a format cannot hold: IP ranges in web filtering, mid-name wildcards, URLs in a V1 domain list, and unfilled values. The V2 JSON is a review format; Microsoft publishes no Graph request shape for V2 rules yet. See how V1 and V2 evaluate.

The same entries are JSON at /api/v1/access-bundles/okta. To check them from the workstation itself, run Test-ChangeIntelAccessBundle -Bundle okta -Value @{ yourOktaDomain = '...' } from the ChangeIntel PowerShell module there: it resolves DNS and tries TCP and TLS to each published host, and reports certificate issuers that suggest TLS inspection.

Which profile takes each destination is worked out from Microsoft's published material, with how strongly it supports the call; Microsoft publishes no host list for its GSA profiles, so none of it is confirmed. Required and optional follow the source where it says so; otherwise they are this bundle's judgement for its scenario, explained in the entry's notes. Confirm in the Global Secure Access client: Advanced diagnostics, Forwarding profile.

Expected to reach web filtering17expected to go through the Internet Access profile, where a block-by-default web filtering policy would have to allow the ones your scenario needs
DestinationPortsPurposeEvidence
*.awsglobalaccelerator.com TCP 443 AWS Global Accelerator front ends used by OktaA shared AWS namespace rather than an Okta-only domain; review it before allowing it on a privileged workstation. PublishedAllow access to Okta IP addresses: Implementation details
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.mtls.okta.com TCP 443 Okta mutual-TLS endpoints for commercial orgsOkta doesn't state the purpose; the name indicates certificate-based (mTLS) flows. PublishedAllow access to Okta IP addresses: Implementation details
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

okta-featureflag-edge.azureedge.net TCP 443 Okta feature-flag edge endpoint listed for the DNS allow listOkta doesn't state the purpose; the label follows the host name. PublishedAllow access to Okta IP addresses: Content Delivery Network (CDN)
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.okta.com TCP 443 Okta service domains for commercial orgs PublishedAllow access to Okta IP addresses: Implementation details
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.oktacdn.com TCP 443 Okta static sign-in assets served from its CDNOkta says to allow IPv6 too if the network has IPv6 clients. PublishedAllow access to Okta IP addresses: Content Delivery Network (CDN)
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

{yourOktaDomain} TCP 443 Your Okta org: sign-in, dashboard and Okta VerifyAlso add any custom domain your org uses. CuratedFind your Okta domainTenant-specific. Okta's allow list publishes wildcards only; the placeholder is Okta's own and already includes the suffix, such as example.okta.com or example.okta-emea.com.
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.kerberos.okta-emea.comoptional TCP 443 Okta Kerberos endpoints for EMEA orgs PublishedAllow access to Okta IP addresses: Implementation details
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.kerberos.okta.comoptional TCP 443 Okta Kerberos endpoints for commercial orgsOkta doesn't state the purpose; Kerberos endpoints are used by agentless Desktop SSO. PublishedAllow access to Okta IP addresses: Implementation details
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.kerberos.oktapreview.comoptional TCP 443 Okta Kerberos endpoints for preview orgs PublishedAllow access to Okta IP addresses: Implementation details
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.mtls.okta-emea.comoptional TCP 443 Okta mutual-TLS endpoints for EMEA orgs PublishedAllow access to Okta IP addresses: Implementation details
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.mtls.okta-gov.comoptional TCP 443 Okta mutual-TLS endpoints for Government orgs PublishedAllow access to Okta IP addresses: Implementation details
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.mtls.okta.miloptional TCP 443 Okta mutual-TLS endpoints for DoD orgs PublishedAllow access to Okta IP addresses: Implementation details
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.mtls.oktapreview.comoptional TCP 443 Okta mutual-TLS endpoints for preview orgs PublishedAllow access to Okta IP addresses: Implementation details
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.okta-emea.comoptional TCP 443 Okta orgs in the EMEA cellRequired when your org domain ends in okta-emea.com. PublishedAllow access to Okta IP addresses: Implementation details
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.okta-gov.comoptional TCP 443 Okta for Government orgs PublishedAllow access to Okta IP addresses: Implementation details
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.okta.miloptional TCP 443 Okta DoD orgs PublishedAllow access to Okta IP addresses: Implementation details
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

*.oktapreview.comoptional TCP 443 Okta preview (sandbox) orgs PublishedAllow access to Okta IP addresses: Implementation details
Internet Access profile · indicated, not confirmed

Not in the Microsoft 365 endpoint list the Microsoft traffic profile is built from, so it is expected to go through the Internet Access profile when that profile is on. Not confirmed: the Entra system profile's hosts aren't published.

Not determined3public material doesn't settle it; check the client's forwarding profile
DestinationPortsPurposeEvidence
crl3.digicert.comoptional TCP 80 Certificate revocation (CRL) for Okta certificatesOkta lists it for certificate revocation troubleshooting on port 80. Also Microsoft 365 endpoint set 125 (Common). PublishedAllow access to Okta IP addresses: Implementation details · set 125
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

crl4.digicert.comoptional TCP 80 Certificate revocation (CRL) for Okta certificatesOkta lists it for certificate revocation troubleshooting on port 80. Also Microsoft 365 endpoint set 125 (Common). PublishedAllow access to Okta IP addresses: Implementation details · set 125
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

ocsp.digicert.comoptional TCP 80 Certificate revocation (OCSP) for Okta certificatesOkta lists it for certificate revocation troubleshooting on port 80. Also Microsoft 365 endpoint set 125 (Common), so it is expected to fall in the GSA Microsoft traffic profile (not confirmed; Microsoft publishes no host list). PublishedAllow access to Okta IP addresses: Implementation details · set 125
Microsoft traffic profile · possible, not confirmed

In Microsoft 365 Common endpoint set 125 (Default category). Microsoft documents that the Microsoft traffic profile is built from this list, combined by traffic category, but not which categories it includes.

Also published

Material the publisher keeps current that is not copied here
ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 7 Oct 04:09 UTC · 182 of 182 readable · documentation 190/193 current