The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Okta can be a sensible choice for a small business, but it is a valuable target because it controls access to many other services. The 2023 support-system incident showed how stolen session tokens could put customer accounts at risk; it did not show that every Okta customer was compromised or that using Okta is inherently unsafe. The practical response is to protect privileged accounts with phishing-resistant authentication, limit exposure in support workflows, and make sure you can revoke sessions and recover access.
Why criminals target Okta
An identity provider sits between users and the services they need. It verifies identities and helps determine what those identities can access. That makes it a high-value control point: an attacker who gains access to an administrator account or a valid user session may be able to reach multiple downstream applications.
Attackers can pursue identity accounts in several ways. Credential stuffing tries username-and-password pairs exposed in unrelated breaches. Phishing and malware can steal credentials or session data. A stolen session token may let an attacker act as an already authenticated user without first entering that user’s password again. Okta’s November 2023 incident investigation described session tokens in support files as part of the risk.
What the 2023 Okta support-system incident showed
In its November 3, 2023 investigation, Okta said a threat actor accessed files associated with 134 customers between September 28 and October 17, 2023. Some files were HTTP Archive (HAR) files containing session tokens, and Okta said five customer sessions were hijacked. These figures describe the incident Okta investigated; they are not a general measure of how often Okta accounts are compromised.
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
In a later update, Okta said the attacker ran and downloaded a report containing the names and email addresses of all users of the Okta customer-support system. Okta also said that FedRAMP High and DoD IL4 customers used a separate support system that was not accessed.
Okta’s SEC filing described the company as a particularly attractive target for sophisticated nation-state actors and organized crime groups because it is a well-known identity and security provider. That is a statement about the risk of being targeted, not proof that a customer is unsafe by default.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Is Okta safe for a small business?
It can be, but “safe” depends on how the service is configured and operated. A small business should pay particular attention to who has administrator privileges, which authentication methods those people use, how support files are handled, and how quickly the organization can revoke a compromised session.
Okta’s The State of Secure Identity Report 2023, published in 2024, reports a 20.3% small-business figure in its analysis of fraudulent signups. That figure concerns fraudulent signups; it is not an Okta customer breach rate, a probability that a small business will be breached, or a comparison with another identity provider.
Rank #3
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
No apples-to-apples, independently measured breach-rate comparison between Okta and competing identity providers is established here. A provider choice is better assessed through concrete controls and operating needs: phishing resistance, administrative isolation, support-data handling, session revocation, incident transparency, integration coverage, migration cost, and recovery usability.
How to make Okta sign-in more phishing resistant
Phishing-resistant authentication creates a cryptographic relationship between the authenticator and the legitimate service. That helps prevent authentication data from being disclosed to a fake site. Okta’s guidance identifies FastPass, FIDO2/WebAuthn passkeys, and smart cards as supported phishing-resistant methods.
Rank #4
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- Protect administrators first. Require phishing-resistant authentication for Okta administrators and other privileged roles. These accounts can change access policies and affect many users, so they merit stronger protection than a standard account.
- Use strong methods for sensitive access. Prefer FIDO2/WebAuthn, FastPass, or smart-card methods for sensitive applications instead of relying only on SMS, email, or one-time codes. The exact options available depend on your configuration and the application.
- Review support workflows. Treat HAR files and other diagnostic exports as potentially sensitive. Limit who can create, receive, and retain them, and avoid sharing session tokens or unnecessary authentication data.
- Monitor and respond. Review sign-in and authenticator events. Investigate unexpected new devices or IP addresses, and keep a workable process for revoking sessions when an account may be compromised.
- Test recovery before enforcement. Verify account recovery and security-key replacement with real users before requiring hardware keys broadly. Maintain recovery keys and carefully controlled break-glass accounts so a lost authenticator does not lock the business out.
Is a YubiKey better than Okta Verify?
They are not direct substitutes. Okta is the identity service; Okta Verify is an authenticator option, while a YubiKey is a physical security key that can be used as a WebAuthn factor. The meaningful comparison is between the authentication methods configured for the account, not between the key and the identity platform.
| Option | What the cited Okta documentation establishes | Practical consideration |
|---|---|---|
| YubiKey using WebAuthn | Okta documents YubiKey as a WebAuthn factor based on FIDO2 standards and rates WebAuthn strongly for phishing and real-time man-in-the-middle resistance. | Check that the exact key model, connector, devices, and account configuration work for your users. Plan for lost-key replacement and account recovery. |
| Okta Verify | The cited phishing-resistance guidance names FastPass as a supported method; it does not establish that every Okta Verify sign-in method is phishing resistant. | Check the specific Verify method and policy you use. Do not assume that an authenticator app name alone guarantees phishing resistance. |
| SMS, email, or one-time-code-only methods | Okta’s recommended sequence prefers phishing-resistant methods over these options for sensitive applications. | Do not make these the sole protection for privileged or especially sensitive access when a supported phishing-resistant method is available. |
Okta’s pre-enrolled YubiKey documentation describes phishing-resistant, passwordless authenticators such as YubiKey as difficult for attackers to intercept or replicate. That protection does not remove the need to protect administrator accounts, manage recovery, or respond to suspicious sessions.
Best Value
- OTP token that provides secure remote access with strong authentication
- Easy to use and easy to carry
- Expected battery life is approximately 7 years
Should you switch away from Okta after the breach?
The 2023 incident alone does not establish that switching will make a business safer. Before deciding, compare the controls you can actually operate in Okta with those available from a candidate provider. Include the practical cost of migrating users, applications, policies, and recovery procedures—not just feature lists.
- Compare phishing resistance: Can you require a strong method for administrators and sensitive applications?
- Examine administrative exposure: Can you restrict and monitor powerful accounts, and separate them from everyday use?
- Review support-data handling: What diagnostic files and account details might be accessible through support workflows, and how are they protected?
- Check incident response: Can your team revoke sessions, investigate sign-ins, and understand a provider’s incident disclosures?
- Evaluate fit and recovery: Do integrations cover the services you use, and can users recover accounts without creating a new security weakness?
- Calculate migration cost: Account for implementation, testing, user disruption, and the work of replacing existing integrations and policies.
If those checks reveal a control gap that you cannot address, migration may be reasonable. If they do not, improving authentication, support-data handling, monitoring, and recovery may be a more direct response than changing providers.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

