Skip to content

This tool is not affiliated with, endorsed by or sponsored by Okta, Inc. Okta is a trademark of Okta, Inc. Other names are trademarks of their respective owners.

Glossary

Super Administrator (Okta)

The most privileged Okta admin role, able to manage every setting, admin and identity provider in the org; the main target of tenant takeovers.

Super Administrator is the highest standard admin role in Okta: it can manage all users, apps, policies, identity providers and other administrators (Okta Help Center: administrators). That makes it the prize in identity attacks. In the System Log, a grant appears as user.account.privilege.grant (or group.privilege.grant for a group), with the role in debugContext.debugData.privilegeGranted. A new Super Administrator created from a freshly compromised admin session is the classic persistence step. See admin role and API token abuse.

This tool is not affiliated with, endorsed by or sponsored by Okta, Inc. Okta is a trademark of Okta, Inc. Other names are trademarks of their respective owners.