Okta Certified Consultant Hands-On Configuration Exam Study Guide
To learn how to prepare for your Okta Certification Exam, watch our video here.
Introduction
Congratulations! You are one step closer toward earning your Okta Certified Consultant certification!
This exam study guide is designed to help you prepare for the Okta Consultant Hands-On Configuration Certification Exam. Passing this exam is a requirement for becoming an Okta Certified Consultant. It is also a prerequisite for anyone seeking to become an Okta Certified Technical Architect. The Okta Consultant Hands-On Configuration exam is based on the Okta Identity Engine and includes both Discrete Option Multiple Choice (DOMC) questions and hands-on configuration tasks.
What does it mean to be an Okta Certified Consultant?
Okta Certified Consultants are technically proficient at implementing the Okta service in a variety of configurations. Consultants have experience integrating common applications such as Microsoft Office 365, Google Workspace, Box, and Salesforce with Okta. They also have extensive knowledge and experience scoping and implementing complex Okta integrations involving multi-forest and multi-domain environments, advanced single sign-on (SSO), and inbound federation with Okta. Consultants have working knowledge of Okta APIs and custom configuration options.
Exam Overview
|
Number and types of questions |
This exam has two parts.
|
|
Case study |
This exam has two case studies.
|
|
Time allotted |
180 minutes |
|
Exam Fee |
USD 250 (USD 100 for each subsequent retake) |
|
Prerequisites |
|
Preparing for the Okta Consultant Hands-On Configuration Exam
Okta Learning offers several courses to help you begin your preparation for this certification exam. Although completing a training class does not guarantee success on an Okta certification exam, we strongly recommend that you complete the following learning paths:
- Configure Role-Based and Attribute-Based Access Control with Okta
- Set Up Enterprise Inbound Federation - This path is only available as a part of the Expert Learning Pass.
Note for Okta Partners: This content is available to all active Partners at no cost via the Okta Learning Portal when they login with their Partner Portal credentials.
Practice Exams
To further help you in your preparation and to improve your skills, we highly encourage you to take the following practice exams. These exams simulate the real certification exam environment and will give you a great opportunity to test your knowledge and skills.
-
- Standard Practice Exams
- Take the free Okta Consultant Standard Practice Exam to familiarize yourself with the format of the DOMC item type. Click the link to check it out.
- Premier Practice Exam
- Take the Okta Consultant Premier Practice Exam to evaluate your readiness for the Okta Certified Consultant exam. The Okta Consultant Premier Practice Exam measures many of the same topic areas and configuration tasks that are measured in the Consultant certification exam. Click the button below to check it out.
- Standard Practice Exams
Consultant Hands-On Configuration Exam subject areas
Part I
The following table lists the topics that are covered in Part I of this exam. These topics are grouped into topic areas, and topic areas roll up into domains/exam sections. Use this list as an outline to guide your study and validate your readiness for Part I of this exam.
|
Exam Section |
Percentage of Exam Related to Section |
Implementing Advanced Sourcing |
8% |
"As a Source" setup and configuration flow |
|
|
Configure attribute level sourcing and configure the priority of the profile sources in an Okta org |
Preparation resources: |
|
Demonstrate understanding of the priority of the profile sources in an Okta org |
Preparation resources: |
Advanced Sourcing Concepts |
|
|
Understand the architecture of advanced sourcing (Example: the flow of attribute data), including how to deploy, test, and troubleshoot common sourcing configurations |
Preparation resources: |
Data Migration Strategy |
|
|
Know the common data migration patterns, including the steps to migrate user data and passwords from an existing system to Okta |
Preparation resources: |
HR-as-a-Source (scenarios) |
|
|
Know how to deploy, test and troubleshoot common sourcing configurations, including HR as a source options such as OIN, API as a source, and CSV directory, and understand the flow of attribute data |
Preparation resources: |
Profile Mappings (Profile Editor) |
|
|
Know how to map attributes from source systems to target systems, how to identify basic attribute transformations, and how to troubleshoot common attribute mapping issues |
Preparation resources: |
Implementing Advanced SSO Strategies |
15% |
Advanced SAML implementation scenarios |
|
|
Know how to use the SAML Wizard and how to perform attribute mappings on SAML assertions |
Preparation resources: |
Advanced Server Access concepts and overview |
|
|
Understand what Advanced Server Access management is and be able to speak to its common use cases |
Preparation resources: |
Okta Access Gateway (OAG) |
|
|
Understand what Okta Access Gateway management is and be able to speak to its common use cases |
Preparation resources: |
OIDC Flows |
|
|
Know the OAuth 2.0 roles of the authorization server, resource server, and resource owner |
Preparation resources: |
|
Know when to use the various OIDC flows based on the type of application (Example: mobile apps, single page applications, web applications on the server side) |
Preparation resources: |
Okta RADIUS Agent for an SSO Solution |
|
|
Know when to use the Okta RADIUS Agent |
Preparation resources: |
|
Know how to configure the Okta RADIUS Agent for an SSO Solution (e.g., to connect from Okta to a VPN); understand the nuances of RADIUS; know which protocols are supported |
Preparation resources: |
Testing and Troubleshooting SSO Integrations |
|
|
Know the various error codes, including the types of tools that Okta recommends to use for troubleshooting SSO integrations, as well as the tools used during each step |
Preparation resources: |
Implementing Custom Configuration Options with Okta |
19% |
Architecture, capabilities, and common use cases of OPP |
|
|
Understand the common use cases for OPP and know the supported OPP features such as create, update, deactivate, and sync password |
Preparation resources: |
Custom Email Domain |
|
|
Know the common use cases for custom email domain |
Preparation resources: |
Deployment Models & the Authentication API |
|
|
Know what's possible with the out of the box sign-in screen vs sign-in widget, custom vanity login UI, etc. |
Preparation resources: |
|
Know the pros and cons of the different deployment models |
Preparation resources: |
Custom URL Domain |
|
|
Know when custom URL domain should be used |
Preparation resources: |
|
Know the difference between BYO and Okta managed certificate, including the pros and cons of each |
Preparation resources: |
MFA as a service |
|
|
Know how to implement, test and troubleshoot configuration of MFA as a Service (MFA for Active Directory Federation Service) |
Preparation resources: |
Okta Hooks |
|
|
Know the various use cases and differences between the different types of hooks |
Preparation resources: |
SCIM App Wizard |
|
|
Know how to implement, test and troubleshoot the SCIM App Wizard |
Preparation resources: |
Implementing Directory Solutions |
13% |
Active Directory Integration |
|
|
Know how to size the Okta Active Directory Agent deployment, configure the Okta Active Directory agent to communicate with multiple domains, configure the Okta Active Directory agent for throughput, configure verbose logging, and configure the proxy settings |
Preparation resources: |
|
Know how to test and troubleshoot common configuration issues in multi-forest/multi-domain environments |
Preparation resources: |
Advanced configuration with DSSO |
|
|
Know how to implement, test, and troubleshoot Agentless Desktop SSO |
Preparation resources:
|
LDAP Integration |
|
|
Know the common use cases for LDAP Agent such as delegated authentication and provisioning to existing LDAP environments, as well as the process to integrate LDAP with Okta |
Preparation resources: |
|
Know the functional differences between Active Directory integration and LDAP integration |
Preparation resources: |
LDAP Interface |
|
|
Understand the existence of the LDAP interface and how it can be used |
Preparation resources: |
Implementing Inbound Federation with Okta |
13% |
IdP Discovery |
|
|
Know how to deploy, test and troubleshoot IdP discovery when configured in Okta, including configuring IdP policy, and IdP routing rules based on user attributes, group membership, etc. |
Preparation resources: |
Okta as a service provider with a 3rd party IdP |
|
|
Know when to use Okta as a service provider (SP) with a 3rd party identity provider (IdP) |
Preparation resources: |
|
Know how to generate IDP-initiated URLs |
Preparation resources: |
Social Identity Providers |
|
|
Know how to implement social login with Okta, including configuring the various components required for social login, such as OAuth 2.0 client in the social provider, an identity provider in Okta, and an OIDC application in Okta |
Preparation resources: |
Inbound Federation |
|
|
Know how to troubleshoot Inbound Federation |
Preparation resources: |
|
Understand how account linking functions |
Preparation resources: |
|
Understand best practices for Inbound Federation |
Preparation resources: |
|
Know when to use Okta Org2Org and how to configure it |
Preparation resources: |
Implementing Okta Policies |
15% |
Okta FastPass |
|
|
Know how OktaFastPass works, the benefits, and the end user experience |
Preparation resources: |
Global Session Policy with Behavioral Detection |
|
|
Know how to explain, deploy, and troubleshoot Behavioral Detection for Global Session Policy |
Preparation resources: |
|
Know how to explain, deploy, and troubleshoot Behavioral Detection for Global Session Policy |
Preparation resources: |
Authentication Policies |
|
|
Know how to explain, deploy, and troubleshoot authentication policies |
Preparation resources: |
Pre-Authn Sign-on Evaluation Policy |
|
|
Understand the benefits of the Pre-authn sign-on evaluation policy |
Preparation resources: |
ThreatInsight |
|
|
Understand when to use ThreatInsights and know how to configure it |
Preparation resources: |
|
Know the capabilities/supported systems that Okta can ingest |
Preparation resources: |
Working with Okta APIs |
6% |
API Code Collection |
|
|
Know the common use cases for Okta APIs, including options for accessing Okta APIs |
Preparation resources: |
Commonly used scripted API calls (Example: deactivate/delete all users in group) |
|
|
Know which APIs are in the Okta API collection, the commonly used ones and what they are used for; but not the exact calls |
Preparation resources: |
OAuth/API AM wrt best practices |
|
|
Know why API AM should be used and why a customer would want a custom authorization server and the security the customer gains by using it |
Preparation resources: |
Working with API Access Management |
11% |
API Code Collection |
|
|
Know the common use cases for API Access Management, how to create a custom authorization server, and how to properly add claims |
Preparation resources: |
Entitlement architecture - Claims vs. Scopes and Their Relationship |
|
|
Know the differences between claims and scopes and how claims and scopes are used in the context of OIDC |
Preparation resources: |
|
Configure API AM Access Policies |
Preparation resources: |
OAuth Grant Types (Including Interaction Flow) |
|
|
Know when to use the various OAuth grant types |
Preparation resources: |
Okta SDKs |
|
|
Know when to use the various OAuth grant types |
Preparation resources: |
Part II
The following table lists the use cases and tasks that are assessed in this exam. Information about each task in the exam is provided in the reference links.
Use Case |
Percentage of Exam Related to Use Case |
App Integrations |
25% |
|
Configuration tasks:
|
Preparation resources: |
Creating a Custom Admin |
25% |
|
Configuration tasks:
|
Preparation resources: |
Configuring Policies |
25% |
|
Configuration tasks:
|
Preparation resources: |
Creating Routing Rules |
25% |
|
Configuration tasks:
|
Preparation resources: |
Other Resources
- The Okta Help Center contains a knowledge library of articles and videos, some of which are pertinent to topics covered on this exam.
- The Okta Content Library offers searchable white papers with a rich body of information to explore before your exam.
- Join the Okta Community to review questions, discussions, ideas, and blogs for additional exam preparation.
Subject matter experts for the Okta Certified Consultant Hands-On Configuration Exam
Okta certification exams are designed and built by subject matter experts who have extensive real world-experiences implementing and administering the Okta service.
Here is the list of subject matter experts who made significant contributions in designing and building this exam:
Anuj Aggarwal
Benjamin Chan
Chris Gustafson
Dale Huggins
Fabio Santos
James Garvin
Najar Aryal
Sarathkumar Manian
Serge Zhivotovsky
Shad Lutz
Yuki Tsuboi





























































