Skip to main content
Fabio Grasso

Fabio Grasso

  • 👋 Ciao! I’m Fabio, a Solutions Engineer specialized in 🔐 Identity & Access Management (IAM). I work between France 🇫🇷 and Italy 🇮🇹 for Okta.
  • 📚 In this space, I share ideas, experiences, and insights about the world of digital identity.
  • 🌍 Although this site is multilingual and some posts are also in Italian and French, most content is in English. To see everything, pick English as your language.

Recent

Okta PAM for Databases: Secure Privileged Access Guide

How Okta Privileged Access database integrations discover privileged database accounts, vault and rotate their credentials, and expose checkout through policies with MFA or approvals. The guide explains the Early Access architecture, required gateway role, account rules, and a ready-to-run Docker lab with MySQL, DBGate, and an Infrastructure Orchestrator gateway.

Okta PAM Workloads: Secure Automation Access

Okta Privileged Access 2026.04.0 introduced workload identity for automation. This article explains how Workloads helps CI/CD pipelines, infrastructure automation, cloud workloads, scripts, and AI agents authenticate with native platform identity and runtime OIDC tokens instead of hardcoded API keys or service account secrets. Today the available workload access pattern is Principal SSH access; additional use cases will be added when available.

Okta Sign-In Widget: Auto-Submit Email or SMS Authenticator

When using Okta Identity Engine (OIE), the Sign-In Widget shows an authenticator selection screen that requires the user to manually pick Email or SMS before proceeding. If your policy only allows one method, this extra click adds friction with no benefit. Here’s how to skip it entirely with a small JavaScript customization in the Sign-In Widget.

Powered by Hugo Streamline Icon: https://streamlinehq.com Hugo Hugo & Blowfish