<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>I_AM Fabio — Okta, IAM &amp; Zero Trust Security Blog on I_AM Fabio</title>
    <link>https://iam.fabiograsso.net/</link>
    <description>Recent content in I_AM Fabio — Okta, IAM & Zero Trust Security Blog on I_AM Fabio</description>
    <generator>Hugo</generator>
    <language>en</language>
    <atom:link href="https://iam.fabiograsso.net/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Okta PAM Workloads: Secure Automation Access</title>
      <link>https://iam.fabiograsso.net/howto/okta-pam-workloads/</link>
      <pubDate>Mon, 15 Jun 2026 11:00:00 +0200</pubDate>
      <guid>https://iam.fabiograsso.net/howto/okta-pam-workloads/</guid>
      <description>Okta Privileged Access 2026.04.0 introduced workload identity for automation. This article explains how Workloads helps CI/CD pipelines, infrastructure automation, cloud workloads, scripts, and AI agents authenticate with native platform identity and runtime OIDC tokens instead of hardcoded API keys or service account secrets.</description>
    </item>
    <item>
      <title>Anyone Can Code… But Only the Rich Can Be Great!</title>
      <link>https://iam.fabiograsso.net/blog/ai-cost-2026/</link>
      <pubDate>Mon, 18 May 2026 09:00:00 +0000</pubDate>
      <guid>https://iam.fabiograsso.net/blog/ai-cost-2026/</guid>
      <description>A critical but not anti-AI reflection on costs, productivity, layoffs and human work in 2026. AI is real and useful, but the promise of replacing a team with a cheap monthly subscription is running into economic, technical and organizational limits.</description>
    </item>
    <item>
      <title>Okta Sign-In Widget: Auto-Submit Email or SMS Authenticator</title>
      <link>https://iam.fabiograsso.net/tips/okta-autoclick-email-or-sms/</link>
      <pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate>
      <guid>https://iam.fabiograsso.net/tips/okta-autoclick-email-or-sms/</guid>
      <description>When using Okta Identity Engine (OIE), the Sign-In Widget shows an authenticator selection screen that requires the user to manually pick Email or SMS before proceeding. If your policy only allows one method, this extra click adds friction with no benefit. Here&amp;rsquo;s how to skip it entirely with a small JavaScript customization in the Sign-In Widget.</description>
    </item>
    <item>
      <title>Times Square and AI in Cafés: What I Learned in New York</title>
      <link>https://iam.fabiograsso.net/blog/okta-ai-newyork/</link>
      <pubDate>Sun, 10 May 2026 10:00:00 +0000</pubDate>
      <guid>https://iam.fabiograsso.net/blog/okta-ai-newyork/</guid>
      <description>Back from a week in New York, I share how AI is now everywhere: from Times Square billboards to subways, from cafés to the laptops of students and professionals. A journey through advertising, real-world use, and governance risks in the era of AI agents.</description>
    </item>
    <item>
      <title>EU AI Act Compliance: Addressing the Identity Layer</title>
      <link>https://iam.fabiograsso.net/blog/okta-ai-compliance/</link>
      <pubDate>Sun, 26 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://iam.fabiograsso.net/blog/okta-ai-compliance/</guid>
      <description>EU AI Act, NIST AI RMF, NIS2, DORA: four regulatory frameworks, one identity layer. How Okta&amp;rsquo;s O4AA blueprint maps to every compliance requirement before the August 2026 deadline.</description>
    </item>
    <item>
      <title>Okta for AI Agents: Access Patterns Deep Dive</title>
      <link>https://iam.fabiograsso.net/blog/okta-ai-access-patterns-deep-dive/</link>
      <pubDate>Thu, 23 Apr 2026 10:00:01 +0000</pubDate>
      <guid>https://iam.fabiograsso.net/blog/okta-ai-access-patterns-deep-dive/</guid>
      <description>Protocol-level deep dive into the four Okta for AI Agents access patterns: ID-JAG token structure, sequence diagrams, audit log examples, and step-by-step Okta configuration for XAA, STS, PSK, and Service Account.</description>
    </item>
    <item>
      <title>Okta for AI Agents: Access Patterns</title>
      <link>https://iam.fabiograsso.net/blog/okta-ai-access-patterns/</link>
      <pubDate>Thu, 23 Apr 2026 10:00:00 +0000</pubDate>
      <guid>https://iam.fabiograsso.net/blog/okta-ai-access-patterns/</guid>
      <description>A strategic overview of the four access patterns for AI agent integrations — XAA, STS, PSK, Service Account — with a comparison matrix, decision framework, and migration roadmap. Companion deep dive covers protocol details and Okta configuration.</description>
    </item>
    <item>
      <title>Opaflix - Session Replay Viewer for Okta Privileged Access (OPA)</title>
      <link>https://iam.fabiograsso.net/howto/okta-opaflix-session-replay-tool/</link>
      <pubDate>Fri, 03 Apr 2026 04:00:00 +0000</pubDate>
      <guid>https://iam.fabiograsso.net/howto/okta-opaflix-session-replay-tool/</guid>
      <description>Opaflix is an open-source tool to browse and replay Okta Privileged Access (OPA) SSH and RDP session recordings from AWS S3. Supports single-tenant and multi-tenant deployments, advanced search, infrastructure graph, and OIDC Authentication.</description>
    </item>
    <item>
      <title>Securing AI: Okta&#39;s Blueprint for the Secure Agentic Enterprise</title>
      <link>https://iam.fabiograsso.net/blog/okta-ai-blueprint/</link>
      <pubDate>Wed, 18 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://iam.fabiograsso.net/blog/okta-ai-blueprint/</guid>
      <description>Okta&amp;rsquo;s Showcase 2026 unveils the Agentic Enterprise Blueprint: a comprehensive framework to discover, govern, and secure AI agents as first-class identities, addressing the emerging shadow AI crisis and regulatory compliance requirements.</description>
    </item>
    <item>
      <title>Okta On-premises Connector for Generic Databases: A Complete Guide</title>
      <link>https://iam.fabiograsso.net/howto/okta-generic-jdbc-connector/</link>
      <pubDate>Sun, 01 Mar 2026 12:00:00 +0100</pubDate>
      <guid>https://iam.fabiograsso.net/howto/okta-generic-jdbc-connector/</guid>
      <description>Comprehensive guide to deploying Okta&amp;rsquo;s On-Premises Provisioning Agent, SCIM Server, and Generic Database Connector using Docker Compose. Covers architecture, setup, configuration, stored procedures, entitlement management, and testing workflows for bridging Okta with on-premises databases.</description>
    </item>
    <item>
      <title>Integrating Okta with IBM i (AS/400) for MFA and Lifecycle Management</title>
      <link>https://iam.fabiograsso.net/howto/okta-as400-ibmi/</link>
      <pubDate>Fri, 30 Jan 2026 10:00:00 +0000</pubDate>
      <guid>https://iam.fabiograsso.net/howto/okta-as400-ibmi/</guid>
      <description>A comprehensive guide to modernizing IBM i (AS/400) security by integrating Okta. This post covers MFA for terminal access using Precisely and explores two options for Lifecycle Management (LCM): the Okta OPP agent with custom scripts and the Aquera SCIM gateway.</description>
    </item>
    <item>
      <title>Grand Canyon, Sedona &amp; Route 66 from Phoenix to Las Vegas (2.5 Days)</title>
      <link>https://iam.fabiograsso.net/travels/phoenix-sedona-grandcanyon-route66/</link>
      <pubDate>Sun, 28 Dec 2025 00:00:00 +0000</pubDate>
      <guid>https://iam.fabiograsso.net/travels/phoenix-sedona-grandcanyon-route66/</guid>
      <description>This is the first post in the travel section of the new blog! As Solutions Engineers and employees of SaaS companies, many of us find ourselves in Las Vegas at least once a year for corporate events like SKO (Sales Kick-Off), Oktane, or similar conferences. Instead of just taking the usual direct flight, why not seize the opportunity to explore some of America&amp;rsquo;s most iconic natural wonders?&#xA;</description>
    </item>
    <item>
      <title>GLPI 11 &#43; Okta: SSO and SCIM Provisioning Guide</title>
      <link>https://iam.fabiograsso.net/howto/okta-glpi-11/</link>
      <pubDate>Sat, 15 Nov 2025 15:46:00 +0200</pubDate>
      <guid>https://iam.fabiograsso.net/howto/okta-glpi-11/</guid>
      <description>How to integrate GLPI 11, an open-source IT service management platform, with Okta for SSO. It covers running a GLPI test environment via Docker, LDAP and SAML configuration walkthroughs, and notes on OAuth/OIDC with commercial plugins. The guide highlights user import, authentication options, demo readiness, and security limitations for non-production use.</description>
    </item>
    <item>
      <title>Lab for test the Okta LDAP Agent with (or without) Docker</title>
      <link>https://iam.fabiograsso.net/howto/okta-lab-ldap/</link>
      <pubDate>Fri, 07 Nov 2025 09:00:00 +0100</pubDate>
      <guid>https://iam.fabiograsso.net/howto/okta-lab-ldap/</guid>
      <description>Introduction # This guide provides a step-by-step walkthrough for deploying the OpenLDAP directory service, and integrate it with Okta, using Docker and Docker Compose.&#xA;</description>
    </item>
    <item>
      <title>Lab for test the Okta MCP Server with (or without) Docker</title>
      <link>https://iam.fabiograsso.net/howto/okta-lab-mcp/</link>
      <pubDate>Sun, 05 Oct 2025 09:00:00 +0100</pubDate>
      <guid>https://iam.fabiograsso.net/howto/okta-lab-mcp/</guid>
      <description>Set up an Okta MCP Server lab for AI-assisted administration using Docker Compose or native install, with practical examples for Claude, Gemini, and VS Code workflows.</description>
    </item>
    <item>
      <title>Quis Custodiet Ipsos Custodes: Why Independent IAM is Essential for Security</title>
      <link>https://iam.fabiograsso.net/blog/quis-custodiet-ipsos-custodes/</link>
      <pubDate>Wed, 03 Sep 2025 05:00:00 +0200</pubDate>
      <guid>https://iam.fabiograsso.net/blog/quis-custodiet-ipsos-custodes/</guid>
      <description>Who will guard the guards themselves? A critical analysis of vendor lock-in risks in IAM and the advantages of an agnostic approach based on Identity Fabric and open standards.</description>
    </item>
    <item>
      <title>Banks under siege. The Strategy: Identity Fabric</title>
      <link>https://iam.fabiograsso.net/blog/report-banca-italia-2024/</link>
      <pubDate>Fri, 29 Aug 2025 00:00:00 +0000</pubDate>
      <guid>https://iam.fabiograsso.net/blog/report-banca-italia-2024/</guid>
      <description>Analysis of 2024 banking cyber incidents (+45%) according to Banca d&amp;rsquo;Italia report and the Identity Fabric strategy for operational resilience in the Italian and European financial sector.</description>
    </item>
    <item>
      <title>Okta RADIUS Agent &#43; Test Client &#43; OpenVPN AS with Docker-compose</title>
      <link>https://iam.fabiograsso.net/howto/okta-radius-docker-compose/</link>
      <pubDate>Sun, 24 Aug 2025 06:25:00 +0000</pubDate>
      <guid>https://iam.fabiograsso.net/howto/okta-radius-docker-compose/</guid>
      <description>Complete Docker-compose stack for testing Okta RADIUS Agent with OpenVPN AS, including automated MFA test scripts and configuration examples. The guide covers setup, configuration, client IP reporting, supported factors, and security best practices.</description>
    </item>
    <item>
      <title>NIST SP 800-63-4: The New Era of Phishing-Resistant Authentication</title>
      <link>https://iam.fabiograsso.net/blog/2025-nist-sp-800-63-4/</link>
      <pubDate>Mon, 18 Aug 2025 00:00:00 +0000</pubDate>
      <guid>https://iam.fabiograsso.net/blog/2025-nist-sp-800-63-4/</guid>
      <description>Technical analysis of the innovations introduced by NIST SP 800-63-4: from the end of forced password expiration to the emphasis on phishing-resistant authentication, with practical parallels on Okta products.</description>
    </item>
    <item>
      <title>Welcome to my new blog: minimal, serverless and open</title>
      <link>https://iam.fabiograsso.net/internal/2025-new-blog/</link>
      <pubDate>Sun, 17 Aug 2025 00:00:00 +0000</pubDate>
      <guid>https://iam.fabiograsso.net/internal/2025-new-blog/</guid>
      <description>Launch of my new blog dedicated to cybersecurity, IAM and CIAM, built with Hugo and hosted on Cloudflare Pages</description>
    </item>
    <item>
      <title>About me - Fabio Grasso</title>
      <link>https://iam.fabiograsso.net/about/</link>
      <pubDate>Sun, 03 Aug 2025 00:00:00 +0000</pubDate>
      <guid>https://iam.fabiograsso.net/about/</guid>
      <description> 👋 I&amp;rsquo;m Fabio Grasso, a Solutions Engineer at Okta, specialized in Identity &amp;amp; Access Management (IAM/CIAM). I work between France 🇫🇷 and Italy 🇮🇹, helping companies on their journey toward secure digital transformation.&#xA;</description>
    </item>
    <item>
      <title>Citrix Step-Up MFA with Okta: Workspace and StoreFront</title>
      <link>https://iam.fabiograsso.net/howto/okta-citrix-stepup-mfa/</link>
      <pubDate>Fri, 27 Jun 2025 00:00:00 +0000</pubDate>
      <guid>https://iam.fabiograsso.net/howto/okta-citrix-stepup-mfa/</guid>
      <description>Learn how to implement step-up MFA with Okta in Citrix environments. This article explores three practical solutions: Okta group-based policies, dual-StoreFront architecture, and Citrix ADC with nFactor authentication. Discover the best approach for your organization.</description>
    </item>
    <item>
      <title>AWS Utilities EC2 with Workflows and auto-update DNS</title>
      <link>https://iam.fabiograsso.net/howto/aws-ec2-workflows/</link>
      <pubDate>Mon, 16 Jun 2025 00:00:00 +0000</pubDate>
      <guid>https://iam.fabiograsso.net/howto/aws-ec2-workflows/</guid>
      <description>Automate AWS EC2 power management and DNS updates using Okta Workflows, AWS Lambda, and CloudWatch. Start and stop VMs from the Okta dashboard, enforce scheduled shutdowns, and dynamically update DNS records. The guide covers setup steps, security considerations, and cost management in AWS demo environments.</description>
    </item>
    <item>
      <title>Federating Microsoft 365 / EntraID Guest Accounts with Okta</title>
      <link>https://iam.fabiograsso.net/tips/guest-accounts-microsoft-office-365-entraid/</link>
      <pubDate>Sun, 23 Mar 2025 00:00:00 +0000</pubDate>
      <guid>https://iam.fabiograsso.net/tips/guest-accounts-microsoft-office-365-entraid/</guid>
      <description>How to handle EntraID B2B guest accounts in Okta: tenant-specific OIDC endpoints, username mapping, and the common pitfalls that block sign-in.</description>
    </item>
    <item>
      <title>Mac OS - Resize Window to a specific size</title>
      <link>https://iam.fabiograsso.net/tips/mac-os-resize-window-to-a-specific-size/</link>
      <pubDate>Fri, 16 Feb 2024 00:00:00 +0000</pubDate>
      <guid>https://iam.fabiograsso.net/tips/mac-os-resize-window-to-a-specific-size/</guid>
      <description>Automate Mac OS window resizing with AppleScript to set precise dimensions and position for applications, useful for video recording or screen sharing.</description>
    </item>
    <item>
      <title>GLPI 10 &#43; Okta: SSO and SCIM Provisioning Guide</title>
      <link>https://iam.fabiograsso.net/howto/okta-glpi-10/</link>
      <pubDate>Wed, 15 Nov 2023 15:46:00 +0200</pubDate>
      <guid>https://iam.fabiograsso.net/howto/okta-glpi-10/</guid>
      <description>How to integrate GLPI, an open-source IT service management platform, with Okta for SSO. It covers running a GLPI test environment via Docker, LDAP and SAML configuration walkthroughs, and notes on OAuth/OIDC with commercial plugins. The guide highlights user import, authentication options, demo readiness, and security limitations for non-production use.</description>
    </item>
    <item>
      <title>Base64 Header in Okta Access Gateway</title>
      <link>https://iam.fabiograsso.net/howto/base64-header-oag/</link>
      <pubDate>Fri, 11 Aug 2023 15:46:00 +0200</pubDate>
      <guid>https://iam.fabiograsso.net/howto/base64-header-oag/</guid>
      <description>This guide explains how to send Base64-encoded HTTP headers with Okta Access Gateway (OAG) using nginx configuration extensions. It covers internal-only app setup, usage of OpenResty modules, and examples for encoding user data in headers. Solutions include native nginx directives and Lua scripting, supporting common legacy integration needs for secure internal communication and custom header enrichment.</description>
    </item>
    <item>
      <title>Okta Flask SCIM Server with Docker Compose</title>
      <link>https://iam.fabiograsso.net/howto/okta-flask-scim-server-docker-compose/</link>
      <pubDate>Wed, 09 Aug 2023 12:25:00 +0000</pubDate>
      <guid>https://iam.fabiograsso.net/howto/okta-flask-scim-server-docker-compose/</guid>
      <description>Enable rapid SCIM server testing with Okta using Flask, Docker Compose, and ngrok tunnels. This guide details a working starter solution with persistent PostgreSQL data, Makefile commands for easy management, and public access via ngrok. Ideal for demo and development, it supports Okta provisioning but implements no production-grade security. Sample endpoints, troubleshooting notes, and port references included for quick setup.</description>
    </item>
  </channel>
</rss>