Okta
What this guide covers
How to actually buy Okta for a Maryland agency — which statewide vehicle you ride, which reseller fulfills the order, the FedRAMP/ATO path, and the functionality gates to clear before you sign. Okta’s Maryland path runs through NASPO and a dedicated DoIT Okta agreement rather than the COTS line, and its FedRAMP High authorization attaches to a specific government boundary — both decisions matter here.
Who it’s for
Engineering leads, identity/security staff, and procurement officers at a Maryland State agency or education entity who have decided they need Okta for IdP, SSO, or identity governance (or are comparing it against the self-hosted alternatives) and need the path from “we want it” to “it’s authorized and on contract.”
Part of the SaaS Catalog. For the vehicles themselves, see Maryland Master Contracts; for the process and thresholds, see Maryland Procurement.
Disclaimer. Not legal or procurement advice. FedRAMP authorizations, contract catalogs, and contract numbers change as awards are renewed and authorizations are re-baselined. Verify every figure below against the FedRAMP Marketplace, the Carahsoft Okta contracts page, and the DoIT Statewide Contracts hub before relying on it. Whether Okta sits on the specific Carahsoft MD COTS line is unverified (see below) — confirm against the live catalog.
TL;DR
- Category: Identity — IdP / SSO / identity governance (Workforce Identity Cloud).
- Maryland vehicle: NASPO ValuePoint (master agreement AR2472) via Carahsoft, plus a DoIT Okta renewal ICPA (signed 2024). Whether Okta sits on the specific Carahsoft MD COTS line (060B2490021) is UNVERIFIED — confirm against the live catalog.
- Reseller: Carahsoft — Okta’s named master government aggregator since 2016, and the only authorized reseller of Okta under the NASPO contract.
- Authorization: Okta IDaaS Government High Cloud (GHC) = FedRAMP High (certified 2023-03-23, Marketplace ID FR2131856836, marketed as “Okta for Government High”). A separate Okta for Government Moderate boundary (DoD IL-4) also exists. Okta Workflows also reached FedRAMP High.
- The ATO trap: Use the Okta for Government High (GHC) boundary for FedRAMP High — the commercial Okta Workforce Identity Cloud tenant is a different boundary.
What This Tool Is
Okta is a SaaS identity platform — its Workforce Identity Cloud provides the identity provider (IdP), single sign-on (SSO), multi-factor authentication, lifecycle management, and identity governance that front your agency’s applications. Agencies reach for Okta when they want a managed, broadly integrated IdP instead of operating one themselves. The self-hostable IdP alternatives are Authentik / Authelia / Keycloak — see Tools and Software → Identity & Access — but for a managed, FedRAMP-authorized IdP most agencies treat Okta as a procurement-and-ATO exercise, which is what this page covers.
Which Maryland Vehicle
| Vehicle | Contract | How Okta rides it |
|---|---|---|
| NASPO ValuePoint | Master agreement AR2472 (via Carahsoft) | The primary path. Carahsoft fulfills your order against the NASPO ValuePoint master agreement through Maryland’s participating addendum. |
| DoIT Okta renewal ICPA | Intergovernmental cooperative purchasing agreement (signed 2024) | A Maryland-specific Okta renewal vehicle DoIT entered; confirm eligibility and ceiling terms for your order. |
| MD COTS 2012 | 060B2490021 (unverified) | Whether Okta sits on the specific Carahsoft MD COTS line is unverified — confirm against the live Carahsoft MD COTS catalog before assuming this path. |
The clear paths are NASPO (AR2472) and the DoIT Okta ICPA. The same publisher can be reachable through more than one vehicle, and which one you ride affects ceiling pricing, terms, and which approvals apply — see Maryland Master Contracts → Where Carahsoft Fits.
Resellers and Pricing Path
Carahsoft is Okta’s named master government aggregator (since 2016) and the only authorized reseller of Okta under the NASPO contract. You do not buy a “Carahsoft contract” — Carahsoft fulfills your order against the NASPO ValuePoint master agreement (AR2472) or the DoIT Okta ICPA. Request a quote referencing the NASPO AR2472 master agreement (or the DoIT Okta ICPA) so the order is priced against the cooperative ceiling rather than commercial list price. Okta is licensed per-user by product/SKU, so the quote depends on your user count and which Okta products you select — size both before you ask.
Authorization and ATO
| Attribute | Value |
|---|---|
| Authorized offering | Okta IDaaS Government High Cloud (GHC) — marketed as “Okta for Government High” |
| FedRAMP status | High — certified 2023-03-23 |
| Marketplace ID | FR2131856836 |
| Other boundaries | Separate Okta for Government Moderate boundary (DoD IL-4); Okta Workflows also reached FedRAMP High |
| Commercial Workforce Identity Cloud tenant in scope? | No — it is a different boundary, not the High ATO |
The single thing to get right for the ATO: provision the Okta for Government High (GHC) boundary if you need FedRAMP High. The FedRAMP High authorization attaches only to the GHC boundary (FR2131856836) — the commercial Okta Workforce Identity Cloud tenant is a different boundary and is not the High ATO. If your classification only requires Moderate, the separate Okta for Government Moderate boundary may apply instead. Confirm the boundary matches your data classification before you commit; provisioning the commercial tenant gives you no High authorization to inherit, and the gap will surface late in your security review.
Functionality Gates to Verify
Clear these before price comparison — any one can disqualify the buy regardless of cost. See the canonical list in Tools and Software → Enterprise Functionality.
| Gate | Okta-specific note |
|---|---|
| SSO (SAML/OIDC) + SCIM | Core to the product; confirm the SCIM provisioning connectors you need are included at your tier. |
| Audit logs | Available (System Log); confirm retention and export meet your records policy. |
| RBAC | Granular admin roles supported; map them to least-privilege before rollout. |
| Data residency / FedRAMP boundary | The Okta for Government High (GHC) boundary is the residency answer — confirm the correct boundary (see above). |
| Accessibility (VPAT/ACR) | Request Okta’s current VPAT; Maryland’s Nonvisual Access (NVA) requirement applies to the procurement. |
| BAA / DPA | Required if any identity data could carry PII/PHI; confirm availability for the government boundary. |
Procurement Steps
- Confirm the need over the OSS alternative. Okta replaces the self-hostable Authentik / Authelia / Keycloak IdPs ($0 license). Document why a managed IdP is worth the spend — that rationale is the core of the budget justification.
- Register / confirm eMMA. Your agency and the reseller must be set up in eMMA.
- Pick the vehicle. Default to NASPO ValuePoint AR2472 or the DoIT Okta ICPA; confirm whether the MD COTS line applies before relying on it (unverified).
- Determine your boundary. Decide whether your data classification requires Okta for Government High (GHC) or the Moderate boundary — this drives what you inherit.
- Get a Carahsoft quote referencing AR2472 (or the DoIT Okta ICPA), sized to your user count and product selection, for the correct government boundary.
- Check the threshold. The order’s dollar value drives the method — purchasing card, small procurement, or BPW review. See Maryland Procurement → how the value picks the path. Do not split a buy to dodge a threshold.
- Run the ATO package. Inherit the FedRAMP controls for the Okta for Government High (GHC) boundary; document the rest.
- Issue the order against the vehicle once approvals clear.
Sources
| Claim | Source |
|---|---|
| Okta IDaaS Government High Cloud (GHC) FedRAMP High (FR2131856836) | FedRAMP Marketplace — FR2131856836 |
| Okta for Government High achieves FedRAMP High | Okta — Okta for Government High Achieves FedRAMP High Authorization |
| Carahsoft as Okta’s NASPO reseller / contracts | Carahsoft — Okta contracts |
| Maryland DoIT Okta renewal ICPA (2024) | MD DoIT Okta Renewal ICPA (signed) |
Whether Okta sits on the specific Carahsoft MD COTS line (060B2490021) is unverified. Confirm the vehicle and the current FedRAMP boundary against the Carahsoft Okta contracts page and the Marketplace listing before relying on any figure here.
Related Resources
- Next: set it up — Okta implementation → — Day 0 → Day 2 configuration and gov-readiness
- SaaS Catalog — Playbook — all tools, compared in one matrix
- Maryland Master Contracts — COTS / CATS+ / Carahsoft, the vehicle this rides
- Maryland Procurement — BPW, eMMA, COMAR thresholds, the process that still binds the order
- Federal Procurement — the federal analog (FAR, GSA Schedules, SAM.gov)
- Tools and Software → Identity & Access — Okta vs. the self-hosted OSS IdPs it replaces
- Tools and Software → Enterprise Functionality — the gates to clear before price