CAS is a tool to authenticate a user, but this is not the same as authorizing one. Effortlessly integrate with enterprise directories or identity providers. It's still relatively small in terms of our partner channels, but it's growing quite rapidly. The JWKS should look something like this: Generate a public/private key pair using the Admin Console. They don't have as many as they expected, so they're not going to buy more, or maybe they have less than they had when they originally contractually agreed with us. And it's interesting that all these trends we track are impacting both the same, which also gives us confidence that it's macro-related. Brett, in the same sentence, you kind of said increased macro headwinds, but then you also reverted to similar to Q4. Click on the ' Use single sign on ' - ' Add App ' option. Is it still assuming you're going to see similar impacts on both product lines? Create and sign the JSON Web Token (JWT). So, that's really how we're thinking about it going forward. The application then sends a request to the CAS server, validating the service ticket. So, that's really how we're thinking about the guidance. Join a DevLab in your city and become a Customer Identity pro! In fact, you all know that OpenAI is a customer, and our Customer Identity Cloud is the login for ChatGPT. So, in terms of the compares, I mean, what you heard me say a second ago, there is some residual impact from the execution challenges we had in FY '23 in the current RPO guidance. Sign in to the Okta Admin Console, go to Security > API > Authorization Servers. We continue to see growth with large customers for both Workforce and Customer Identity, and we are proud to work with some of the most important organizations in the world, such as OpenAI, the U.S. Air Force Recruiting Service, and AIA. By connecting your Okta organization to Citrix Cloud, you can provide a common sign-in experience for your subscribers to access resources in Citrix Workspace. By hosting the keys in a URL, you can conveniently rotate the keys without having to update the app configuration every time. From professional services to documentation, all via the latest industry blogs, we've got you covered. That's an identity problem, and we can help with that. Verify updates include attributes expected in Azure AD. We all need hundreds of customers versus 18,000-plus customers, right? This includes the cash outlay of approximately $14 million related to the organizational restructuring. Okta continues to build on its position as the leading independent identity partner. I guess, coming back to the guide, the cRPO guide, certainly the implied second-half revenue guide, Brett, implies growth exiting the year in the mid-teens, if not maybe even the low teens. I have a spring boot zuul api gateway with routes configured for downstream microservice. Okta Workflows sends HTTP requests with the Authorization header containing the word Basic followed by a space and a base64 encoded string of :. It portends the future of being able to do more. Navigate to Identity Providers >> Corporate Identity Providers. I would just also add to that -- that I would say that we remain committed to this profitable growth concept, right? 117 is where we landed. We're also seeing continued strength in customers with over $1 million of ACV. Theyjust revealed what they believe are thetenbest stocksfor investors to buy right now and Oktawasn't one of them! Two great examples in Q1 were with Indeed and NerdWallet. They can spend it on Okta through the marketplace. Get rid of passwords in the customer authentication experience using email credential links, factor sequencing, or WebAuthn. So, IGA, it's off to a strong start, but it's only in the hundreds of customers. That being said, the tuning of go-to-market and the running of the go-to-market machine on a global basis is something we're always improving, whether it's better top-level, more effective campaigns in terms of driving demand generation, whether it's just operationally how we're prosecuting leads to opportunities, how the sales team has taken those opportunities and all the kind of the blocking and tackling of sales -- the sales funnel and the sales machine, we're continuously improving that. But I do know that it's just -- they've tried customer identity stuff in the past. Forward-looking statements involve known and unknown risks and uncertainties that may cause our actual results, performance or achievements to be materially different from those expressed or implied by the forward-looking statements. client_assertion: The signed JWT. Hey, Todd, I wonder if you could maybe opine on kind of a story that's going on with investors. Set up Oktas cloud-based authentication to give your users high-assurance but simple-to-use factors like biometrics and push notifications. Unlike pre-built connectors, connections aren't tested automatically in the API Connector cards. And then, maybe just a quick update on the sales force's comfortability selling CIAM. Okta Identity Engine began shipping with every new Workforce customer in early 2022. Or does it get worse from here? Cost basis and return based on previous market day close. This URL contains public keys that clients can use to verify the signature of client-based access tokens and OpenID Connect ID tokens. Thank you for taking my questions. Thanks. And related to that, you've talked about IGA and PAM and presumably some other products being interesting to customers. Before you go, I wanted to let you know that we'll be attending the Mizuho Cyber Summit virtual event on June 12th. If authorized, a service ticket is attached to the URL. Thanks for the question. Yeah. The number of fully ramped salespeople is close to a more normalized level as average tenure increases, and we're seeing positive trends in the number of sales reps closing Customer Identity Cloud deals. When Azure AD Connect takes over the account, the mail attribute is deleted from the object. If you are using an Okta SDK, you can skip this section and the Get an access token section. I mean, Microsoft last week at their Build conference announced kind of a new program or a new product around CIAM. But I mean since you guys mentioned about the future of Identity Governance, you guys are seeing almost one-third or more of the total kind of Workforce Identity Cloud spend going to OIG. There's important Workforce customers that want us to -- are going through strategic transformations and want to make sure that we're going to be there to support them for massive rollouts and huge investment in Okta. Go to Administrative Templates > Citrix Components > Citrix Workspace > User Authentication > Local user name and password. Because what I think investors are really struggling with is the cRPO guide is candidly deemed to be disappointing. Well, great. No matter what industry, use case, or level of support you need, weve got you covered. Empower agile workforces and high-performing IT teams with Workforce Identity Cloud. And I don't think it's like a -- it's come -- it feels like it's come on all at once, but it's really been a culmination of really a lot of important trends in the world, both just like the algorithmic advancements and what they're doing with originally what was TensorFlow and now the large-language models in various domains and -- or it's the compute power, which everyone knows about or -- the key thing, too, is just the data. Dave? See Scopes and supported endpoints. Businesses will be able to easily integrate modern cloud infrastructures such as AWS, EC2, or Kubernetes into Okta for centralized policies and controls across the resources their workers need. I'm Dave Gennarelli, senior vice president of investor relations at Okta. Each access token enables the bearer to perform specific actions on specific Okta endpoints, with that ability controlled by which scopes the access token contains. More customers on OIE means greater opportunity to upsell our higher-value services and also higher retention rates based on customers converting to date. Well, the seat expansions are really our customers' employees, right? Before you continue, ensure user attributes are syncing and appear on the Pending Export tab. If you remember last time, I talked about macro worsening, and we basically spent most of this call talking about macro worsening. Hi, I'm creating a design for authentication between a bunch of backend services. Include the service being called, the type of authentication, and a reference to the account being used. The macro is a little bit of a different story. I mean, it's going to change. Once the user is authenticated through the CAS server, a service ticket is attached to the URL. Header Value: the value to be passed to the service along with the header name. And then on the Customer side, too, I mean, I know you said that there's no -- you guys aren't seeing an impact -- a difference from macro impact on that. Historically, Okta turned to partners primarily for reach. I mean can you say this was the bottom? Welcome to Okta's first-quarter fiscal year 2024 earnings webcast. It's also cross-sells where you have Workforce and you buy Customer or you buy Customer -- you have Customer and you buy Workforce. So, next, let's go to Gabriela Borges at Goldman. We're extending the same great secure access management as well as identity governance capabilities to privileged resources. It's still a relatively small number given the number of 18,000-plus customers and the number of deals we do in a quarter. scope: Include the scopes that allow you to perform the actions on the endpoint that you want to access. There are also many different client libraries available that can authenticate using CAS. OKTA earnings call for the period ending March 31, 2023. And the -- so, I thought it would be more greenfield. So, we're seeing it in both sides of the business. In the interest of time, please limit yourself to one question, and then, you're welcome to queue back up with additional questions. It was released, I think, into beta like six weeks ago. The JSON Web Key Generator tool extracts the public key from the key pair automatically. And we've had a -- you mentioned the dot-military -- the instance for the DoD, which is the dot-military instance. When a user accesses another web application, the authorization is handled on the back end, and the user does not even have to be involved. I can't give you an exact number. The private_key_jwt client authentication method is the only supported method for OAuth service apps that want to get access tokens with Okta scopes. We're harnessing that data for Security Center, which is now generally available for Okta Customer Identity Cloud. On the Create a new app integration page, select API Services as the Sign-in method and click Next. Turning to our Q1 results. Create a service account and configure a Service Principal Name To use Kerberos authentication for agentless Desktop Single Sign-on (DSSO), you need to create a new service account and set a Service Principal Name (SPN) for that service account. Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support. Total headcount at the end of Q1 was approximately 5,700. The CAS protocol is open-source and publicly available. Eugenio will turn his attention to the overall growth and operational excellence of Okta, including further accelerating our go-to-market effectiveness and increasing automation across the company. 2023 Okta, Inc. All Rights Reserved. CAS can provide an SSO (single sign-on) solution for multiple web applications to provide a more seamless end-user experience. But we also think there's a big opportunity to -- I mean, the IGA market right now is not that big. Ask us on the Authentication and authorization are not the same thing. So, that's very positive. We think it could be that -- contribute that much. The AWS Marketplace has been pretty successful for us. The CAS protocol is a single sign-on open-source service that allows users to sign in to one trusted server one time in a session and still be able to access multiple applications without signing in over and over again. I'll now cover some of the highlights and achievements in the quarter that we believe position Okta for long-term success. So, where is that conservatism coming from? Connect and protect your employees, contractors, and business partners with Identity-powered security. And then, the real quick follow-up was, do you think you're rightsized with the restructuring you had in the first quarter? Yeah. Non-GAAP operating margin was strong as well. These are consistent across Workforce and Customer. Optional. Todd, you've mentioned CIAM being a key focus area this year. Awesome. Yeah. Since the API Connector cards can be used with multiple connections, enter a detailed name to distinguish each connection. We're also pleased to have turned the corner on the challenges we faced last year. Innovate without compromise with Customer Identity Cloud. We're also continuing to make sure the go-to-market machine is humming as effectively as it can. One thing is just the qualitative conversations with customers, conversations with analysts in the market, industry analysts, etc., etc. But it looks like you have yourself kind of reaccelerating a bit into the next quarter and actually even more in the second half of this year. OK. Next, we'll go to Fred Havemeyer at Macquarie. There is no limit to the number of JWKs that you can add for an app. At our investor day last November, I indicated that our historic norms for net dilution was in the 2% to 3% range and that we expected that range to be elevated in the near term primarily related to the change in our stock price. Before you disable Okta sync, update the attribute Okta is syncing. It means that there's going to be tons of new industries created and industries changed. Calculated by average return of all stock recommendations since inception of the Stock Advisor service in February of 2002. Add user sign-up to your apps and manage customer identities at scale via APIs or from Okta's user-friendly admin console. If you look back over the past couple of years, how much has seat count growth or classic upsell contributed to net retention versus how much is cross-sell today? Use a tool such as this JSON Web Key Generator (opens new window) to generate a JWKS public/private key pair for testing. Secure your apps and VPN with a robust policy framework and a set of modern second-verification factors. Here are just a few notable examples of customer wins and upsells in Q1, which come from a wide range of industries. Lastly, I want to provide a couple of comments to help with modeling Okta. Maybe we can get these last two quickly. I know we're a little bit past the top of the hour, but we'll go into overtime a little bit more here, try to get to a few more questions. I actually think -- I don't think that people are waiting at all for the integration between -- to go with IGA, for the integration between IGA and Privileged. So, firstly, I wanted to get a sense of, between the Customer Identity Cloud and the Workforce Cloud, how much of a cross-sell opportunity still exists. Thanks for taking the question. Next up, we have Rudy Kessinger from D.A. What was the question? Enable the Fabric admin settings: Log in to the Fabric admin portal. Basic: A simple username and password scheme built into the HTTP protocol. We expect that the next wave of customers will be much broader, and it will also be customers that maybe weren't as hand-selected. I mean, annual revenue is inching up a point here, 17%, 18% but cRPO going the other way. I think people are just being more thoughtful about the uncertainty out there in the macro. Though we may not state it explicitly during the meeting, all references to profitability are non-GAAP. Yeah. We continue to make meaningful progress on the actions we've taken to drive efficiency in our cost structure. The response should look something like this (the token is truncated for brevity): Note: The lifetime for this token is fixed at one hour. By default, each new application sets this percentage at 50%. So, the -- I guess the good news and the bad news is that -- the good news is that it's changing. Create a JSON Web Token (JWT) and sign it using the private key for use as the client assertion when making the. Yeah. Overview Use API Connector function cards to make authenticated basic, OAuth 2, or custom connections to third-party services. Thanks. But the other thing that we saw in the quarter, which was a real strength, was cross-selling across all products, like whether it was like more WIC products to a WIC customer or a WIC customer buying CIC. I see that there are quite a few hands raised already, and I'll take them in the order. If there are add functions for a user in Azure AD, their on-premises account doesn't match the cloud account.