Executive Summary

As enterprises expand their digital footprint across applications, devices, infrastructure, and a growing population of human and nonhuman identities, fragmented identity environments create security gaps, operational inefficiencies, and rising administrative overhead. Disconnected identity tools broaden the attack surface, making it difficult to enforce consistent access policies, detect and respond to threats quickly, and scale identity operations to keep pace with growth. Centralizing identity into a unified solution enables organizations to strengthen security, streamline operations, and reduce overhead and complexity while providing the visibility and control required to manage an increasingly dynamic and distributed workforce environment.

To solve these critical security challenges, organizations need to adopt a new approach to identity architecture: an identity security fabric. The Okta Platform brings a comprehensive suite of identity security capabilities onto a single platform, including posture management, access management, governance, privileged access, device access, threat detection and response, orchestration, and automation. Together, this unified identity layer secures all identity types (human and nonhuman — including AI agents) and delivers end-to-end identity security from visibility and access control to governance and remediation.

Okta commissioned Forrester Consulting to conduct a Total Economic Impact™ (TEI) study and examine the potential return on investment (ROI) enterprises may realize by adopting an identity security fabric with Okta.1 The purpose of this study is to provide readers with a framework to evaluate the potential financial impact of adopting an identity security fabric with Okta on their organizations.

216%

Return on investment (ROI)

 

$10.6M

Net present value (NPV)

 

To better understand the benefits, costs, and risks associated with this investment, Forrester interviewed six decision-makers with experience adopting an identity security fabric with Okta. For the purposes of this study, Forrester aggregated the interviewees’ experiences and combined the results into a single composite organization: a multinational enterprise with approximately $3 billion in annual revenue and 9,000 employees that operates across a complex, distributed environment with a large portfolio of applications, devices, infrastructure, and identities.

Prior to adopting an identity security fabric with Okta, the interviewees’ organizations managed fragmented identity environments consisting of on-premises directories, basic single sign-on (SSO) tools, and multiple point solutions for identity management, access management, and identity security. This disjointed approach limited visibility into access and identity activity, made it difficult to enforce consistent security policies, and required significant manual effort to manage provisioning, access reviews, and lifecycle processes. As application portfolios expanded and identity threats became more sophisticated, these limitations created operational inefficiencies, increased security risk, and constrained organizations’ ability to scale identity security effectively.

After implementing an identity security fabric with Okta, the interviewees’ organizations centralized identity security into a unified solution, which improved visibility, strengthened security posture, and automated key identity processes. Key results from the investment include a reduced likelihood of identity-related breaches, improved business continuity through faster detection and remediation of identity threats, and lower costs through consolidated legacy identity tools and reduced SaaS waste. Interviewees’ organizations also achieved greater operational efficiency through faster application onboarding, reduced identity and access-related support tickets, and more streamlined access reviews and compliance certifications, along with improved efficiency in integrating new mergers and acquisitions. These improvements collectively streamlined day-to-day identity operations while enabling their organizations to scale more securely and efficiently over time.

Key Findings

Quantified benefits. Three-year, risk-adjusted present value (PV) quantified benefits for the composite organization include:

  • Reduction in the likelihood of identity-related breaches by 90%. Adopting an identity security fabric with Okta reduces breach risk by detecting and responding to identity-based threats in real time, identifying misconfigurations and access risks before they can be exploited, and expanding the use of phishing-resistant authentication across the workforce. By centralizing identity controls and applying consistent policies across users, devices, applications, and infrastructure, the composite organization reduces its exposure to credential-based attacks and improves its ability to prevent and contain identity-driven incidents. For the composite, this yields a threeyear, riskadjusted total PV of $1.6 million.

  • Reduction in mean time to remediate (MTTR) identity-related incidents by 90%. Okta improves business continuity by accelerating the detection and remediation of identity-based threats and subsequent authentication disruptions such as lockouts, access delays, and MFA friction. Automated detection and response, combined with centralized identity visibility and risk-based access controls, minimize the duration and impact of security incidents, which allows employees to maintain access to critical systems and continue working with limited interruption. For the composite, this yields a threeyear, riskadjusted total PV of $11.0 million.

  • SaaS cost savings of $2.17 million over three years from eliminating redundant applications and reclaiming unused licenses. Okta reduces the cost of fragmented identity environments by replacing multiple point solutions for identity management, access management, and identity security with a single platform. Consolidation eliminates overlapping software spend and reduces the need for custom integrations and manual processes. Increased visibility into application usage enables the composite to identify and reclaim unused licenses, while automated lifecycle management improves ongoing license efficiency and limits SaaS sprawl over time. At the same time, centralized administration and automation reduce the number of resources required to manage identity operations. For the composite, this yields a threeyear, riskadjusted total PV of $2.4 million.

  • Reduction in time to onboard new applications by 75%. Okta accelerates onboarding by eliminating custom integrations and provisioning logic through its prebuilt connectors and automation. Standardized processes and workflows reduce setup time and allow teams to onboard applications quickly and consistently as demand grows. For the composite, this yields a threeyear, riskadjusted total PV of $125,000.

  • Reduction in identity and access management (IAM) support ticket volume by 50% by Year 3. Okta reduces identity and access-related support workloads by eliminating common ticket types and streamlining remaining requests through automation. Okta Lifecycle Management removes many access requests entirely through automated birthright provisioning, while Okta Identity Governance enables self-service access requests with built-in approvals and provisioning. Passwordless authentication reduces password reset tickets, and Okta Workflows automates fulfillment tasks that previously required manual intervention. These combined capabilities reduce both ticket volume and resolution effort, subsequently lowering the operational burden on IT support teams. For the composite, this yields a threeyear, riskadjusted total PV of $103,000.

  • Reduction in administrative effort for access certification campaigns by 90%. Okta replaces manual, spreadsheet-driven access reviews with automated workflows, including in-platform reviews, reminders, and automated remediation. This removes the need for manual tracking and follow-up while enabling the composite to run certifications more efficiently and at scale. For the composite, this yields a threeyear, riskadjusted total PV of $109,000.

  • Reduction in time required for identity integration during M&A events by 65%. Okta improves M&A efficiency by connecting to existing directories and automating user provisioning and access migration, which reduces dependencies on full directory consolidation and manual coordination. Okta Lifecycle Management and Workflows streamline integration activities to allow IT teams to complete data integration and user migration with less effort. For the composite, this yields a threeyear, riskadjusted total PV of $116,000.

“Okta is significantly more cost-competitive than our previous tooling; in some cases, it’s several times cheaper than comparable solutions. More than that, it’s actually aligned to what we need.”

Senior SecOps engineer, software

Unquantified benefits. Benefits that provide value for the composite organization but are not quantified for this study include:

  • Improved visibility into and control over AI agents and shadow AI. Centralized identity provides the composite a clear view into what is connecting to enterprise systems and who has access, even as it introduces AI tools and agents across the environment. With access control managed through Okta, it is significantly harder for unmanaged tools to access systems without approval, while giving IT teams the ability to monitor activity and take action when needed. Although AI governance continues to evolve, having this foundation in place makes it easier to establish guardrails, limit excessive access, and bring shadow usage back under control as it emerges.

  • Faster employee onboarding. Integrating Okta with HR systems fundamentally changes how the composite provisions employees, replacing email-based requests and manual coordination with automated account creation and access assignment. New hires arrive with the right applications and entitlements already in place instead of waiting extended periods to be fully provisioned, while additional access is granted quickly through automated approval workflows. This reduces onboarding delays and enables employees to become productive more quickly, without relying on IT to complete setup.

  • Reduced end-user authentication friction. SSO and passwordless authentication streamline how employees access applications by eliminating repeated credential entry and reducing login time from tens of seconds to just a few seconds per interaction. Because employees authenticate frequently throughout the day, these small time savings compound into a noticeably faster and less disruptive experience. Removing passwords also eliminates a common source of friction, allowing users to move between applications more quickly without interruptions.

  • Strategic vendor partnership. Ongoing engagement with Okta supports identity strategy development and helps teams navigate new use cases with confidence. Rather than operating as a transactional vendor, Okta builds familiarity with organizational challenges and priorities to make it easier to evaluate new capabilities and move initiatives forward.

Costs. Three-year, risk-adjusted PV costs for the composite organization include:

  • Fees to Okta totaling $3.7 million. The composite organization pays annual subscription fees for Okta across 9,000 users. This investment provides a unified platform for end-to-end identity security capabilities — from access management and governance to posture management, threat detection, privileged access, and device trust — along with built-in orchestration to automate identity workflows across the enterprise technology stack. Pricing follows a per user per month model and remains fixed over the three-year agreement term. Fees include the Gold Premier Success Plan, which provides dedicated success resources and priority support. The composite organization also incurs a one-time Okta Professional Services investment at the outset to support deployment planning and initial configuration.

  • Implementation, ongoing management, and training costs of $1.2 million. The composite organization incurs internal labor costs driven by the deployment and operation of the Okta Platform. Implementation is supported by a small team of internal resources and spans multiple months, with effort driven by configuration, testing, and application integration activities. Following initial deployment, ongoing management is supported by a dedicated team of internal resources, with a portion of their time allocated to platform administration, including provisioning workflows, application integrations, authentication policies, and access governance. Training requirements are light, with limited initial onboarding and minimal ongoing effort to support new hires and incremental feature adoption.

The financial analysis that is based on the interviews found that a composite organization experiences benefits of $15.5 million over three years versus costs of $4.9 million, adding up to a net present value (NPV) of $10.6 million and an ROI of 216%.

“A breach in our organization could cost up to $1 billion, and we are required to publicly disclose it. In a financial services environment, that level of exposure would have a significant reputational and business impact. Okta helps us reduce the risk of that happening.”

IAM staff engineer, fintech

“[Adopting an] identity security fabric [with Okta] has shifted us from a more siloed, application-by-application identity control model toward a centralized identity security layer. This makes it easier to enforce consistent access policies, ensure trusted device use, reduce reliance on weaker authentication factors, and respond to identity risk in a more coordinated way.”

IAM staff engineer, fintech

Key Statistics

216%

Return on investment (ROI) 

$15.5M

Benefits PV 

$10.6M

Net present value (NPV) 

<6 months

Payback 

Benefits (Three-Year)

[CHART DIV CONTAINER]
Reduced likelihood of an identity-related breach Improved business continuity due to faster identity threat detection and remediation Legacy environment savings Faster application savings Reduction in identity and access management-related support tickets Improved efficiency of access review and compliance certifications Improved M&A efficiency

Customer Journey: Adopting An Identity Security Fabric With Okta

Drivers leading to the adoption of an identity security fabric with Okta

Interviews

Role Industry Region Employees
Revenue IAM staff engineer Fintech Multinational 5,000 $2.5B
Senior SecOps engineer Software Multinational 3,000 $200M
IT systems admin Software Multinational 1,000+ $300M+
VP, information security
 
System engineer architect
Insurance US 1,000 $1B
IT infrastructure manager Software North America 1,000 $100M

Key Challenges

Prior to adopting an identity security fabric with Okta, interviewees’ organizations managed fragmented identity environments that combined on-premises directories, basic SSO tools, and a collection of point solutions for authentication, provisioning, governance, and security. These environments required continuous coordination across disconnected systems; lacked a unified view of identity across users, applications, and devices; and relied heavily on manual processes that did not scale with growing organizational complexity. As identity threats grew more sophisticated and workforce and application portfolios expanded, the limitations of this fragmented approach became increasingly difficult to absorb.

Interviewees noted how their organizations struggled with common challenges, including:

  • Limited visibility and control across identity environments. Identity data and access controls were distributed across multiple disconnected systems, which made it difficult to understand entitlements, monitor access activity, enforce consistent policies, or respond to risks in a timely manner. Security and IT teams lacked the centralized view needed to govern identity effectively across a growing portfolio of applications and users, and gaps between tools created blind spots that elevated risk without anyone having clear ownership of the problems.
    The IAM staff engineer in fintech explained: “Previously, our user lifecycle processes were mainly built around our on-premises environment, which was well-governed due to our regulatory requirements across multiple countries. But those systems were quite isolated, and our SaaS tools lacked centralization and consistent oversight. That is why we needed Okta to help close the gap by giving us a more unified control layer across both environments. We also saw we could get great value from [Okta Verify’s] device visibility, which helped us to see managed and registered devices without needing a separate mobile device management solution.”
    The IT systems admin in software shared: “We were looking to [improve] our control across our entire tech stack to have clearer visibility into what each employee has access to. Instead of managing multiple usernames and passwords, we wanted our users to have a single set of credentials that gave them access to everything, from their workstation to Okta, email, [instant messaging], and other applications.”

  • Inconsistent security enforcement and elevated identity risk. Gaps in authentication strength, device validation, and policy enforcement increased organizations’ exposure to identity-based security incidents. Without a unified control plane, enforcing consistent access policies across applications was operationally difficult, and the ability to detect and remediate identity risks was quickly constrained by the fragmentation of security tooling. Interviewees described environments where even when threats were identified, manual response workflows left their organizations exposed for hours while investigation and containment proceeded.
    The IAM staff engineer in fintech said: “Okta is a leader in the identity and access management space. As our number of SaaS applications grew, we realized we needed a more centralized way to protect accounts and manage access. Before Okta, we didn’t have a consistent approach to authentication or visibility across systems. With Okta, we’ve been able to implement stronger security controls while creating a foundation to scale identity management more broadly across the organization.”
    The senior SecOps engineer in software explained: “We were focused on reducing our attack surface from a security perspective and unifying that experience across our tools. Bringing everything together meant that if we needed something within that framework, Okta was the natural place to look.”
    The VP of information security in insurance shared: “We wanted to provide our employees with a more consistent and secure way to access applications, rather than managing different credentials and MFA methods. As our environment grew, it became clear we needed a more unified approach to managing authentication and user access. From an IT perspective, this was especially important for improving security during offboarding. We needed a more reliable way to ensure that when a user was disabled, their access to downstream applications would be removed automatically.”

  • Inefficient access governance and audit readiness. Validating access at scale required manual data extraction, spreadsheet-based tracking, and significant cross-team coordination. Access certification campaigns were a recurring operational burden: Administrators exported entitlement data from individual applications, distributed spreadsheets to reviewers via email, chased responses for weeks, and manually triggered deprovisioning for any access revoked. The friction involved meant many organizations ran reviews less frequently than their security or compliance posture required, and audit preparation consumed disproportionate IT and compliance resources.
    The senior SecOps engineer in software said: “Before [Okta], our auditors and compliance teams couldn’t access what they needed directly; we had to generate reports, coordinate requests, and support access reviews manually. It was a lot of back and forth and required our involvement every time. That created a lot of overhead and made it harder to run audits as efficiently as we wanted.”

  • High operational burden from manual lifecycle management. Provisioning, deprovisioning, and access changes were largely manual and required coordination across multiple teams. This created a steady flow of support tickets and often delayed access requests by days. IT teams were heavily involved in routine tasks, and for global organizations, time zone differences made things worse, as requests could sit untouched for hours and offboarding often depended on someone being available at the right time.
    The system engineer architect in insurance said: “As we moved more to the cloud and adopted more SaaS applications, we were managing all of those separately. This was before we had the automation provided through workflows, so the onboarding and offboarding process was difficult, to say the least.”
    The senior SecOps engineer in software explained: “[Before Okta], we didn’t have a unified, central place for identity and access. I spent hours and days taking screenshots, pulling Excel reports, and moving those reports around just to manage access and support reviews. It was a lot of manual effort across different tools.”
    The IT infrastructure manager in software said: “We had a lot of manual processes before we moved to Okta. I remember offboarding someone and having a folder of all the programs I had to go into just to manually deprovision access. Even where there was some provisioning, if you really wanted it to work, you had to build custom APIs yourself. You could do it, but it was a lot to maintain, especially for a lean team.”

  • Shadow IT and SaaS sprawl. Decentralized application adoption resulted in unmanaged accounts, orphaned access, and ongoing spend on unused or underutilized licenses. Without visibility into which applications employees were actually using, organizations defaulted to broad team-wide license provisioning and had limited ability to rationalize their SaaS portfolios or reclaim spend systematically. The problem compounded over time as new tools were adopted without governance infrastructure to manage their lifecycle. Beyond the unnecessary spend it created, unmanaged accounts also represented an active security exposure. Accounts that persisted beyond an employee’s departure or a project’s completion created standing access that fell outside normal monitoring and review cycles. In environments without automated governance, these accounts remained valid indefinitely, providing a potential entry point that no one was actively watching.
    The IT systems admin in software explained: “It was an issue with how decentralized things were. We had teams or technical leads going out and setting up accounts with different services on their own and then managing access themselves. Over time, that became hard to keep up with. People wouldn’t always remove users, and if someone owned a system and left the company, we could lose access entirely. Then we’d have to go through a number of recovery steps just to get back into it, and in some cases, those accounts would just keep running in the background without anyone actively managing them.”

Investment Objectives

Interviewees’ organizations sought a solution that could consolidate their fragmented identity environments and address immediate operational challenges and longer-term strategic identity requirements. Key objectives included:

  • Establish a unified solution by centralizing identity security across applications, devices, infrastructure, and identities.

  • Strengthen identity security posture and reduce risk by enforcing consistent access controls.

  • Improve governance and audit readiness by enabling scalable access reviews.

  • Reduce operational complexity and IT burden by consolidating point solutions and automating lifecycle management.

  • Improve efficiency and scalability of identity operations to support growing users, applications, and environments.

  • Increase visibility into SaaS usage to track application adoption, reduce license waste, and manage access entitlements more effectively across the portfolio.

  • Support future identity needs and evolving use cases, including new security requirements, workforce models, device environments, and emerging AI-driven workloads.

“Scalability has been really important for us as the organization grows and changes. Okta has allowed us to scale much more efficiently and support growth without increasing operational overhead.”

Senior SecOps engineer, software

Composite Organization

Based on the interviews, Forrester constructed a TEI framework, a composite company, and an ROI analysis that illustrates the areas financially affected. The composite organization is representative of the interviewees’ organizations, and it is used to present the aggregate financial analysis in the next section. The composite organization has the following characteristics:

  • Description of composite. The multinational, industry-agnostic enterprise has $3 billion in annual revenue and approximately 9,000 employees. It operates across a complex, distributed environment with a large and growing portfolio of workforce applications, devices, and identity populations. The organization manages identity across hundreds of applications spanning SaaS and on-premises environments. Before deploying Okta, it relied on a fragmented combination of on-premises directories, basic cloud access tools, and multiple overlapping point solutions for identity management, access management, and identity security, each requiring separate licensing, integration, and ongoing administrative effort.
    This fragmented environment resulted in inconsistent visibility and control, gaps in security enforcement, and significant operational overhead driven by manual processes that did not scale with organizational growth. Limited visibility into application usage further contributed to unused and underutilized software licenses, as access was often provisioned broadly without clear insight into actual user activity. Over time, this led to increased cost, duplicated functionality across tools, and difficulty rationalizing identity infrastructure and SaaS spend.

  • Deployment characteristics. The composite adopts an identity security fabric with Okta across its workforce environment, establishing a unified identity security layer that spans access management, governance, posture management, threat detection, privileged access, and device trust, with built-in orchestration to automate identity workflows across the enterprise technology. The deployment supports 9,500 workforce identities and 9,500 devices across hundreds of applications.
    The difference between total employees (9,000) and workforce identities (9,500) reflects the inclusion of contractors and nonhuman identities, such as service accounts, system accounts, automated workloads, and emerging AI-driven agents, that are onboarded, governed, and reviewed in Okta alongside employees. Device count (9,500) also exceeds employee count, consistent with environments where some employees authenticate from multiple endpoints, including a primary laptop and/or a mobile device.

Implementation spans the Okta Platform, is completed in the initial period, and requires one month of effort per product on average. Okta Professional Services supports initial planning and configuration, while internal IAM and IT resources lead deployment activities. Fifteen Okta administrators and support personnel receive light training during rollout to manage and operate the environment.

 KEY ASSUMPTIONS

  • $3 billion annual revenue

  • 9,000 employees 

  • 9,500 workforce identities and devices

  • Adopts an identity security fabric with Okta by using a suite of identity security capabilities, including Access Management (Universal Directory, SSO, Adaptive MFA, etc.), Okta Identity Governance (OIG), Identity Security Posture Management (ISPM), Identity Threat Protection (ITP), Okta Privileged Access (OPA), Okta Device Access (ODA), and Okta Workflows

Analysis Of Benefits

Quantified benefit data as applied to the composite

Total Benefits

Ref. Benefit Year 1 Year 2 Year 3 Total Present Value
Atr Reduced likelihood of an identity-related breach $653,501 $653,501 $653,501 $1,960,504 $1,625,161
Btr Improved business continuity due to faster identity threat detection and remediation $5,227,500 $4,356,250 $3,485,000 $13,068,750 $10,970,811
Ctr Legacy environment savings $945,316 $987,816 $987,816 $2,920,947 $2,417,915
Dtr Faster application onboarding $44,880 $50,490 $56,100 $151,470 $124,676
Etr Reduction in identity and access management-related support tickets $37,128 $41,769 $46,410 $125,307 $103,141
Ftr Improved efficiency of access reviews and compliance certifications $44,030 $44,030 $44,030 $132,090 $109,496
Gtr Improved M&A efficiency $69,615 $0 $69,615 $139,230 $115,589
  Total benefits (risk-adjusted) $7,021,970 $6,133,856 $5,342,472 $18,498,298 $15,466,789

Reduced Likelihood Of An Identity-Related Breach

Evidence and data. Interviewees reported that before adopting an identity security fabric with Okta, their organizations relied on reactive, fragmented, application-by-application identity controls that left them exposed to credential-based attacks, phishing campaigns, misconfigured access policies, and authentication anomalies. Without unified visibility across their identity posture, security teams struggled to keep pace with modern identity threats, which made breach risk reduction a top security and business priority.

After adopting an identity security fabric with Okta, interviewees said their organizations achieved a meaningful reduction in breach likelihood through three complementary capabilities. ITP provided real-time detection and automated response to identity-based threats, including brute force attempts and suspicious session activity, reducing response times. ISPM delivered continuous visibility into misconfigurations, unused administrative permissions, exposed credentials, and policy gaps, which enabled proactive hardening and, in many cases, automatic remediation before adversaries could act. Phishing-resistant MFA within Okta Access Management eliminated credential phishing as a viable attack vector, which increased the share of workforce authentication protected by high-assurance factors.

Interviewees emphasized that these capabilities’ value was amplified by their integration within a single platform, which enabled consistent policy enforcement, richer contextual access decisions, and more coordinated threat response across the environment.

  • The IAM staff engineer in fintech explained: “With ITP and Workflows, it’s much easier to deal with risk now. We get alerts about suspicious events, and we can terminate sessions even on mobile devices. For example, if a device is no longer up to date, [Okta] will terminate [instant messaging] sessions. Before, this was not possible, and sessions would remain active, which created additional security risk.”
    The staff engineer continued: “We’ve been targeted several times, and our Okta environment was one of the main targets. What we saw during those attacks was that even if a user password was leaked, attackers were unable to access the system. Since we are now passwordless and require devices to be registered and managed, we have been protected several times with Okta.”
    The interviewee described a specific phishing incident that Okta helped contain: “One time we were targeted very severely: Around 600 employees received a phishing email, and it was very sophisticated. About 50 people opened it, and around 10 entered their passwords. Even though we don’t rely on passwords anymore, attackers were able to find some old credentials. But because of the multiple security layers, we were notified immediately that there was phishing activity. If we didn’t have Okta in place, especially without those controls, attackers could have easily gotten access to SaaS tools.”

  • The IT infrastructure manager in software explained: “Adaptive MFA through Okta has been huge. Right out of the gate, we block every sanctioned country, so that already lowers our exposure. We also have systems that detect things like proxy or VPN usage, because attackers will use any tool they can to make it look like they’re coming from a trusted location. … We’ve set things up so users can only log in from their country of origin based on their HR profile. If they’re traveling, they can request an exception. Being able to adjust on the fly really limits the exposure you have from accounts being compromised. It’s been powerful for us.”
    The manager continued: “Zero standing privileges is a big thing; people request access when they need it. We’ve also used Workflows so that if people stop using a system for a period of time, their access is removed. That’s not only a cost benefit, it’s a security benefit. If an account is compromised, that’s one less system an attacker can get ahold of.”

  • The IT systems admin in software explained: “If there’s an incident, we can act immediately. We can lock someone out or apply a deny rule just by adding them to a group instead of going through a full deprovisioning process. For terminations, Okta Workflows are a big contributor to our security because we can trigger off something like updating a user’s status [in our HR system] and automatically remove access, clear sessions, transfer data, and delete accounts.”

  • The VP of information security in insurance shared: “All access is configured within Okta, which gives us strong visibility for audits. If an identity, whether it’s a user, service account, or automated process, is no longer being used, we can identify that and revoke access. We run regular service account audits, and if something isn’t behaving as expected, we can remove its access immediately, with deprovisioning happening within seconds, if not milliseconds.”

Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:

  • The composite organization expects $2.5 million in cumulative costs per identity-based breach based on direct and indirect costs including incident response, regulatory penalties, reputational damage, and operational disruption. It has a 67% likelihood of experiencing a breach annually. Furthermore, 60% of breaches are driven by identity-related issues, including compromised credentials, misconfigured access, and gaps in authentication controls.2

  • Okta addresses 85% of these identity-based attacks, based on the scope of threats mitigated by phishing-resistant authentication, real-time threat detection and response, and continuous identity posture monitoring.

  • By adopting an identity security fabric with Okta, the composite reduces its likelihood of experiencing an identity-related breach by 90%.

Risks. This benefit will vary among organizations based on:

  • The cumulative cost of an identity-based breach, which will vary based on industry, regulatory environment, and the sensitivity of data at risk.

  • An organization’s baseline breach likelihood and the proportion of breaches that are identity-based before deploying Okta.

  • The percentage of identity-based attacks addressable by Okta’s platform, which may vary based on the specific threat landscape and the breadth of Okta products deployed.

Results. To account for these risks, Forrester adjusted this benefit downward by 15%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $1.6 million.

90%

Reduction in the likelihood of an identity-related breach

“[Adopting an] identity security fabric with Okta has reduced our exposure to credential-based compromise, improved how we contain incidents, and closed detection gaps by bringing identity signals together in one place. It’s shifted us from managing identity at the application level to a centralized identity security layer where we can respond in a much more coordinated way.”

IAM staff engineer, fintech

Reduced Likelihood Of An Identity-Related Breach

Ref. Metric Source Year 1 Year 2 Year 3
A1 Cumulative cost of an identity-based breach Forrester research $2,500,000 $2,500,000 $2,500,000
A2 Average likelihood of a breach Forrester research 67% 67% 67%
A3 Percentage of breaches that are identity-based attacks Forrester research 60% 60% 60%
A4 Percentage of attacks addressable with Okta Interviews 85% 85% 85%
A5 Annual risk exposure addressable with Okta A1*A2*A3*A4 $854,250 $854,250 $854,250
A6 Reduction in the average likelihood of an identity-related breach with Okta Interviews 90% 90% 90%
At Reduced likelihood of an identity-related breach A5*A6 $768,825 $768,825 $768,825
  Risk adjustment 15%      
Atr Reduced likelihood of an identity-related breach (risk-adjusted)   $653,501 $653,501 $653,501
Three-year total: $1,960,504 Three-year present value: $1,625,161

Improved Business Continuity Due To Faster Identity Threat Detection And Remediation

Evidence and data. Interviewees described identity-related security incidents as a source of significant operational disruption that extended well beyond their security teams. When authentication anomalies, brute force attempts, or suspected credential compromises required investigation, the downstream effects were immediate: Employees faced lockouts, access delays, and repeated MFA challenges that prevented them from accessing critical systems. In interviewees’ prior environments, manual investigation and remediation workflows meant these disruptions often lasted for hours during each incident.

Several interviewees highlighted how ITP changed this dynamic. By continuously analyzing authentication signals, user behavior, and session context across the environment, ITP automatically detected and responded to threats by blocking suspicious IPs, flagging anomalous login patterns, and triggering automated remediation policies without requiring manual intervention. Interviewees noted that threats their teams previously spent hours investigating were now identified and contained within minutes, and in many cases were stopped entirely before they could generate employee-facing disruption.

Interviewees also cited Okta’s adaptive authentication and session protection capabilities within Access Management as critical to maintaining continuity during security events. By applying risk-based policies that evaluated device posture, network context, and behavioral signals in real time, Okta ensured that legitimate users maintained access while anomalous sessions were challenged or terminated. This reduced the collateral disruption that blanket lockdowns or broad MFA step-ups had previously caused. The net effect, interviewees said, was fewer incidents requiring investigation each year, faster containment when incidents did occur, and a subsequent reduction in employee productivity loss attributable to identity-related security incidents.

  • The senior SecOps engineer in software explained: “With Identity Threat Protection and Identity Security Posture Management, it’s more of a set up-once-and-monitor situation. Okta does a good job managing how those tools work on the back end, so in some cases, there just isn’t work that we need to do. We’re not manually managing IP block lists or common password lists anymore; it’s all being handled for us. It’s been a benefit on a lot of levels to have everything together.”
    The senior SecOps engineer continued: “Previously, our response time for things that required manual intervention was a few hours. For example, if it’s the weekend and someone flags a brute force attempt, we might not act on it until later. With some of the identity security posture and workflow capabilities from Okta, those actions can happen immediately. If a credential is exposed, we can cut it off right away, rotate it, or take action automatically. There’s essentially no response time on that. In a lot of situations, that brings response time down from a few hours to basically no time.”

  • The IAM staff engineer in fintech said: “Before Okta, our identity controls were more fragmented and relied more on traditional MFA and application-specific controls. Today, a much larger share of authentication is protected by phishing-resistant factors like FastPass, along with device-based access controls. We’re also using more contextual signals during authentication, things like device posture, OS compliance, and location, which allows us to make better access decisions and enforce policies more consistently.”
    The IAM staff engineer continued, “Because we now have more centralized visibility and response capabilities, we can detect and react to issues much faster, which reduces both detection and response time and helps limit disruption when incidents occur.”

  • The IT systems admin in software said: “One of the biggest things Okta has given us is awareness of threats and the ability to react to them very quickly, within the day. We can see things through reports and logs and take action right away. We’ve had situations where open sites that accept usernames and passwords would get brute forced and start locking people out, but we’ve mitigated those, so they’re gone now. As far as our primary company tech stack, it’s in Okta and it’s doing its job.”
    The IT systems admin continued: “Okta’s Identity Threat Protection and session protection give us visibility into things that may not have been reported before, and they’re stopping them. So it’s not like we even have to do anything in some cases.”

  • The system engineer architect in insurance explained: “If someone is trying to brute force a login, Okta handles that and blocks those attempts. So we’re not seeing a whole bunch of accounts locked out, and we don’t have to go in manually. We haven’t gone as far as automatically disabling users, but a lot of that response is already handled for us.”

  • The manager of IT infrastructure in software said: “Because everyone logs in through Okta, we can use Workflows to look at activity and immediately take action. For example, if someone hasn’t logged into an application, we can pull that access right away. That level of automation also helps us respond quickly when something isn’t right since everything is in the same system. You don’t have to worry about integrations breaking or processes failing; it just works.”

Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:

  • The composite experiences identity-related incidents requiring investigation and remediation, including authentication anomalies, brute force attempts, and suspected credential compromises, that generate meaningful employee productivity loss when not contained quickly. The cost of 1 hour of IAM-related employee productivity downtime is $250,000, when employees are unable to authenticate, access critical systems, or complete their work during active identity security events.

  • The composite experiences 12 identity-related incidents that require investigation and remediation in Year 1, 10 in Year 2, and eight in Year 3. This declining trajectory reflects the progressive hardening of the composite’s identity posture as Okta’s proactive controls, particularly ISPM’s continuous misconfiguration detection and ITP’s automated threat response, reduce the frequency of incidents requiring manual intervention over time.

  • Before deploying Okta, the composite’s average mean time to detect (MTTD) an identity-related incident is 0.5 hours and its average MTTR is 2 hours. With ITP’s automated detection and response capabilities, the composite reduces MTTD and MTTR by 50% and 90%, respectively.

Risks. This benefit will vary among organizations based on:

  • The hourly cost of IAM-related employee productivity downtime, which will vary based on organization size, workforce composition, and the degree to which business operations depend on continuous identity and access availability.

  • The number of identity-related incidents requiring investigation and remediation per year in the prior environment, which will vary based on an organization’s existing security posture and threat exposure.

  • An organization’s baseline MTTD and MTTR for identity-related incidents before deploying Okta.

Results. To account for these risks, Forrester adjusted this benefit downward by 15%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $11.0 million.

90%

Reduction in MTTR identity-related attempted incidents

“We no longer have to manually remediate brute force attacks or manage block lists anymore. Okta just takes care of it out of the box.”

Senior SecOps engineer, software

Improved Business Continuity Due To Faster Identity Threat Detection And Remediation

Ref. Metric Source Year 1 Year 2 Year 3
B1 Cost of 1 hour of downtime related to IAM Composite $250,000 $250,000 $250,000
B2 Identity-related attempted incidents requiring investigation and remediation Composite 12 10 8
B3 Average MTTD identity-related attempted incidents in prior environment (hours) Composite 0.5 0.5 0.5
B4 Business loss during detection effort B1*B3 $125,000 $125,000 $125,000
B5 Reduction in MTTD with Okta Interviews 50% 50% 50%
B6 Business value protected due to faster MTTD B4*B5 $62,500 $62,500 $62,500
B7 Average MTTR identity-related attempted incidents in prior environment (hours) Composite 2 2 2
B8 Business loss during remediation effort B1*B7 $500,000 $500,000 $500,000
B9 Reduction in MTTR with Okta Interviews 90% 90% 90%
B10 Business value protected due to faster MTTR B8*B9 $450,000 $450,000 $450,000
Bt Improved business continuity due to faster identity threat detection and remediation B2*(B6+B10) $6,150,000 $5,125,000 $4,100,000
  Risk adjustment 15%      
Btr Improved business continuity due to faster identity threat detection and remediation (risk-adjusted)   $5,227,500 $4,356,250 $3,485,000
Three-year total: $13,068,750 Three-year present value: $10,970,811

Legacy Environment Savings

Evidence and data. Before adopting an identity security fabric with Okta, interviewees’ organizations incurred significant costs from fragmented identity tooling and operations, including overlapping point solution spend, unused software licenses, and manual identity processes. Their environments consisted of a patchwork of solutions for SSO, MFA, provisioning, governance, and credential management, and beyond that operated in silos, required dedicated staff to maintain, and produced functional overlap.

Consolidating onto Okta eliminated much of this redundancy. Okta Lifecycle Management capabilities replaced standalone provisioning tools and manual identity operations through integrations with HR systems; centralized governance capabilities displaced legacy access certification tooling, including homegrown solutions; access management capabilities replaced legacy SSO vendors; and automation through Workflows reduced the need for custom scripts and manual processes previously required to manage identity operations.

Beyond direct point solution consolidation, interviewees identified SaaS license waste as a significant cost driver in their prior environments. Limited visibility into application usage meant access was often provisioned broadly and resulted in unused or underutilized licenses across their organizations. By serving as a centralized authentication layer, Okta provided visibility into actual application use across the employee base, which allowed interviewees’ organizations to identify unused accounts and reclaim licenses.

Staffing requirements to support identity operations also declined. In prior environments, teams had to manage provisioning, access reviews, and policy enforcement manually across multiple systems. With consolidation and automation, the platform absorbed many of these tasks, reducing the number of resources required to manage the identity environment while allowing existing staff to focus on higher-value activities, including improving identity governance practices, strengthening security policies, optimizing access controls, and supporting strategic IT and security initiatives.

  • The IT infrastructure manager in software reported that their organization realized $500,000 in annual savings from reduced SaaS sprawl, noting: “Because everything is behind SSO, we get visibility into all the applications people are using, including overlaps. That allows us to proactively guide users toward tools we already have instead of buying new ones. Without that visibility, it’s easy for teams to adopt new tools without realizing there’s already something in place that does the same thing. Over time, that leads to a lot of duplication across systems.”
    The manager continued: “When we revoke an account, it automatically removes access across downstream systems, which eliminates associated licenses. One identity can be tied to multiple applications, so removing unused access creates cascading savings across the environment. It’s also much easier to see who is actually using a tool when everyone is required to log in through SSO. That visibility helps us avoid overprovisioning licenses, especially for teams where access is broadly assigned but not actively used.”

  • The VP of information security in insurance said: “Switching from [our legacy MFA solution] to Okta was a direct cost saving. On user access reviews, Okta Identity Governance replaced our in-house system, so we saved development time and didn’t need resources dedicated to maintaining it.”
    The VP added: “There are also time savings from an IT perspective because it’s a single pane of glass. When you can manage everything from one system instead of bouncing between tools, it makes a big difference operationally.”

  • The IAM staff engineer in fintech shared: “With Lifecycle Management, we can quickly see which users are assigned to applications and when they last logged in. Business owners can track usage, like how many users accessed an application in the last 60 or 90 days. That visibility helps them understand whether an application is actually being used. For example, if we’re paying for 2,000 licenses but only a small portion of users are active, it becomes clear that we’re not getting full value and then we can cut back on our spend.”

  • The senior SecOps engineer in software said: “One of the biggest areas we consolidated was credential management. We previously had multiple password management tools, and we reduced that down significantly. Cost-wise, that was roughly a 50% reduction based on what we saw in renewals.”
    The engineer continued: “Without Okta, managing identity would require a much larger team. We now have a much smaller team managing the environment because automation handles provisioning, workflows, and integrations at scale. We’re running millions of automated actions that would otherwise require manual effort.”

Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:

  • The composite incurs $200,000 annually for legacy identity point solutions in the prior environment, including tools for SSO, MFA, provisioning, governance, and credential management. With Okta, the composite decommissions 75% of these point solutions in Year 1 and 100% by Years 2 and 3.

  • The composite organization has 9,000 employees, each requiring access to a range of SaaS applications to perform their roles, and on average, the composite spends $1,500 per employee annually on SaaS licenses. With Okta, the composite reduces unused and underutilized software licensing spend by 4%.

  • In the prior environment, the composite dedicates 10 full-time resources to managing identity systems, including provisioning, access reviews, and policy enforcement across multiple tools. The composite reduces the number of resources required to manage identity operations by 66% with Okta.

  • The average fully burdened annual salary for an identity management resource is $127,920.

  • For this benefit, the composite has a productivity recapture rate of 50%. Employees spend half of the time they save on activities that generate business value, but not all reclaimed time is dedicated to value-added work.

Risks. This benefit will vary among organizations based on:

  • The volume and cost of point solutions in the prior environment, which will vary based on the breadth of the existing identity tooling landscape and the degree of vendor consolidation achieved with Okta.

  • The number of employees and the average percentage carrying unused SaaS licenses, which will vary based on organization size, SaaS portfolio complexity, and the maturity of license management processes before deploying Okta.

  • The number of resources dedicated to managing the prior identity environment and their fully burdened annual salaries.

Results. To account for these risks, Forrester adjusted this benefit downward by 15%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $2.4 million.

4%

Reduction in unused software licensing spend and SaaS sprawl

$1.6 million

Cost savings from reduced unused software licensing spend over three years

“The value of Okta is priceless. Having a single place to see, manage, and verify access has significantly reduced overhead. The time savings alone are immeasurable.”

IT systems admin, software

Legacy Environment Savings

Ref. Metric Source Year 1 Year 2 Year 3
C1 Point solution spend in prior environment Composite $200,000 $200,000 $200,000
C2 Decommission rate with Okta Interviews 75% 100% 100%
C3 Subtotal: Reduction in legacy software spend C1*C2 $150,000 $200,000 $200,000
C4 Employees Composite 9,000 9,000 9,000
C5 Average total SaaS licensing spend per employee Composite $1,500 $1,500 $1,500
C6 Reduction in unused software licensing spend and SaaS sprawl with Okta Interviews 4% 4% 4%
C7 Subtotal: Reduced unused software license spend and SaaS sprawl C4*C5*C6 $540,000 $540,000 $540,000
C8 Resources dedicated to management of prior environment Composite 10 10 10
C9 Reduction in resources required to manage environment with Okta Interviews 66% 66% 66%
C10 Average fully burdened annual salary for an IAM engineer and IT resource Composite $127,920 $127,920 $127,920
C11 Productivity recapture TEI methodology 50% 50% 50%
C12 Subtotal: Reduced ongoing identity platform management effort C8*C9*C10*C11 $422,136 $422,136 $422,136
Ct Legacy environment savings C3+C7+C12 $1,112,136 $1,162,136 $1,162,136
  Risk adjustment 15%      
Ctr Legacy environment savings (risk-adjusted)   $945,316 $987,816 $987,816
Three-year total: $2,920,947 Three-year present value: $2,417,915

Faster Application Onboarding

Evidence and data. Before adopting an identity security fabric with Okta, interviewees described onboarding new internal applications to their identity environments as a manual, time-intensive process that required custom integrations, application-specific provisioning logic, and coordination across teams. With Okta, app onboarding became faster and more standardized. The Okta Integration Network (OIN), with pre-built SAML, OIDC, and SCIM integrations, reduced the need for custom configuration, while Okta Lifecycle Management automated provisioning and deprovisioning across applications, which eliminated the need to build and maintain application-specific scripts. Okta Workflows further reduced effort for more complex integrations by enabling teams to automate conditional logic and multisystem processes without custom development. This streamlined approach reduced initial setup time and ongoing maintenance, enabling teams to onboard additional applications without increasing integration effort.

  • The IAM staff engineer in fintech explained: “Before Okta, we had to build provisioning and deprovisioning for each application individually, which could take three to four weeks per application. There was also ongoing effort required to maintain those integrations. After moving to Okta and using standard protocols, onboarding takes only a few hours to configure provisioning and access.”
    The engineer added: “We also use group-based rules heavily, which allows us to automate access changes very quickly. Tasks that previously took days, like setting up groups and managing access, can now be handled in minutes.”

  • The senior SecOps engineer in software shared: “Onboarding time still depends somewhat on the application, but when a prebuilt integration is available, it becomes very straightforward. We can complete the entire setup, including sign-on, group-based access, and provisioning much more quickly now.”
    The engineer continued: “If onboarding takes longer, it’s usually because of limitations on the application side rather than anything related to Okta. When integrations are supported, the process is quick and repeatable.”

  • The VP of information security in insurance said: “We’ve seen some meaningful time savings for onboarding an application. Once you’ve set up an application once, it becomes second nature rather than having to learn a different approach for every application. In the past, for something like a SaaS trial, we might not have even bothered setting up SSO because it required too much effort. With Okta, if the application is already supported, we’ll onboard it into our environment right away so users can access it with SSO. It’s just much more convenient to do so.”

Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:

  • The composite onboards 40 new applications in Year 1, 45 in Year 2, and 50 in Year 3.

  • In the prior environment, onboarding each new application required 40 hours on average. With Okta, the composite reduces the time required to onboard each application by 75%.

  • The average fully burdened hourly rate for an IAM engineer is $88.

  • For this benefit, the composite has a productivity recapture rate of 50%. Employees spend half of the time they save on activities that generate business value, but not all reclaimed time is dedicated to value-added work.

Risks. This benefit will vary among organizations based on:

  • The number of new internal applications onboarded per year.

  • The average time required to onboard a new application in the prior environment, which will vary based on the complexity of legacy integration approaches and the degree of custom development previously required.

  • The fully burdened hourly rate for IAM engineers involved in application onboarding.

Results. To account for these risks, Forrester adjusted this benefit downward by 15%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $125,000.

75%

Reduction in time to onboard new applications

“Now that we are doing much more automation in Okta, it has become one of the most critical systems in our company.”

IAM staff engineer, fintech

Faster Application Onboarding

Ref. Metric Source Year 1 Year 2 Year 3
D1 New applications onboarded Composite 40 45 50
D2 Average time to onboard each new application before Okta (hours) Composite 40 40 40
D3 Reduction in time to onboard new applications with Okta Interviews 75% 75% 75%
D4 Average time to onboard each new application reclaimed with Okta (hours) D2*D3 30 30 30
D5 Total time to onboard and integrate new applications reclaimed with Okta (hours) D1*D4 1,200 1,350 1,500
D6 Average fully burdened hourly rate for an IAM engineer Composite $88 $88 $88
D7 Productivity recapture TEI methodology 50% 50% 50%
Dt Faster application onboarding D5*D6*D7 $52,800 $59,400 $66,000
  Risk adjustment 15%      
Dtr Faster application onboarding (risk-adjusted)   $44,880 $50,490 $56,100
Three-year total: $151,470 Three-year present value: $124,676

Reduction In Identity And Access Management-Related Support Tickets

Evidence and data. Interviewees said access request and identity management tickets were a persistent drain on help desk capacity before they adopted an identity security fabric with Okta. Fulfilling a single request often required coordination across multiple teams, including manual routing, approvals, and provisioning across individual applications. Password resets, account unlocks, and routine access requests generated a steady volume of repetitive, low-complexity tickets.

Okta reduced this volume across several areas. Okta Lifecycle Management enabled automatic birthright access based on HR-driven attributes, which eliminated many access requests at onboarding. For non-birthright access, Okta Identity Governance provided a self-service request catalog with built-in approvals and automated provisioning to mitigate help desk involvement for supported applications. Within Okta Access Management, passwordless authentication reduced reliance on passwords and significantly lowered reset-related tickets. Workflows further streamlined fulfillment by automating multistep provisioning tasks that previously required manual intervention to enable consistent, round-the-clock processing.

  • The VP of information security in insurance said: “Previously, access requests had to be routed to multiple teams, each responsible for a different system. Tickets would sit in queues, get picked up, and then require manual work to provision access. With automation through Workflows, that process has been streamlined significantly. We’ve eliminated a lot of the manual onboarding and offboarding steps across systems and reduced the number of people involved. Onboarding a user used to take close to two days for the help desk. Now it’s closer to 2 to 3 hours, with much less manual intervention.”

  • The IT infrastructure manager in software explained: “We’ve seen around a 30% reduction in ticket volume. A lot of the common requests are now automated: Instead of creating tickets, we build access workflows that handle those requests automatically.”
    The manager continued: “In Okta, setting up access for a new application takes about a minute, compared to building custom workflows in ticketing systems before. That makes it much easier to eliminate repetitive access request tickets.”

  • The IAM staff engineer in fintech said: “Before, we were getting around 20 password reset requests alone per week. Since moving to Okta FastPass and eliminating passwords, that number has dropped to zero. Previously, each request took about 20 minutes to resolve because we had to verify the user and handle the reset securely.”

  • The IT systems admin in software shared: “Access request tickets have dropped by over 95%. Instead of going back and forth to approve and provision access, users can request access through the catalog, managers approve it, and provisioning happens automatically. From the help desk perspective, there’s essentially no involvement for most requests anymore.”
    The IT systems admin continued: “Workflows also take over a lot of processes that other teams used to manage themselves. We’ve centralized that and automated it, which reduces overhead not just for the help desk but for other teams as well.”

  • The senior SecOps engineer in software said: “The time savings isn’t just the task itself; it’s eliminating delays in how tickets get processed. Before, requests would sit unworked outside business hours until someone on the team could pick them up. With Workflows, those requests are handled immediately, regardless of time zone. Instead of tickets sitting idle for hours, the system processes them automatically.”
    The engineer continued: “Because so much of this is now automated, we don’t need on-call support for these types of requests anymore. The system handles most of the day-to-day access and provisioning tasks without intervention.”

Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:

  • The composite organization receives 100 IAM-related support tickets per week. With Okta, the composite reduces IAM support ticket volume by 40% in Year 1, 45% in Year 2, and 50% in Year 3.

  • In the prior environment, each IAM support ticket required 1 hour on average to resolve, including time spent routing, approving, and provisioning access across systems. With Okta, the composite reduces the time required to resolve IAM tickets by 60%.

  • The average fully burdened hourly rate for an IT resource handling support tickets is $35.

Risks. This benefit will vary among organizations based on:

  • The volume of IAM-related support tickets generated per week in the prior environment.

  • The average time required to resolve each IAM-related support ticket in the prior environment.

  • The fully burdened hourly rate for IT resources handling identity and access support tickets.

Results. To account for these risks, Forrester adjusted this benefit downward by 15%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $103,000.

50%

Reduction in IAM support ticket volume by Year 3

Reduction In Identity And Access Management-Related Support Tickets

Ref. Metric Source Year 1 Year 2 Year 3
E1 IAM support tickets per week in prior environment Composite 100 100 100
E2 Reduction in IAM support ticket volume with Okta Interviews 40% 45% 50%
E3 IAM support tickets eliminated with Okta E1*52 weeks*E2 2,080 2,340 2,600
E4 Average time to resolve each IAM support ticket before Okta (hours) Composite 1.0 1.0 1.0
E5 Reduction in time to resolve IAM support ticket with Okta Interviews 60% 60% 60%
E6 Time reclaimed per IAM support ticket with Okta (hours) E4*E5 0.6 0.6 0.6
E7 Total time reclaimed (hours) E3*E6 1,248 1,404 1,560
E8 Fully burdened hourly rate for an IT resource Composite $35 $35 $35
Et Reduction in identity and access management-related support tickets E7*E8 $43,680 $49,140 $54,600
  Risk adjustment 15%      
Etr Reduction in identity and access management-related support tickets (risk-adjusted)   $37,128 $41,769 $46,410
Three-year total: $125,307 Three-year present value: $103,141

Improved Efficiency Of Access Reviews And Compliance Certifications

Evidence and data. Interviewees described access certification and entitlement reviews as among the most operationally burdensome recurring obligations their teams faced before Okta. The process was largely manual: Teams exported user entitlement data from individual applications, distributed spreadsheets to managers via email, tracked responses manually, followed up repeatedly to collect certifications, and then triggered deprovisioning actions by hand for any access that was revoked. For organizations running reviews across dozens of applications and hundreds of user populations, the cumulative administrative effort consumed weeks of work per campaign cycle, and the friction involved meant many organizations ran reviews less frequently than their security or compliance posture required.

Interviewees said that OIG transformed access certifications from a manual coordination exercise into a configured, automated workflow. Their organizations created campaigns that were defined once and executed consistently, with in-application reviewer tasks, automated reminder sequences via email and messaging platforms, and policy-driven remediation that automatically triggered deprovisioning through SCIM or Okta Workflows for applications without native provisioning support. Designated reviewers could review and bulk approve or reject entitlements directly within the platform without navigating spreadsheets or responding to email chains, while teams responsible for administering access certifications were freed from the tracking and follow-up work that had previously dominated campaign cycles.

  • The VP of information security in insurance explained: “Okta Identity Governance replaced an in-house system we had built for access reviews. Previously, we had a resource spending a meaningful portion of their time maintaining it, especially during review cycles.”
    The system engineer architect at the same organization added: “Access reviews were time-consuming, which limited how often we could run them. In some cases, we struggled to complete them even once a year. With Okta, we’re now able to run them twice a year and are working toward increasing that frequency further.”

  • The IT systems admin in software shared: “Monthly access campaigns used to require pulling exports, creating tickets, and following up with reviewers. It took two to three months of effort from multiple admins to complete a full cycle. Now, we can initiate a campaign, run automated reminders, and handle most remediation through Okta. What used to take months now takes about 8 hours of effort for one person. It’s a huge time savings.”

  • The IT systems admin added: “We run dozens of campaigns each quarter across different user roles and systems. Okta allows managers to review and bulk approve or reject access directly in the platform instead of working through spreadsheets or tickets. If access is revoked, deprovisioning is handled automatically through integrations or Workflows. Even where additional steps are required, we can automate most of that, which removes a lot of the manual follow-up and remediation effort.”

Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:

  • The composite runs 200 access review and compliance certification campaigns annually that cover regulatory requirements, internal security reviews, and entitlement certifications across the application portfolio.

  • In the prior environment, each campaign required 8 hours of administrative and coordination effort on average. With OIG, the composite reduces administrative and coordination effort per campaign by 90%.

  • The average fully burdened hourly rate for an IAM engineer or security/GRC administrator responsible for coordinating access certification campaigns is $74.

  • For this benefit, the composite has a productivity recapture rate of 50%. Employees spend half of the time they save on activities that generate business value, but not all reclaimed time is dedicated to value-added work.

Risks. This benefit will vary among organizations based on:

  • The number of access review and compliance certification campaigns run per year, which will vary based on the size of the workforce, the number of applications in scope, and the frequency of reviews required by internal security policies and regulatory obligations.

  • The average administrative and coordination effort per campaign in the prior environment, which will vary based on the degree of manual processes involved and the tools previously used to manage certifications.

  • The fully burdened hourly rate for resources involved in access review and compliance certification activities.

Results. To account for these risks, Forrester adjusted this benefit downward by 15%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $109,000.

90%

Reduction in time spent on administrative and coordination effort per access certification campaign

Improved Efficiency Of Access Reviews And Compliance Certifications

Ref. Metric Source Year 1 Year 2 Year 3
F1 Workforce access review and compliance certification campaigns Composite 200 200 200
F2 Average time spent on administrative and coordination effort per access certification campaign before Okta (hours) Composite 8 8 8
F3 Reduction in time spent on administrative and coordination effort per access certification campaign with Okta Interviews 90% 90% 90%
F4 Total time reclaimed on administrative and coordination effort per access certification campaign with Okta (hours) (rounded) F2*F3 7 7 7
F5 Average fully burdened hourly rate for an IAM engineer or security/GRC administrator Composite $74 $74 $74
F6 Productivity recapture TEI methodology 50% 50% 50%
Ft Improved efficiency of access reviews and compliance certifications F1*F4*F5*F6 $51,800 $51,800 $51,800
  Risk adjustment 15%      
Ftr Improved efficiency of access reviews and compliance certifications (risk-adjusted)   $44,030 $44,030 $44,030
Three-year total: $132,090 Three-year present value: $109,496

Improved M&A Efficiency

Evidence and data. For organizations that have undergone mergers and acquisitions, interviewees explained that integrating identity environments required coordinated effort across directory consolidation, user data alignment, and access reconfiguration. These activities were typically manual and sequential, which extended integration timelines over several months. With Okta, these organizations streamlined identity integration by connecting existing directory environments and standardizing access earlier in the process. Okta Lifecycle Management automated the provisioning of users based on existing directory attributes, while Okta Workflows supported the automation of access assignment and migration tasks across systems. This removed dependencies on manual coordination and directory consolidation to accelerate integration timelines and subsequently reduce IT effort.

The VP of information security in insurance explained: “We went through an acquisition after moving to Okta, and it was much easier, especially for Day 1 access. We deployed the AD agent into the acquired environment and were able to start granting users access immediately instead of waiting on months of planning and integration.”

The VP added: “We could integrate Okta with [the other organization’s] Active Directory and provide application access without waiting for full directory consolidation. In prior acquisitions, this process took six to nine months. With Okta, we completed it in two to three months. It was a huge difference.”

Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:

  • The composite completes one merger or acquisition event in Year 1 and Year 3. For each event, 10 IT resources are involved in identity integration efforts and spend 75% of their time on M&A-related integration activities.

  • In the prior environment, identity and data integration requires six months on average. With Okta, the composite reduces the time required for identity and data integration by 65%.

  • The average fully burdened hourly rate for an IT resource involved in M&A integration is $35.

  • For this benefit, Forrester assumes a 50% productivity recapture rate, meaning that half of the time savings is redirected toward activities that generate business value.

Risks. This benefit will vary among organizations based on:

  • The frequency of mergers and acquisitions, which will vary based on an organization’s growth strategy and corporate development activity.

  • The number of IT resources involved in identity integration efforts during M&A events and the percentage of their time dedicated to this work.

  • The complexity of an acquired organization’s identity environment and the degree of Active Directory consolidation required.

Results. To account for these risks, Forrester adjusted this benefit downward by 15%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $116,000.

65%

Reduction in time spent on data integration for M&A

Improved M&A Efficiency

Ref. Metric Source Year 1 Year 2 Year 3
G1 Average M&A instances Composite 1 0 1
G2 IT resources involved in combining active directory environments Composite 10 10 10
G3 Average percentage of IT time spent on M&A Interviews 75% 75% 75%
G4 Average time spent on data integration before Okta (months) Composite 6 6 6
G5 Reduction in time spent on data integration for M&A with Okta Interviews 65% 65% 65%
G6 Time reclaimed for M&A effort (hours) G1*G2*G3*160 hours*G4*G5 4,680 0 4,680
G7 Average fully burdened hourly rate for an IT resource E8 $35 $35 $35
G8 Productivity recapture TEI methodology 50% 50% 50%
Gt Improved M&A efficiency G6*G7*G8 $81,900 $0 $81,900
  Risk adjustment 15%      
Gtr Improved M&A efficiency (risk-adjusted)   $69,615 $0 $69,615
Three-year total: $139,230 Three-year present value: $115,589

Unquantified Benefits

Interviewees mentioned the following additional benefits that their organizations experienced but were not able to quantify:

  • Improved visibility into and control over AI agents and shadow AI. As interviewees’ organizations expanded their use of AI tools and autonomous agents, Okta’s centralized authentication and access control layer provided an increasingly important foundation for governing how those tools accessed enterprise systems. By requiring users of AI applications to authenticate through Okta and enforcing device trust, phishing-resistant authentication, and contextual access policies for critical systems, organizations gained visibility into which AI tools were operating in their environments and the ability to revoke access from human and nonhuman identities instantly when needed. Interviewees acknowledged that AI governance remained an evolving challenge, with shadow AI representing a particularly difficult problem, but noted that having centralized identity controls already in place made it significantly easier to detect unauthorized tools, enforce access boundaries, and respond to ungoverned AI activity.

    • The IT infrastructure manager in software said: “Having a centralized identity layer gives us visibility into what’s connecting to our systems and who has access. We can enforce policies like requiring managed devices and restrict where and how systems are accessed, which makes it much harder for unauthorized AI tools or agents to interact with our environment.”
      The manager continued: “AI introduces new risks because tools can be connected without full oversight. Having centralized authentication means we can monitor access and apply consistent controls, rather than trying to manage it across individual systems.”
    • The IT systems admin in software said: “Most AI tools have to go through [Okta]. We block direct sign-ups and require access through SSO, and only our IT team can create and manage those accounts. That helps us limit shadow use and keep things governed. There are still cases where someone sets something up outside of that process, but with [Okta’s] controls like verified domains and application restrictions, we’re able to reduce that risk and bring it back under governance.”
    • The IAM staff engineer in fintech explained: “One of the main concerns with AI is making sure these agents don’t have excessive access. When you connect an agent to applications, it can easily end up with more permissions than it actually needs. That’s why we’re focused on putting guardrails in place between AI systems and our applications. We’re being deliberate about how we roll out AI. We want to make sure access is controlled and limited, and that we can govern how these agents interact with our systems.”
    • The senior SecOps engineer in software shared: “Every AI application we’re using is integrated with our identity layer for authentication and access control. That gives us a central point to manage access and understand how those tools interact with our environment.”
      The engineer continued: “We’re also using AI in a controlled way to query identity data and surface access information. Instead of manually generating reports or pulling data, we can automate those queries, which reduces manual work while still keeping everything governed through Okta.”

  • Faster employee onboarding. Interviewees described a fundamental shift in how they provisioned new employees after integrating Okta with HR systems of record. By establishing their HR system as the authoritative identity source, the act of creating or updating an employee record automatically triggered downstream account creation and application provisioning in Okta, which eliminated the manual handoffs, email-based requests, and days-long delays that had previously left new hires without access on their first day. Birthright access policies ensured that employees arrived with the applications and entitlements appropriate to their role already in place, while access requests for anything beyond birthright were fulfilled automatically upon manager approval.

    • The VP of information security in insurance explained: “Integrating Okta with [our HR system] was a major improvement for us because it became our single source of truth. Previously, we had to wait for emails from HR to trigger account creation or deactivation. Now, once a user is created in the system, it automatically kicks off provisioning in Okta. Before, a new employee might have partial access on Day 1, but it could take several days to get everything they needed. With Okta, that process is much more complete and consistent.”

“Okta has made a big difference for onboarding. New employees start with the access they need instead of waiting days to get fully provisioned across systems. They can get to work much faster.”

VP of information security, insurance

  • The senior SecOps engineer in software said: “Onboarding used to involve a lot of coordination. We had scheduled blocks each week just to create accounts, and it took about 30 minutes per user, not including all the back and forth to set up credentials and walk users through access.”
    The engineer continued: “Now everything is much more consolidated. We don’t have to manually set up accounts or walk users through the process. It’s handled automatically, which eliminates a lot of the overhead.”

  • The IAM staff engineer in fintech said: “Before Okta, our onboarding and offboarding automation was really complicated and required support from multiple engineers to maintain. It wasn’t very efficient or easy to manage. After moving to Okta Workflows, one engineer was able to rebuild the process, and it’s now much simpler. We only review it periodically instead of constantly maintaining it.”
    The engineer concluded: “Those resources have been freed up, and the process is easier for others to understand and update when changes are needed. That’s been one of the biggest improvements for us.”

  • Reduced end-user authentication friction. Interviewees reported that Okta’s SSO and Okta FastPass significantly reduced the time employees spent authenticating throughout the workday. By replacing repeated credential entry with a single authentication event and enabling passwordless access, their organizations reduced login times from tens of seconds to just a few seconds per authentication. These improvements reduced friction during daily workflows and minimized the interruptions associated with repeated logins, particularly in environments where employees authenticate frequently across applications.

    • The IAM staff engineer in fintech said: “Before Okta, users spent around 30 seconds logging into applications. With Okta Verify and FastPass, that’s been reduced to about 2 to 3 seconds. That time savings adds up because employees log in multiple times throughout the day; in our case, around 10 times per day. It’s a noticeable improvement in how quickly they can access applications.”

  • Strategic vendor partnership. Interviewees described Okta as an active partner (rather than a transactional vendor) that engaged with them regularly to understand evolving requirements and support long-term identity strategies. This ongoing collaboration helped their organizations align their roadmaps with new capabilities, make more informed implementation decisions, and build internal momentum for identity initiatives.

    • The system engineer architect in insurance said: “Okta has been one of the vendors that really works to understand our challenges and where they can help. That relationship is very different from vendors we rarely engage with, and it makes it easier for us to evaluate and adopt new solutions because they understand what we’re trying to solve.”
    • The senior SecOps engineer in software explained: “Okta has become a trusted part of our strategy with leadership. When we bring forward new initiatives tied to Okta, there’s already confidence in the platform because it has consistently delivered value. That credibility helps us move faster. We don’t have to rejustify the investment each time; it’s already seen as a proven foundation for new capabilities and workflows.”

Flexibility

The value of flexibility is unique to each customer. There are multiple scenarios in which a customer might adopt an identity security fabric with Okta and later realize additional uses and business opportunities, including:

  • Securing AI agents and nonhuman identities. As their organizations expand their use of AI-powered tools and autonomous agents, interviewees described Okta as a foundational platform for governing nonhuman identities over time. While many organizations are still in the early stages of AI adoption, having centralized identity already in place positions them to onboard and manage these tools more effectively as use cases scale. Interviewees emphasized that authentication, policy enforcement, and provisioning frameworks will be critical to managing AI agents as first-class identities. As Okta continues to invest in capabilities for nonhuman identity management, interviewees expect the platform to play a central role in enabling secure and scalable AI adoption.

    • The VP of information security in insurance said, “We’re still early in our AI adoption, but it’s much easier to establish the right security controls at the beginning than it is to go back later and try to find and govern all of these AI agents.”
      They concluded, “As we deploy AI agents, Okta’s capabilities provide a layer of visibility and control that will be important as we expand our usage.”

  • Expanding identity-driven automation. Interviewees described a compounding return as their organizations expand automation beyond initial provisioning and access use cases to encompass broader identity and IT operations. As teams became more familiar with Okta Workflows, they identified additional manual processes that could be automated, steadily increasing the scope of efficiency gains. The platform’s no-code approach enabled this expansion without requiring dedicated development resources, allowing automation to scale alongside organizational needs. Over time, interviewees expect identity operations to continue shifting away from manual coordination toward more automated, policy-driven processes to further embed efficiency across identity and access management functions.

  • Future-proofing identity investments. Organizations that have already deployed Okta for workforce identity can extend the same platform, policies, integrations, and operational expertise to new identity use cases without introducing additional identity infrastructure. Interviewees noted that they can leverage established governance frameworks, authentication controls, and provisioning processes as identity requirements evolve, which allows their organizations to address emerging business and security needs using capabilities already in place. This positions their organizations to support future identity scenarios, including AI agents and nonhuman identities, while maximizing the value of prior investments, reducing complexity, and avoiding the need for separate identity solutions.

Flexibility would also be quantified when evaluated as part of a specific project (described in more detail in Total Economic Impact Approach).

Analysis Of Costs

Quantified cost data as applied to the composite

Total Costs

Ref. Cost Initial Year 1 Year 2 Year 3 Total Present Value
Htr Fees to Okta $141,750 $1,426,950 $1,426,950 $1,426,950 $4,422,600 $3,690,363
Itr Implementation, ongoing management, and training effort $195,300 $405,552 $405,552 $405,552 $1,411,956 $1,203,848
  Total costs (risk-adjusted) $337,050 $1,832,502 $1,832,502 $1,832,502 $5,834,556 $4,894,211

Fees To Okta

Evidence and data. Interviewees reported that their organizations paid annual licensing fees for the Okta Platform, typically structured as a unified pricing bundle that encompassed capabilities including access management, governance, posture management, threat detection, privileged access, and device trust, with built-in orchestration to automate identity workflows across the enterprise technology stack. Pricing was structured on a per user per month basis and remained fixed over their three-year contract term.

Interviewees explained that the annual fee also included the Gold Premier Success Plan, which provided access to dedicated success resources and priority support to help drive adoption and maximize platform value. In addition to recurring subscription costs, organizations incurred a one-time professional services investment at the outset of their engagements to support deployment planning and initial configuration. Interviewees described managing most implementation activities internally, with professional services focused on enabling setup and supporting early platform rollout.

Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:

  • The composite enters into a three-year agreement with Okta for the Okta Platform for 9,000 employees.

  • Annual fees include the Gold Premier Success Plan, which provides dedicated success resources and priority support throughout the agreement term.

  • The composite incurs a one-time professional services investment at the outset of the engagement to support deployment planning and initial configuration.

  • Pricing is fixed for the duration of the agreement term. Pricing may vary. Contact Okta for additional details.

Risks. This cost will vary among organizations based on:

  • The number of workforce identities licensed.

  • The specific Okta products and SKUs included in the agreement.

  • Negotiated pricing, contract terms, and discount levels.

Results. To account for these risks, Forrester adjusted this cost upward by 5%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $3.7 million.

Fees To Okta

Ref. Metric Source Initial Year 1 Year 2 Year 3
H1 Annual licensing fee and Gold Premier Success Plan Okta   $1,359,000 $1,359,000 $1,359,000
H2 Okta Professional Services Okta $135,000      
Ht Fees to Okta H1+H2 $135,000 $1,359,000 $1,359,000 $1,359,000
  Risk adjustment 5%        
Htr Fees to Okta (risk-adjusted)   $141,750 $1,426,950 $1,426,950 $1,426,950
Three-year total: $4,422,600 Three-year present value: $3,690,363

Implementation, Ongoing Management, And Training Effort

Evidence and data. Interviewees reported that their organizations incurred internal labor costs to support the implementation, ongoing management, and training required to operate Okta. Implementation effort was driven primarily by the number of applications being integrated, the number of products deployed, and whether organizations were migrating from legacy identity systems. Initial deployments typically spanned several months and involved a small number of internal resources responsible for configuration, testing, and rollout. In migration scenarios, additional effort was required to transition applications and establish governance, though the work remained concentrated within a limited team.

Interviewees explained that once the core platform was established, enabling additional capabilities or deploying new products required significantly less effort. Most new features were implemented following a short period of testing and validation, while the actual configuration effort was limited and deployment was often straightforward. The majority of time associated with these efforts was attributed to internal testing, communication, and change management rather than technical complexity.

Interviewees indicated that ongoing management required consistent but manageable effort from a dedicated group of IAM and IT resources. Ongoing responsibilities included maintaining the provisioning and deprovisioning of workflows, onboarding new applications, managing authentication policies, and supporting access governance processes.

Training effort was light. Interviewees described a short onboarding period supported by documentation and guided troubleshooting and an intuitive user experience, enabling personnel to become effective on core tasks quickly. On-demand access to resources also supported continuous, situational learning as users encountered new scenarios. Training was concentrated during the initial rollout and remained minimal thereafter, focused on onboarding new personnel and supporting incremental feature adoption.

  • The IT systems admin in software said: “Most features are straightforward to enable; often it’s just turning on a feature flag. The actual implementation takes very little time, but we spend one to two weeks testing and making sure everything behaves as expected before rolling it out.”
    The IT systems admin added, “Our day-to-day work includes maintaining workflows for provisioning, deprovisioning, and alerting, along with onboarding new applications as they come in.”

  • The VP of information security in insurance explained: “We were able to deploy Okta Device Access to all users in about a month after a similar period of testing. The effort was manageable and involved only a small number of resources. During broader rollouts, we also had help desk staff supporting users through the transition, which required coordination but not extensive technical effort.”

Modeling and assumptions. Based on the interviews, Forrester assumes the following about the composite organization:

  • The composite deploys the Okta Platform, including Access Management (Universal Directory, SSO, Adaptive MFA, etc.), OIG, ISPM, ITP, OPA, ODA, and Okta Workflows, which work together to provide end-to-end identity security — from visibility and access control to governance and remediation.

  • Implementation is supported by a team of three internal resources dedicated full time for six months to configuration, testing, and rollout activities. The average fully burdened hourly rate for an IAM engineering or IT resource is $62.

  • Following initial deployment, five internal resources support ongoing management of the Okta environment and dedicate approximately 60% of their time to platform administration. The average fully burdened annual salary for an IAM engineering or IT resource is $127,920.

  • Initial training includes 15 Okta administrators and support personnel, each requiring an average of 8 hours to become effective in core platform tasks. In Years 1 through 3, ongoing training supports five personnel annually to accommodate new hires and incremental feature adoption, with an average fully burdened hourly rate of $62.

Risks. This cost will vary among organizations based on:

  • The scope of the identity security platform deployment and the complexity of integrating or migrating existing identity systems, applications, and environments, which will affect the overall implementation effort required.

  • The number of resources involved in ongoing management and the percentage of their time dedicated to Okta administration, which will vary based on the size of the identity environment and the degree of automation achieved.

  • The number of personnel requiring initial and ongoing training and the time required to reach proficiency, which will vary based on the organization’s prior identity management experience and the complexity of the deployment.

Results. To account for these risks, Forrester adjusted this cost upward by 5%, yielding a three-year, risk-adjusted total PV (discounted at 10%) of $1.2 million.

Implementation, Ongoing Management, And Training Effort

Ref. Metric Source Initial Year 1 Year 2 Year 3
I1 Total time dedicated to implementation (months) Composite 6      
I2 Resources involved during implementation period Composite 3      
I3 Average fully burdened hourly rate for an IAM engineer or IT resource C10/2,080 hours $62 $62 $62 $62
I4 Subtotal: Implementation effort I1*160 hours*I2*I3 $178,560      
I5 Resources involved in ongoing management Composite   5 5 5
I6 Average percentage of time spent on ongoing management Interviews   60% 60% 60%
I7 Average fully burdened annual salary for an IAM engineer or IT resource C10   $127,920 $127,920 $127,920
I8 Subtotal: Ongoing management effort I5*I6*I7   $383,760 $383,760 $383,760
I9 Okta admin and support personnel Composite 15 5 5 5
I10 Time spent on training (hours) Interviews 8 8 8 8
I11 Average fully burdened hourly rate for an IAM engineer or IT resource I3 $62 $62 $62 $62
I12 Subtotal: Training effort I9*I10*I11 $7,440 $2,480 $2,480 $2,480
It Implementation, ongoing management, and training effort I4+I8+I12 $186,000 $386,240 $386,240 $386,240
  Risk adjustment 5%        
Itr Implementation, ongoing management, and training effort (risk-adjusted)   $195,300 $405,552 $405,552 $405,552
Three-year total: $1,411,956 Three-year present value: $1,203,848

Financial Summary

Consolidated Three-Year, Risk-Adjusted Metrics

Cash Flow Chart (Risk-Adjusted)

[CHART DIV CONTAINER]
Total costs Total benefits Cumulative net benefits Initial Year 1 Year 2 Year 3

Cash Flow Analysis (Risk-Adjusted)

  Initial Year 1 Year 2 Year 3 Total Present Value
Total costs ($337,050) ($1,832,502) ($1,832,502) ($1,832,502) ($5,834,556) ($4,894,211)
Total benefits $0 $7,021,970 $6,133,856 $5,342,472 $18,498,298 $15,466,789
Net benefits ($337,050) $5,189,468 $4,301,354 $3,509,970 $12,663,742 $10,572,578
ROI           216%
Payback           <6 months

 Please Note

The financial results calculated in the Benefits and Costs sections can be used to determine the ROI, NPV, and payback period for the composite organization’s investment. Forrester assumes a yearly discount rate of 10% for this analysis.

These risk-adjusted ROI, NPV, and payback period values are determined by applying risk-adjustment factors to the unadjusted results in each Benefit and Cost section.

The initial investment column contains costs incurred at “time 0” or at the beginning of Year 1 that are not discounted. All other cash flows are discounted using the discount rate at the end of the year. PV calculations are calculated for each total cost and benefit estimate. NPV calculations in the summary tables are the sum of the initial investment and the discounted cash flows in each year. Sums and present value calculations of the Total Benefits, Total Costs, and Cash Flow tables may not exactly add up, as some rounding may occur.

From the information provided in the interviews, Forrester constructed a Total Economic Impact™ framework for those organizations considering adopting an identity security fabric with Okta.

The objective of the framework is to identify the cost, benefit, flexibility, and risk factors that affect the investment decision. Forrester took a multistep approach to evaluate the impact that adopting an identity security fabric with Okta can have on an organization.

Due Diligence

Interviewed Okta stakeholders and Forrester analysts to gather data relative to adopting an identity security fabric with Okta.

Interviews

Interviewed six decision-makers at organizations that have adopted an identity security fabric with Okta to obtain data about costs, benefits, and risks.

Composite Organization

Designed a composite organization based on characteristics of the interviewees’ organizations.

Financial Model Framework

Constructed a financial model representative of the interviews using the TEI methodology and risk-adjusted the financial model based on issues and concerns of the interviewees.

Case Study

Employed four fundamental elements of TEI in modeling the investment impact: benefits, costs, flexibility, and risks. Given the increasing sophistication of ROI analyses related to IT investments, Forrester’s TEI methodology provides a complete picture of the total economic impact of purchase decisions. Please see Appendix A for additional information on the TEI methodology.

Total Economic Impact Approach

Benefits

Benefits represent the value the solution delivers to the business. The TEI methodology places equal weight on the measure of benefits and costs, allowing for a full examination of the solution’s effect on the entire organization.

Costs

Costs comprise all expenses necessary to deliver the proposed value, or benefits, of the solution. The methodology captures implementation and ongoing costs associated with the solution.

Flexibility

Flexibility represents the strategic value that can be obtained for some future additional investment building on top of the initial investment already made. The ability to capture that benefit has a PV that can be estimated.

Risks

Risks measure the uncertainty of benefit and cost estimates given: 1) the likelihood that estimates will meet original projections and 2) the likelihood that estimates will be tracked over time. TEI risk factors are based on “triangular distribution.”

Financial Terminology

Present value (PV)

The present or current value of (discounted) cost and benefit estimates given at an interest rate (the discount rate). The PVs of costs and benefits feed into the total NPV of cash flows.

Net present value (NPV)

The present or current value of (discounted) future net cash flows given an interest rate (the discount rate). A positive project NPV normally indicates that the investment should be made unless other projects have higher NPVs.

Return on investment (ROI)

A project’s expected return in percentage terms. ROI is calculated by dividing net benefits (benefits less costs) by costs.

Discount rate

The interest rate used in cash flow analysis to take into account the time value of money. Organizations typically use discount rates between 8% and 16%.

Payback

The breakeven point for an investment. This is the point in time at which net benefits (benefits minus costs) equal initial investment or cost.

Appendix A

Total Economic Impact

Total Economic Impact is a methodology developed by Forrester Research that enhances a company’s technology decision-making processes and assists solution providers in communicating their value proposition to clients. The TEI methodology helps companies demonstrate, justify, and realize the tangible value of business and technology initiatives to both senior management and other key stakeholders.

Appendix B

Endnotes

1 Total Economic Impact is a methodology developed by Forrester Research that enhances a company’s technology decision-making processes and assists solution providers in communicating their value proposition to clients. The TEI methodology helps companies demonstrate, justify, and realize the tangible value of business and technology initiatives to both senior management and other key stakeholders.

2 Forrester's Security Survey, 2026.

Disclosures

Readers should be aware of the following:

This study is commissioned by Okta and delivered by Forrester Consulting. It is not meant to be used as a competitive analysis.

Forrester makes no assumptions as to the potential ROI that other organizations will receive. Forrester strongly advises that readers use their own estimates within the framework provided in the study to determine the appropriateness of an investment in an identity security fabric with Okta. For any interactive functionality, the intent is for the questions to solicit inputs specific to a prospect’s business. Forrester believes that this analysis is representative of what companies may achieve by adopting an identity security fabric with Okta based on the inputs provided and any assumptions made. Forrester does not endorse Okta or its offerings. Although great care has been taken to ensure the accuracy and completeness of this model, Okta and Forrester Research are unable to accept any legal responsibility for any actions taken on the basis of the information contained herein. The interactive tool is provided ‘AS IS,’ and Forrester and Okta make no warranties of any kind.

Okta reviewed and provided feedback to Forrester, but Forrester maintains editorial control over the study and its findings and does not accept changes to the study that contradict Forrester’s findings or obscure the meaning of the study.

Okta provided the customer names for the interviews but did not participate in the interviews.

Consulting Team:

Zahra Azzaoui

Published

July 2026