These API permissions allow updates to be made directly from Oort to Duo
Name
Remediation Type
Grant write resource
Reset Factors
Okta SSWS API Token Scopes
API
HTTP Operation
/api/v1/*
READ
As we require the minimal set of privileges, the custom admin role must be created in order to support remediations in Oort (ref to Oort Help Desk Admin role in https://oortpreview-admin.oktapreview.com):
Add a "Machine to Machine" application (Applications --> Applications) should be configured in Auth0 (via a configured API (Applications --> APIs) with the following scope permissions:
Scope
Description
Purpose
read:users
Read Users
Get a list of Users
read:logs
Read Logs
Read Auth0 Event logs
read:user_logs
Read logs relating to users
Read Auth0 User logs
read:guardian_factors
Read Guardian factors configuration
Get a list of Users and Authenticator configurations