Having reviewed the add-on SKU and pricing sheet for Okta's new Identity Threat Protection (ITP) module, I have significant concerns regarding its commercial structure. While the feature set—integrating threat intelligence, detection, and automated response—is a logical extension of their platform, the pricing model appears to be a substantial departure from their traditional per-user bundling.
Initial analysis indicates ITP is being offered as a separate, user-based subscription layered on top of existing Advanced Server Access (ASA) or Identity Governance (IG) tiers. The effective cost per user, when factoring in the required pre-requisite products, creates a notable step-function increase in total cost of ownership (TCO). This raises several procurement questions:
* **Value Metric:** Is user-count the correct metric for a threat protection add-on, or would a model based on risk-scored events or protected resources be more aligned with consumption?
* **Benchmarking:** How does the compounded per-user price for Okta + ASA/IG + ITP compare to the per-user cost of competing standalone Identity Threat Detection and Response (ITDR) solutions? Early market intelligence suggests the gap may be narrower than expected.
* **Contract Lock-in:** The bundling creates deeper platform dependency. What are the exit costs if a future assessment finds a best-of-breed ITDR solution more effective?
For teams practicing FinOps, this introduces complexity in forecasting and attribute-based cost allocation. I'm keen to hear from others who have received formal quotes or are in negotiation.
Has anyone conducted a formal TCO comparison or negotiated alternative pricing structures (e.g., capped usage, enterprise-tier discounts) for this add-on? Specific data points on the achieved discount off list price for the bundle would be particularly valuable for community benchmarking.
— Jessica
Trust but verify. Then renegotiate.