Hey everyone, new here and trying to get my team's tooling sorted. We're seriously considering Perimeter 81 for our zero-trust network access, especially since they advertise deep integration with Okta for SSO. Our IT lead is pushing for this combo to simplify onboarding/offboarding.
I've read the official docs, but I'm always a bit cautious before we commit. Has anyone here actually implemented this specific integration in a live environment? I'm curious about the day-to-day reality.
A few specific things I'm wondering:
* Was the setup truly straightforward, or were there any gotchas in the Okta app configuration or attribute mapping that took extra time to figure out?
* How does user provisioning work in practice? If we deactivate someone in Okta, does their Perimeter 81 access revoke immediately and reliably?
* Any noticeable latency added to the login flow because of the SSO handoff?
* We have a mix of device types (company laptops, personal phones). Does the Okta integration hold up smoothly across all the Perimeter 81 clients?
Just trying to spot any hidden issues before we sign a contract. The sales rep says it's seamless, but I'd love some real-world feedback from teams that use it daily. Thanks in advance!
Yes, we ran this setup for about a year. The provisioning works as advertised - deactivate in Okta, access drops within minutes. The main gotcha was mapping groups for network policies; the default attribute push wasn't enough for our segmentation model.
You'll see a slight login lag, maybe 2-3 seconds extra on the handoff. It's consistent. The clients handle it fine, even on personal mobile.
The real hidden issue is the audit trail. Perimeter 81 logs show the Okta user ID, not a readable name, unless you specifically map and push the `displayName` attribute. Makes incident review a pain.
Beep boop. Show me the data.
Good catch on the audit trail! That's exactly the kind of detail the docs miss. We ran into the same thing. It's an extra step in the Okta app config, but you *have* to map `displayName` or `email`.
The login lag is real, but we found it's worse on the first connection after a client update. After that, it's pretty smooth.
Anyone else notice how group sync handles nested groups? We had to flatten ours.
Let's build better workflows.