Setting a security baseline that writes your audit trail

Template your Okta configurations, catch drift fast, and hand auditors proof on demand.

Bottom Line Up Front

Every regulated client you support has to keep its identity and access security controls switched on and be able to prove it. Templating your Okta security baseline with ZeroConfig makes that configuration fast and consistent across your whole book. Monitoring for drift shows you what has changed and where. ZeroConfig, ZeroTek Audit, and the Log Viewer together turn "we're compliant" into evidence you can export on demand, no matter what framework or jurisdiction your clients answer to.

Key Takeaways
  • Regulated clients must keep identity and access controls enforced and show proof of compliance. Frameworks from HIPAA to PCI DSS to the FTC Safeguards Rule expect ongoing review and prompt correction, not one-time setup.
  • A templated Okta security baseline deploys a strong, identical configuration across every client in minutes, replacing slow, error-prone manual work.
  • You can tailor the baseline for a specific client and monitor drift against that client-specific standard.
  • Drift monitoring shows exactly which orgs changed and where, turning a 45–60 minute manual review into about two minutes and enabling fast, documented remediation.
  • ZeroConfig, ZeroTek Audit, and the Log Viewer combine into audit evidence you can export on demand, so audit prep is a straightforward and repeatable task.

You stand up each new client's Okta the right way: MFA enforced, strong authenticators, sensible session policies, network zones defined, ThreatInsight—the configuration your best engineers would sign off on. Then the environment starts to live. An engineer makes a one-off change at 2 a.m. during an incident and means to revert it later. A co-managed client's internal admin adjusts a setting without realizing what depends on it. Someone who knew exactly why a policy was written the way it was moves on to another job. None of these is dramatic on its own. But multiply small changes across 30, 80, or 100 tenants over a year, and the careful baselines you deployed no longer do what they should.

For regulated clients—law firms, medical practices, financial advisors, startups chasing SOC 2, schools—that drift isn't just an operational nuisance. It's the gap between the controls they're supposed to have and the controls you can prove they have. And proving it, across every client, on demand, is where a lot of MSPs lose days they never get to bill for.

What regulated clients have to show

Auditors and insurers aren't looking for a single flawless snapshot, and they don't expect settings will never change. They're looking for evidence that your controls are in place, that you review them, and that when something moves out of line you catch it and correct it promptly. Much of what they ask about is identity and access management (IAM): who can reach what, how they authenticate, and how access changes are governed and recorded. Across the frameworks your clients operate under, that same expectation shows up over and over:

  • Healthcare. The HIPAA Security Rule requires covered entities and their business associates to regularly review records of information system activity—audit logs, access reports, incident tracking—under 45 CFR 164.308(a)(1)(ii)(D), backed by audit controls that record and examine activity in systems handling ePHI (164.312(b)).

  • Payments. PCI DSS v4.0 is organized around logging and monitoring all access to cardholder data (Requirement 10), reviewing logs daily, and— newer in v4.0—promptly detecting and rectifying failures in critical security controls (Requirement 10.7). Its "business-as-usual" philosophy is explicitly about proving controls hold throughout the year, not just at assessment time.

  • Financial services. The FTC Safeguards Rule expects institutions to maintain "systems to detect, on an ongoing basis, changes in information systems that may create vulnerabilities" (16 CFR 314.4(d))—one of two accepted routes, and essentially a description of drift detection.

  • Legal. ABA Model Rule 1.6(c) requires lawyers to make "reasonable efforts" to prevent unauthorized access to or disclosure of client information, and Comment [18] frames "reasonable" as an ongoing, risk-based judgment rather than a one-time box to tick.

The specifics differ by framework and by jurisdiction—and that's true whether your clients operate in the US, Canada, or anywhere else. But the through-line is identical: keep the controls enforced, keep an eye on them, fix what drifts, and be able to show your work.

Brutal by hand and monumental at scale

Detecting drift manually means opening a tenant, walking its live configuration against what it's supposed to be, and noting every deviation—groups, authenticators, policies, network zones, and the dozens of small settings that together make up a security posture. For one org with a straightforward setup, that's a careful 45-to-60-minute review. For a book of 30 or 80 clients, repeated on any meaningful cadence, it's a full-time job. The worst-case scenario is that it doesn’t happen at all—until an audit, an incident, or an insurer forces it. And that’s exactly when you least want to discover that three tenants drifted in a consequential way months ago.

The mechanism: a templated security baseline

This is the problem ZeroConfig was built to solve. Okta is powerful and the policy engine intuitive, but configuring it well by hand is still detailed, and for an MSP with multiple clients it’s detailed and repetitive. ZeroConfig lets you define a security baseline once, turning hours of careful setup into minutes. And you don't have to be a seasoned Okta expert to start: ZeroTek provides customizable pre-built ZeroConfig templates drawn from our extensively field-tested MSP best practices, so you can stand up a robust security baseline fast—with our Okta-certified team helping you understand every setting rather than leaving you to decode Okta on your own. (For the mechanics and the deployment economics, see the ZeroConfig platform page and how automated Okta configurations change the economics of MSP deployments.)

Most MSPs use ZeroConfig exactly this way, and the payoff is consistency: every client starts from the same strong foundation, built the way your best people would build it. Element Technologies, an MSP serving 50+ law firms with 3,100+ identities behind 180+ apps, describes the new playbook plainly. "Create the Okta org in ZeroTek, assign the baseline template, run ZeroConfig, go set up the branding—you're done. In under an hour," says Kyle Falany, Site Reliability Engineer at Element. Before ZeroConfig, that same consistency demanded per-client documentation to track every tiny manual discrepancy—one engineer spells a group name with a dash, another with a space. Now the standard is simply the standard, everywhere.

Take it further: client-specific baselines

You don't have to stop at one house standard. Take that baseline, tailor it to a specific client with different needs—additional policies and controls a given regulator or contract requires, for example—and save it as that client's own template. Now you're monitoring drift against the configuration that client is supposed to have. A customized baseline is still a baseline, so everything that follows—detection, remediation, evidence—works identically whether the template is your standard or a bespoke one.

That matters most for co-managed tenants, where a client's own admins have access and can change things. Mantle Group, which delivers Okta to biotech and venture-backed startups, relies on exactly this. "ZeroConfig's ability to centrally build, manage, and modify client-wide secure baselines is critical," says Alex Scheer, Head of Security at Mantle. "As we continuously optimize security in response to evolving threats, ZeroConfig allows us to push needed changes efficiently and transparently."

Drift detection is the ongoing control and the on-demand evidence

Once a baseline is assigned, keeping a client aligned to it stops being a manual audit and becomes a quick check. ZeroConfig compares an org's live configuration against its assigned template and shows you exactly which orgs need attention and where to look. (For how drift happens and how detection works under the hood, see Okta configuration drift for MSPs.)

For Mantle, that check went from a 45-to-60-minute manual review per Okta org to about two minutes. "It's immediately obvious whether changes occurred—and exactly where they were made compared to the assigned configuration," says Nick Thomas, Head of Technology at Mantle. When a deviation turns out to be unwanted, remediation pushes the baseline back and documents what changed, with a clear before-and-after. The result, in Mantle's words, is keeping customers compliant to their agreed security configuration without slowing anyone down.

Read that against the frameworks above and the overlap is exact. Regularly review the state of your controls; catch what's drifted; correct it promptly; keep a record. The template is your control, the drift report is your detection, and the remediation history is your proof that you acted.

The full audit trail: ZeroConfig, ZeroTek Audit, and the Log Viewer

Configuration is one layer of the story. A complete evidence package also answers who did what and what happened inside Okta. ZeroTek gives you both in the same platform.

ZeroTek Audit is a single, searchable record of every create, update, and delete action your team takes across all your customers' Okta orgs: role changes, deep-link sessions, configuration changes—each tied to a named technician, with support-ticket references where your team enters them. It's the "here's how our admins actually operated" layer, and it exports cleanly. The Log Viewer runs live queries against the Okta System Log—user sign-ins, authentication activity, admin actions—scoped to a specific user, group, app, or an entire org, and exports to CSV or PDF. Put simply, ZeroTek Audit consolidates what your team does in ZeroTek; the Log Viewer consolidates what happens in Okta. Both are built to make troubleshooting and evidence-gathering fast.

Together with ZeroConfig's baseline and drift records, those two features are the evidence auditors ask for. When New England Network Solutions (NENS) prepared for its own SOC 2 Type II audit, that's essentially the package they assembled: the Okta policies that define the rules, admin-activity logs from ZeroTek Audit showing how their team operated under those rules over time, and the per-app integration settings that tie it all together—the rules, the proof of how admins worked within them, and how each app connects to centralized identity. When one of their clients faced a bank's audit, proving MFA enforcement and access policies came down to exporting the relevant Okta policies, rather than pulling data from every application by hand. (We cover that evidence workflow in depth in choosing an IT service provider for compliance audit success.)

From maintenance burden to service line

There's a business story sitting on top of the security one. The work of keeping clients aligned and audit-ready—which for some MSPs might have been an unbudgeted scramble—becomes a defined, repeatable service you can put your name on: continuous monitoring of identity and access controls, a quarterly configuration review, an annual evidence package. It scales, because the review that took the better part of an hour per client now takes about two minutes, and the evidence exports in a click. And it's a real differentiator: when a prospect's incumbent MSP needs a week to assemble proof and you demonstrate you can produce what they need in minutes, you've shown a regulated organization exactly why it should work with you. It's the same foundation that makes cyber-insurance renewals painless and anchors a broader compliance practice.

You already have the receipts

For a regulated client, compliance demands a set of continually operating controls, and a story they have to be able to tell on demand. A templated security baseline keeps those controls consistent from day one; drift monitoring keeps them honest; and ZeroConfig, ZeroTek Audit, and the Log Viewer turn the whole thing into evidence you can hand over whenever someone asks. That's how "we're compliant" stops being an assertion and becomes a record.

See how ZeroConfig and ZeroTek's audit tooling fit your stack and your clients. Book a 30-minute walkthrough with one of our Okta-certified team members. No salespeople.

See ZeroTek in Action

See how the platform works for your specific use cases

No slides. No script. Our team will walk you through the platform on a 30-minute call and answer any questions you have about your specific use cases.

Talk to our team →
Featured Case Study
Element Technologies
Managed Service Provider · 50+ Okta orgs managed
Challenge

Element needed a repeatable way to deploy a consistent Okta baseline across dozens of clients without manual checklists.

Outcome

ZeroTek centralized management across clients. ZeroConfig standardized their baseline and cut tenant setup from hours to minutes.

3.5x
Faster to setup a new client
30%
YoY increase in managed users
See It Live

See how 100+ MSPs are building
high-margin identity practices

A 30-minute demo will show you exactly how ZeroTek fits your stack, your team, and your client base. No pressure. No prep required.