Executive summary
Boston Tech Advisors (BTA), under the leadership of veteran IT executive Benjamin Katz, provides fractional CIO leadership together with hands-on technical execution. The firm is dedicated to simplifying, automating, and securing mid-market IT environments, enabling internal teams to operate them with confidence and efficiency.
Identity security is essential, and BTA needs it to be reliable, fast, and scalable. ZeroTek turned Okta’s industry-leading identity and access management (IAM) platform into a repeatable operating model that delivers strong baseline configurations, highly automated management, and hardened identity security for every client. The result: efficient rollouts, fewer tickets, and very satisfied customers.
“ZeroTek’s licensing model makes Okta very, very accessible for my clients.”
– Benjamin Katz, CTO
Boston Tech Advisors
Customer profile:
mid-market, 200–500 employees
Boston Tech Advisors serves mid-market organizations (200–500 employees) with lean IT teams that are operationally strong but need help designing and executing a modernization program.
Some clients come to BTA with Okta in place but underused. For new and existing Okta deployments alike, BTA uses ZeroTek’s field-tested best practices to optimize security configurations, enforce strong MFA, and automate user management with Okta Lifecycle Management (LCM) to accelerate onboarding, access, and offboarding.
A representative client (Boston area, ~500 users) before BTA got to work:
- Windows fleet: 150+ laptops bound to on-prem AD; 30+ unmanaged Macs
- Legacy core: On-prem Exchange and Active Directory
- Identity: Okta Classic Engine (licensed directly) used only for SSO, not yet updated to Okta Identity Engine (OIE), no MFA
- Provisioning: Manual, error-prone account setup and management across ~60 SaaS apps
Resulting issues, identified by Katz:
- Slow onboarding
- Inconsistent access
- License sprawl
- Weak offboarding hygiene
- Broad attack surface tied to legacy on-prem AD/Exchange

Modernizing security with ZeroTek | Okta
First things first: Katz got the client onto Microsoft Office 365 (M365) and retired on-prem Exchange. Then he solved the remaining business problems with ZeroTek | Okta as the IAM core of his tech stack.
Okta gives customer IT operations the right foundation: industry-leading identity and access security, easy directory and app integrations, and automated lifecycle management.
ZeroTek makes delivery of Okta easy with:
- Consumption-based licensing and billing. “ZeroTek’s licensing model makes Okta very, very accessible for my clients,” says Katz.
- Expert partner support, onboarding, and repeatable best practices. ZeroTek’s field-tested best practices, deployment blueprints, online resources, and Okta-certified technical support ensure robust, secure deployments every time.
- Simplified management of multiple Okta tenants through a single secure dashboard.
“With Okta, everything is easier and better instantly, as soon as you roll it out—for the techs, for the end users.
Nobody ever wants to go back to how things were.”
How Boston Tech Advisors modernized and simplified IT with ZeroTek | Okta
Working with ZeroTek’s Okta Certified Consultants and leveraging ZeroTek best practices for Okta wherever possible, here’s how BTA addressed the client’s IT problems.
1 – Optimized the Okta configuration and consolidated directories
- Upgraded the client’s Okta Classic to OIE, then secured Okta with policies that leverage passwordless MFA, geofencing, and threat detection.
- Consolidated on-prem AD under Okta to weed out orphaned and duplicate accounts, reduce Microsoft licensing costs, and simplify management.
- Integrated M365 with Okta to deliver easy, secure SSO access to the apps people use every day.
- Standardized Okta group-based access to SaaS apps and automated provisioning through SCIM wherever supported.
- Established birthright apps for all employees, then layered access for departments and teams via Okta groups.
2 – Automated device provisioning and patching
- Established a new system so that new hires log into a new device with their Okta password; the device builds itself and the apps they need arrive automatically.
- Windows: Microsoft Intune + Autopilot for zero touch builds; Action1 for patching.
- Mac: Kandji for zero-touch builds and patching.
3 – Closed the lifecycle loop
- Established routine HR sync: The team uses an HR CSV file daily to update Okta, which then pushes job title and manager attributes into M365. “It might sound trivial, but with hundreds of employees, it truly makes a difference that changes to job title or manager are reflected quickly and accurately in M365,” says Katz.
- Configured contractor close-out: Daily Okta inactivity emails; if they do not authenticate with Okta before the deadline, they are automatically deactivated and all access cut off.
- Created an Okta-Slack integration to notify of rogue, unintegrated apps: Slack notifies all client Admins for all user creation/deactivation events to prompt app owners until all systems sit behind Okta.
- Integrated SentinelOne: Suspicious activity can trigger rapid account deactivation in Okta.
4 – Shrunk attack surface by reducing AD reliance
- Reduced AD reliance to only a handful of AD-dependent legacy systems.
- Gated access for a small group of users, strongly secured with AD-specific Okta policies.
- Created plan for decommissioning AD and eliminating server costs once required legacy systems sunset.
5 – Initiated second phase
- Leveling-up passwordless authentication with full implementation of Okta FastPass.
- Tightening up device trust on sensitive apps using certificates/Intune signals and FastPass posture checks.
- Automating HR CSV updates to sync employee attributes, additions and terminations nightly to keep both Okta and M365 current.

Katz says the key to a successful transformation is securing commitment and buy-in from both management and the IT team.
Outcomes: faster onboarding,
stronger security, lower costs, data accuracy
By deploying Okta through ZeroTek, BTA transformed IT for its client:
- Faster user onboarding: From days to minutes; devices build themselves and apps arrive automatically.
- Stronger security: Phishing-resistant, passwordless MFA, automated offboarding, reduced AD footprint, contractor auto-cleanup.
- Lower costs: Flexible consumption-based Okta licensing + rightsized SaaS entitlements.
- Data accuracy: HR-sourced titles and managers flow into M365 for a clean org chart, faster workflows and approvals.
- Empowered internal team: BTA leaves a clean, automated identity core the in-house team can run.
By deploying Okta through ZeroTek, BTA transformed IT for its client:
- Faster user onboarding: From days to minutes; devices build themselves and apps arrive automatically.
- Stronger security: Phishing-resistant, passwordless MFA, automated offboarding, reduced AD footprint, contractor auto-cleanup.
- Lower costs: Flexible consumption-based Okta licensing + rightsized SaaS entitlements.
- Data accuracy: HR-sourced titles and managers flow into M365 for a clean org chart, faster workflows and approvals.
- Empowered internal team: BTA leaves a clean, automated identity core the in-house team can run.
“With Okta, everything is easier and better instantly, as soon as you roll it out—for the techs, for the end users,” observes Katz. “Nobody ever wants to go back to how things were.”
Katz says the key to a successful transformation is securing commitment and buy-in from both management and the IT team. With this client, the existing IT staff were eager to participate and played a central role in the outcome, involved in every step of the process including technical calls with ZeroTek. Okta is now in steady hands with the internal team, and Katz views this project as much their success as it is BTA’s.
“ZeroTek’s technical support consistently provides the best professional services and support I’ve experienced in my 30 years in IT.
They’re like no other vendor I’ve worked with.”
The ZeroTek experience
For Katz, a defining aspect of the ZeroTek experience is the partnership quality.
“ZeroTek’s technical support consistently provides the best professional services and support I’ve experienced in my 30 years in IT. The team really took the time to understand my goals and then accelerated the process of reaching them. They’re like no other vendor I’ve worked with.”
For Katz, a defining aspect of the ZeroTek experience is the partnership quality.
“ZeroTek’s technical support consistently provides the best professional services and support I’ve experienced in my 30 years in IT. The team really took the time to understand my goals and then accelerated the process of reaching them. They’re like no other vendor I’ve worked with.”
What stood out:
- Diligent and safe execution. Changes were staged to avoid lockouts and user disruption.
- Responsive collaboration. BTA and ZeroTek moved the work forward in focused, two-hour working sessions with clear objectives.
- Documentation and repeatability. Katz adopted ZeroTek’s patterns for naming, grouping, and app onboarding to keep orgs consistent and streamline management for himself and his clients. Reference documentation has been “absolutely excellent”.
“ZeroTek | Okta align perfectly with our whole approach, which is to move rapidly toward everything being passwordless, and to use the industry’s best tools to do it.”
Looking ahead: passwordless by default
The future for Boston Tech Advisors undoubtedly involves protecting an ever-growing roster of clients with Okta. As Katz puts it:
“I’ve got a new client, staff of about 70, rapid growth, and the VP of Engineering knew they wanted Okta. And because I’ve partnered with ZeroTek, I was able to say to him, ‘Sure, I can turn that on for you tomorrow.’ That’s what ZeroTek makes possible. ZeroTek | Okta align perfectly with our whole approach, which is to move rapidly toward everything being passwordless, and to use the industry’s best tools to do it.”
Bottom line: together, ZeroTek | Okta give Boston Tech Advisors—and their clients—a clear, dependable path to a passwordless-by-default future.

“Because I’ve partnered with ZeroTek, I can say, ‘Sure, I can turn on Okta for you tomorrow.’ That’s what ZeroTek makes possible.”
Why technical leaders choose Boston Tech Advisors
Boston Tech Advisors brings CIO-level judgment with hands-on engineering experience to help mid-sized businesses modernize and stabilize their IT and level-up security. Clients can either run the updated systems themselves or have BTA provide ongoing services. Either path starts with the same foundation: industry-leading Okta to protect digital identities and access, automate the lifecycle, and simplify management—then integrate Okta with whatever tools are needed to tailor the solution to each client’s exact requirements.
Their choice of Okta reflects how BTA works: they seek out high-caliber technologies, vet them carefully, and only deploy what delivers the best outcomes. That discipline, paired with a knack for elegant, practical engineering, lets BTA craft innovative, highly effective solutions for all their clients.
Boston Tech Advisors brings CIO-level judgment with hands-on engineering experience to help mid-sized businesses modernize and stabilize their IT and level-up security. Clients can either run the updated systems themselves or have BTA provide ongoing services. Either path starts with the same foundation: industry-leading Okta to protect digital identities and access, automate the lifecycle, and simplify management—then integrate Okta with whatever tools are needed to tailor the solution to each client’s exact requirements.
Their choice of Okta reflects how BTA works: they seek out high-caliber technologies, vet them carefully, and only deploy what delivers the best outcomes. That discipline, paired with a knack for elegant, practical engineering, lets BTA craft innovative, highly effective solutions for all their clients.
Boston Tech Advisors on ZeroTek | Okta
600+
Passwordless Okta Verify users
65+
SaaS apps behind Okta
6+
Hours saved on every onboarding
50+
Inactive accounts removed through automation
Are you ready?
Ready to explore how ZeroTek | Okta can help your MSP deliver next-level security services to your customers?
