Okta
Octa
User convenience is improved, and the operational burden is reduced.
Key points for implementation
- Business systems that previously required individual authentication can now be used with SSO.
- By consolidating information in Okta, we can achieve centralized management and unified workflows.
- With Okta, modifying authority settings due to personnel changes is easy, eliminating mistakes such as forgetting to delete settings.
OK Co., Ltd.
IT Support Department, IT Headquarters
Infrastructure Group Manager
Akifumi Iizuka
OK Co., Ltd.
IT Support Department, IT Headquarters
Infrastructure Group
Kazuo Takahashi Marcos
OK Co., Ltd.
IT Support Department, IT Headquarters
Infrastructure Group
Hibiki Shindo
The lack of a unified authentication system necessitates separate authentication for each system, resulting in an excessive burden on those responsible for ID management.
OK, a discount supermarket chain operating over 160 stores in Tokyo and three surrounding prefectures, operates under the management principle of "High Quality, Everyday Low Price." They display posters in their stores stating, "If you find any product more expensive than elsewhere, please let us know. We will lower the price." They aim to offer the lowest prices in the region for national brand products. Furthermore, they have been expanding into the Kansai region since 2024, and their OK Club membership has surpassed 7.76 million (as of March 2025), demonstrating steady business growth.
Previously, the company lacked a unified authentication system across the entire organization, requiring separate authentication for each system. This compromised user convenience and placed a significant burden on management. Akinori Iizuka, manager of the Infrastructure Group in the IT Support Department of the IT Headquarters, explains the situation at the time: "We had implemented an enterprise-grade cloud business platform as a common application, and we were using a single sign-on (SSO) product for authentication. However, this system was not used for other systems or services. Therefore, users had to authenticate individually when using each system, and the large number of IDs made managing them a significant burden for those in charge."
The proliferation of authentication systems stemmed from the fact that each system had its own designated person responsible for user management, leading to inconsistencies in operation and a personalization of tasks. Kazuo Takahashi of the Infrastructure Group, IT Support Department, IT Headquarters, recalls, "Not only our own employees but also those from external partner companies were subject to management, and personnel changes occurred frequently, so the operational burden was considerable."
The company considered using existing SSO products, but they lacked the functionality to cover authentication across the entire company. "the Company use a large number of systems and services, and the existing products couldn't cover all of them. Also, because we couldn't track user-specific permissions or license management—that is, who was using which services—ID management had to be done entirely manually," said Iizuka.
Amidst this situation, in response to the COVID-19 pandemic that began in 2020, the company also shifted its operations to remote work. As a result, opportunities to access business systems from outside the company increased dramatically. This led to a recognition of the importance of an IdP (Identity Provider) for securely accessing business systems from outside the company.
"A few years before the COVID-19 pandemic, we commissioned a consulting firm to conduct a security survey in the form of a questionnaire. The diagnosis revealed issues with ID management, and we felt the need to prioritize countermeasures," said Iizuka.
Therefore, the company decided that a system was needed to reduce the workload by automating operations in order to fundamentally solve these problems, and thus began considering its implementation.
In addition to Okta's high profile as an IDaaS, we appreciate its rich security and visualization features.
OK was looking for a system that could securely process authentication in bulk when they learned about Okta, a provider of next-generation authentication infrastructure. "What sealed the deal was that, in addition to being a globally renowned IDaaS, it has a wealth of security and visibility features, and we thought that this would enable us to achieve integrated ID management at the company-wide level," said Iizuka.
Specifically, the features that were evaluated highly included, first and foremost, integration with Active Directory (AD). The company operates its business systems in a hybrid on-premises and cloud environment, and integration with AD was a mandatory requirement. The proof-of-concept (PoC) confirmed that Okta's API made this integration easy. In addition, the ability to automate identity management tasks with Okta's proprietary automation tool, "Okta Workflows," using no-code/low-code methods, was also highly valued for its user lifecycle management capabilities. Furthermore, the inclusion of user-initiated onboarding features was also an attractive security feature.
"At Okta, we send an email notification, and users can access the system simply by setting up a password and multi-factor authentication (MFA). The ability for external members to securely access the system from their own PCs is a significant advantage in terms of improved convenience," says Takahashi.
The company conducted a Proof of Concept (PoC) in November 2023 to confirm integration with Active Directory (AD), among other things. They decided to adopt the solution in January 2024 and began implementation work. Deployment was completed in May 2024.
Business systems can now be used with SSO—leading to centralized management, standardized workflows, automation of tasks, and reduced operational burden.
OK has 1,500 Okta users, including both headquarters employees and staff from external business partners. Policies are customized and applied to each user. Internal users have SSO as standard, allowing them to access the dashboard without entering a password by opening the Okta URL. However, external users, such as those working remotely, are required to use MFA, thus maintaining a secure environment.
Users have not expressed any particular confusion regarding the change in authentication method. The company has always managed all user and password information in Active Directory (AD), and users have been using this system for many years, so they are accustomed to it. Currently, some of this operational methodology remains, but by synchronizing AD information with Okta, authentication in AD is automatically performed in Okta as well, so many users are able to use the system without being aware that the authentication system has changed. Shindo Hibiki of the Infrastructure Group, IT Support Department, IT Headquarters, said, "Even after introducing Okta, we only distributed login procedure manuals and did not conduct any special training, but users seem to be able to access and use the system and services without any confusion. We have received very few inquiries."
Another significant benefit is the reduction in the burden of management and operation.
"Operational efficiency has definitely improved. Previously, user information and permissions were managed individually in each system. With this implementation, the process has changed to granting permissions from the Okta Group, resulting in centralized management and a unified workflow," (Takahashi).
Furthermore, previously, it was necessary to modify permissions for each system in response to personnel changes or retirements. However, by disabling permissions on Okta, all linked systems can be disabled at once, reducing the workload and preventing errors such as forgetting to delete permissions.
"In terms of management improvements, we've integrated Infrastructure as Code (IaC) tools when registering various types of information in Okta, automating tasks such as user grouping and permission granting. In addition, by sharing configuration information across the software development platform, multiple engineers can review whether the settings are correct, and the handover of management has also become easier," said Takahashi.
We will gradually expand the scope of Okta's application and promote operational automation, working to reduce man-hours and minimize errors.

Going forward, OK aims to further improve efficiency by expanding the scope of Okta's application and advancing automation.
"Currently, Okta's system coverage is only about 30%, and we can't say that we're fully utilizing its lifecycle management capabilities. However, this isn't a technical problem; it's because coordination and negotiation with each individual in charge are necessary. In the future, we plan to gradually expand the scope of application and further improve efficiency by automating the process through provisioning," said Takahashi.
Furthermore, the company plans to reduce man-hours and errors by automating manual operations. "We want to actively promote automation in order to realize a secure system environment and improve compliance. In particular, Okta Workflows can be integrated with various applications and services using low-code/no-code, so we would like to utilize it to automate business processes," says Takahashi.
User Profile
| OK Co., Ltd. | |
| location | 6-3-6 Minato Mirai, Nishi-ku, Yokohama City, Kanagawa Prefecture |
| Introduction time | May 2024 |
| URLs | https://ok-corporation.jp |
| Founded in 1958, this discount supermarket chain operates over 160 stores in Tokyo and three surrounding prefectures. With a management philosophy of "High Quality, Everyday Low Price," they carefully select and sell valuable, delicious, fresh, healthy, and convenient products from among high-quality goods. Their business goal is to achieve 20% annual growth without debt, and they began expanding into the Kansai region in 2024. | |
Inquiry/Document request
In charge of Macnica Okta Co., Ltd.
- TEL:045-476-2010
- E-mail:okta@macnica.co.jp
Weekdays: 9:00-17:00