Hey everyone. Thanks for tuning in to day two of Oktane. I hope you all enjoyed yesterday's inside look at the last year of life at Okta. It's definitely a new take on the keynote format and a chance to hear straight from the people building Okta every day. The story of innovation really begins with Okta's platform. Our platform is the foundation to build incredible new products and features, while also making those identity capabilities more accessible to everyone in your organizations. Okta's platform approach is core to how we think about identity, but it's also a recognition of the role identity plays in your organizations. All of you want choice in the technology you adopt. It's what enables your organizations to be nimble. It's what keeps your employees happy and productive, and it's what drives your customer experiences forward.
It's also what gives you the ability to adapt to whatever changes come your way. In a cloud-centric world, identity has become a true primary cloud, just as important as your other primary clouds, like your infrastructure or your collaboration clouds. It's also the secure epicenter of your organization's tech connections. Without security and identity independence, there is no technology choice. Across your organization, that need for technology freedom could not be greater, because today, identity is top of mind from the boardroom to your spare bedroom, reaching people across every business team. Whether it's security, IT admins, business units, DevOps, or developers, everyone can use the Okta platform to drive business goals. Yesterday, we talked about the Okta Identity Engine, one of our key platform services. It's going to bring all kinds of customization to the access experiences you're building.
Along with our other platform services, it makes identity customizable and extensible. For us, creating the best workforce or customer identity platform means offering you a range of options, from out-of-the-box configurable solutions to raw APIs and SDKs, so that you can build for any use case you dream up. We think every step of the journey should be programmable, with a ton of documentation to make auth easy for everyone. That customizability is an especially big deal for customer identity, making it possible for you to deliver on each of the diverse identity use cases your customers need. The potential for customer identity is massive for every organization today. Everyone is moving their business online, and with that push comes the need to not only deliver safe and secure experiences, but to create meaningful ones for your customers.
It also means opening up more of our platform to devs for free and allowing you to do some new things with the Okta Integration Network so that you can automate how identity impacts security and customer experiences. Our product leaders are really excited to talk you through some of the things we're announcing to bring more choice and access for the teams building cutting-edge digital products. What you're probably really excited about is the announcement we made just over a month ago, our plan to join forces with Auth0. The feedback has blown me away. Not only do we share the same vision, our values and how we operate are tightly aligned. We have the same worldview when it comes to the role identity plays in powering the internet.
Each company has its own strengths and expertise, and coming together will give customers more choice to meet every identity need. We are going to maintain and invest in both platforms, and in the background, we'll be integrating our technologies over time to provide even more innovation. Ultimately, the identity challenges all of you face are unique. Each of you have different teams building the experiences that propel your organizations and people forward. We're committed to meeting you where you are and helping all of you find the solution that best addresses your identity use cases. We have a ton of exciting stuff to share with you today, but first, I wanted you to meet Auth0's CEO and Co-Founder, Eugenio Pace. He's joining Okta and will remain the CEO of Auth0, reporting to me. Welcome, Eugenio.
Thank you, Todd. It's great to be here.
It's great to have you.
Yeah. Thank you.
This is all about identity, two companies coming together t o build a great solution for customers all around identity. Why is identity important now for companies? What have you seen in terms of how identity applies to different companies, different organizations?
Well, if anything, 2020 has shown us that everything is digital. Everything. Education, our healthcare, our entertainment, everything, it's technology surrounding us. There's one thing that they have in common is that they all need to know who we are. The opportunity is massive. I see that we have a lot of work to do still, and by working together now, we can bring that future that we imagined fast-forward to the present. Instead of waiting five years, we can do it in two years.
That's a good point. One of the most exciting things for me about identity is how horizontal the opportunity is. As you look inside your customers, what do you see about how identity applies to different roles and responsibilities inside the company?
It really doesn't matter how you slice and dice this thing. It applies to everything. It's every country, every region, every customer segment, whether in media or entertainment or manufacturing. Inside a company, whether you're a developer building applications, whether you're a designer or you're a product manager or you're on the board or you're an executive, identity is pervasive. It's universal. It needs to be acknowledged in all, in everything.
Yeah, it's a great point about how identity applies to really every role inside of a company. We've known each other for a while, about seven years?
Eight.
Eight years, yeah. Time flies. I've admired Auth0 and watched you guys grow. Tell us about, from your perspective, what Auth0 stands for.
Well, the admiration is mutual. I've seen you grow as well and grow your company. In many ways you've been an example that we look up to. Above everything, Auth0, it's about empowering developers. It's about empowering everybody building applications in the world to make it a better world. If you're a builder, if you're creating apps, that's us.
What you guys have done building a product and a community and a brand around developers is truly impressive. Nice work on that.
Thank you.
Looking forward, what excites you most about the innovation we can build together?
Well, what is exciting first and above everything is that we both have the same opinion of the future. We have the same convictions about what's possible, and we can bring that what's possible today. We can do it faster. We can do it more in a global scale, in a ways that it would have taken us a longer time to realize. That's exciting.
Fast-forward the future.
Yes.
Speaking of the future, the future is all about developers, and you guys have done an amazing job building this evangelical base of developers. Tell us the secrets to that success. What have you done to make that happen?
Yeah. We founded the company with this belief that every company in the planet is a software company, even though they might not call themselves a software company. If you're a software company, you need software developers. Therefore, every company in the planet needs software developers. Guess what? There's not enough of them. Anything that would make their life easier and simpler and would allow them to build faster, better, more secure applications would be valuable. That was the hypothesis. That's how we built Auth0.
Everything from the first contact, from searching on your favorite search engine for a problem, finding a content that will explain how to solve that problem, all the way to tinkering and trying things out, which is how developers like to operate, all the way to actually committing to a contract with us. The entire journey is optimized. We design it with that in mind, from first contact to long-term commitment. That shows in the API design, in the documentation, in the content, in enabling everybody to become an expert without having to be an expert on this domain.
Eugenio, what you and the team have accomplished is truly impressive, and I can't wait to work with you on building the future of identity. Thank you very much.
Thank you. Looking forward to it.
As Eugenio and I were saying, we're continuing to push new customer identity technologies and capabilities across both of our platforms. That's because we're never going to stop innovating, and some of the things we're announcing on the developer experience side really highlight how we're making it happen. Now I'll turn it over to Ryan, Diya, and the rest of the team to share a bit more.
Thank you, Todd, and thank you all for being here. I'm really excited to hear from key product leaders in the company about all the innovation in our products, to see that innovation in action through the form of demos. We're going to start by talking with two key leaders in our product organization, Okta's Chief Product Officer, Diya Jolly, and our Director of Developer Relations, Emeka Afigbo. Welcome to you both.
Thanks, Ryan.
Thank you.
Diya, let's start with you. Everybody talks about digital transformation. Obviously, developers are at the center of that, but their needs have changed over the years, specifically enterprise. Tell us how that has happened over the years.
Yeah, of course. Today, software has become an integral part of any organization. Any organization, no matter what they're selling, needs to be able to connect with their consumers digitally to be able to remain relevant and thrive. Developers have obviously become a critical resource in companies, and they're scarce. Developers are the ones that are building new applications, new experiences, as well as moving forward innovation in organizations. While doing all of this, they need to ensure that the technology that they're building is also secure. This is a lot to ask of them. New business requirements, new attack vectors, new technological innovations that they need to keep on top of and implement.
As a result, developers are always looking for tools that make their lives easier, that help them get their projects up and running faster, that help them provide rich documentation and support when they inevitably run into trouble, and that are future-proof from a requirements perspective. This is what has really fueled the intense industry focus on developer frameworks, on CI/CD automation, on microservices that developers can use within their apps, and more. The essence really is that developers just need tools that can work across their tool chains, whether they're working in a hybrid-cloud or multi-cloud environment.
Certainly sounds challenging, and it's probably only accelerating. If that's the case, what's Okta's vision to make these developers successful?
That's a great question, Ryan. Our vision is not just to provide a world-class set of authentication and authorization services for developers. It's to actually help them also secure the applications they are building, secure their APIs, and secure their infrastructure. The goal of the Okta Identity Platform is to provide a unified platform that reduces the burden on developers to actually be able to build their apps, to be able to use the services and APIs that they need to get up and running, to be able to test their apps and deploy their apps into production.
Now developers can get up and running faster than they could before, and they can focus on moving forward their business requirements. This is why we're reimagining the Okta Developer Platform and the Okta Developer Experience to speed up time to production across the application development life cycle and also across the entire developer tool chain.
That's certainly a compelling vision. Emeka, I want to come to you. You've been a developer for a long time. As a developer yourself, what's your view on how Okta is solving these problems?
Thank you, Ryan. First of all, I'm excited to say that we announced our enhanced developer edition, and this exposes a greater surface area of the Okta Identity Platform through an expanded free 15,000 monthly active user tier. What this means is that whether you're a developer building a simple application or a complex application, you can now begin to design, build, and deploy all sorts of awesome digital experiences. Secondly, we're announcing a bunch of great integrations into app platforms like Heroku and API gateways like Kong. What this means for you as a developer is that you can directly integrate Okta into your application stack.
We're also releasing some new open-source tooling sample code documentation that enables developers to really get up to speed in building the applications without needing to know all the nuances of identity before you can become productive with our platform. Thirdly, we are also excited to announce that we've enhanced our developer community with experts in different programming environments. As a developer, this means that you can then quickly and easily find answers to your questions when you need help and get active help right in the moment when you need it.
That's amazing. A new 15,000 monthly active user tier that's free, integrations with Heroku and Kong, better documentation, and an enhanced community. Is that right?
Yes.
That's amazing.
Spot on.
I'm sure people are going to be asking, when is it available, and where can developers find this information?
Oh, yeah. It's available right now as we speak. All the open-source integrations that we're launching, the sample apps, the documentation, everything, and the new Developer Edition is available at developers.okta.com right now. You can literally, as a developer, sign up and start building and deploying your awesome digital experiences. As we continue to innovate on our Identity Platform, you're going to be seeing more features and functionality available in the Developer Edition.
I love it. Well, Emeka, Diya, thank you. I want to actually now throw it over to the demo team so you can see some of the things that Emeka talked about in action. Demo team, take it away.
Hey, everyone. I'm Danielle, a Product Manager here at Atco Foods, a global grocery company. We recently decided to launch a new direct-to-consumer brand with a snack delivery service called MunchBox. The launch is ambitious. We want a MunchBox on every single sofa, so we need to get a new app with a great registration and login experience spun up right away. I've asked my Lead Developer, Micah, to get going on the prototype.
Thanks, Danielle. I know intimately that it usually takes months to get something like this developed and into production, and it figures that Danielle lays this on me after she assigned me, no joke, five other projects this morning. It's high visibility, and I want the visibility. All right. I know this is going to be a big effort, and I know the app will need authentication and authorization. I've heard good things about Okta, let's take a look at what they offer. Looks like a free Okta developer account supports a lot of users and seems to handle a lot of the hard things about building auth. It looks pretty simple to sign up and get started with GitHub or Google, I'll use this for my prototype.
Hey, Micah. Hate to be the bearer of bad news, but our execs just moved up our timeline by one month, and they want to see a prototype next week. Any ideas?
What? That's crazy. I need to rethink my whole approach to fit these new timelines. Let me grab Brian from our DevOps team and see the best way to model this out and get it into production. Brian, we have this crazy deadline. We've just had another project dropped in our lap. If I have an end-to-end app, will you be able to deploy it to production? It's going to need authorization and authentication, and Okta seems to be a great fit. Will that work for our production environment?
Hey, Micah. As long as the app is easy to containerize, then we should be good to go. Using Okta is a no-brainer. We already use it internally for SSO and even to manage access to AWS. Don't worry about it. When it's ready to go to production, I'll take care of it.
Great. Thanks, Brian. It's great to hear that I can use my developer tools to speed up the prototype and know that it will easily translate to our production environment. I'll use JHipster, an application generator, to create a React front end and a Spring Boot back end. I'll deploy the application with Heroku, an application hosting service, and I'll use the Okta add-on to provision and configure an Okta instance on the fly as the authentication service. First, I'll prototype an app with JHipster and set some of the configuration here. I'm choosing Okta as the authentication provider, so I don't have to build auth myself. All right. The JHipster app is done. Second, let me deploy this to Heroku.
I know I can create an Okta org right from the command line, and the Heroku add-on is doing some basic Okta setup for me, including an admin user and password. This makes it so I don't have to leave the terminal at all. It's automatically going to create an Okta developer org and assign an API token for easy integration with MunchBox. It will also create a single-page app in Okta for MunchBox with all the OAuth config filled in. While that's running, let me take a look at Okta's documentation.
There's a sign-in widget here that seems to handle all of the core flows around signing in, so I don't have to build registration, login, and email validation flows for our customers by myself. That will save me a few days work. That's all done. Now my skeleton application is created, and I'm going to log in as the admin, and I can see that I'm all set. This was great. I didn't need to spend any time implementing login and registration, which means I can focus on building out the different MunchBox pages. All done. Now I'll send it off to Danielle.
Micah, this is great. Look at all of these snacks. I know you're happy that it looks like you spent 100 hours of time on this versus the 10 you actually did because you used Okta. Our execs loved the prototype. They told me at lunch, and they said to ship it. I'm going to ask Brian how soon he can get this app deployed to production.
Okay. Now I'm going to take the app that Micah built and deploy it to Amazon's Kubernetes service using Terraform, an open-source tool that creates and manages infrastructure from config files. The JHipster build already created the container, so all that was left for me to do was to update our Terraform config to include Okta. Don't tell him, but while Micah was spending all that time on the business logic for the new MunchBox application, it only took me about 10 minutes to update the Terraform config to include the Okta Terraform provider. To get the deployment started, I'll just run Terraform apply.
We use the Okta Terraform provider to configure the MunchBox Okta production tenant with a new OAuth application and the related resources, the deployment of the app to EKS, the creation of application health checks, the setup of load balancers, and finally, the DNS entries needed for the MunchBox domain. Cool. It looks like Terraform is finished. It only took about two minutes to deploy the app and all its dependencies. That's much faster than it used to take just to get access to the Kubernetes cluster. Danielle, you're all set. The new application has been deployed.
Let's take a look. The MunchBox app is live, and the registration page looks great. Okta's developer experience made that entire process go way faster than any identity project I've ever worked on, which is going to make me look great in front of our exec team. I suppose the team did a stellar job taking this from idea to prototype to production really fast. Kind of makes me feel like we can do anything. Like we really are making the world a better place through more efficient snacking. Hey, Micah, can you jump on those other five projects that I assigned you in the next hour or so?
Thanks, demo team. That was great. MunchBox is certainly a great idea because I know that snacks as a service is a giant market. I wish you all a lot of luck. We're going to continue the conversation here around customer identity, but we're going to add a new voice to the mix. I'm pleased to introduce to the panel Maureen Little, our Vice President of Strategic Alliances. Welcome, Maureen.
Hey, Ryan.
Diya, I actually want to start with you. You can't talk about developers without talking about customer identity, and that landscape has changed a lot. From your perspective, how has it evolved most recently?
That's a great question, Ryan. In the last year, the digital economy has fast-forwarded by nearly five to seven years. Today, every organization, as we discussed, needs to have digital touchpoints with its customers and customer experiences for their customers to be able to interact with. Now, in doing so, they need to be able to bring online and offline experiences together. They need to be able to stitch together experiences across multiple products and across their partner ecosystem. All of this is extremely complicated, and it's hard, but it's also extremely valuable because this is the only way to provide a compelling experience for their end customers.
That's super interesting. Talk more about that complexity. I want to hear more about that.
You can think of the complexity along three different vectors. First, the number of tools and technologies that developers have to use is increasing exponentially for them to be able to bring a customer experience to life. Every day there are new attacks and attack vectors, and developers have to think about them and keep their application secure. Third, the amount of customer data and information these organizations have to deal with is increasing exponentially, and developers have to build their applications in a way such that they adhere to the compliance and privacy regulations of every region. If you think about it, building an application and a customer experience now has become much more complicated than it was ever before.
That certainly does sound complex. Okta's ecosystem, I think, plays a role in helping solve that complexity, doesn't it?
Yes, it does. When you think about this, Okta has integrated with all the partners there are across the customer experience tech stack. However, over the last six months, we've actually deepened our integration with four key categories. The first one is the tools and technologies that developers use to build and maintain their apps so that we can actually help them get to market faster. The second are tools that help assess risk and prevent against fraud, so that developers can keep their application secure. Third are downstream systems where customer information needs to flow, like CRM and marketing systems. Fourth are tools that developers use to ensure compliance against regional privacy regulations.
Now, Okta wants to serve every developer and every customer, so we're adopting a best of breed approach so that you can pick the right tools and technologies for your business, for your app, and for your organization. In addition, we're taking this a step further. We're also ensuring that we have multiple integration patterns, whether that's low code, no code, or pro code, so that any team that touches customer identity, whether it's developers, security, marketing, product development, can actually use the tools that are the most effective for them.
Thanks for that detailed explanation. Emeka, I want to come to you. As a long-time developer yourself, what Diya just talked about, how is that going to help developers' lives and make it easier for them?
It's actually quite exciting, Ryan. What this means is that as a developer, you can take things like custom scripting and setting up integrations away from your already considerable to-do list, right?
Right.
It also means that as a developer, you no longer need to worry about setting up and maintaining different integrations and deployments because this can now be offloaded onto non-technical teams or less technical teams. An example of this is that if the business decides that they want to change the way identity flows into, say, a CRM application, this can be handled by either an identity team or an operations team, depending on what makes the most business sense, which then leaves the developer to focus on what we think is most important, and that is creating a great customer experience.
Wow, that's super clear. Thanks. Time to bring Maureen into the mix. Maureen, you work with a ton of our partners. I want to talk about fraud detection and risk signaling, specifically from the integration standpoint. I'd love to get your take on that.
When you think about it, Ryan, organizations have to gain consumer trust no matter what application that consumer comes in, no matter what device. What they need is to be able to assess the risk coming in from that application. The first thing that we decided to do was figure out, is that person actually human? Because you want to take that insight and intelligently allow the good consumers who are actually trying to consume content or buy something through and block the bad guys. The first step is figure out if they're human.
Okta has partnered with the leaders globally in bot detection and web application firewall, companies like Fastly, White Ops, F5, PerimeterX, and we're going to expand very, very soon into other kind of risk areas, behavioral data, transactional risk. Our main goal here is we want it to be easy when someone is licensing and using Okta to assess that risk and make that consumer experience seamless.
Those integrations make a ton of sense for security and for risk and for fraud. What about the customer experience? I know we have some new customer identity workflow integrations in that area as well. Is that right?
Yeah. Actually, we started first thinking about social login. Consumers already have their social login. We've expanded access via social logins from our existing ones of Apple, Facebook, and Google to extend and add more companies that these consumers already use, Amazon, GitHub, and others. We're even expanding internationally into international partners like LINE and WeChat. It's more than that. The Okta Integration Network is this amazing catalog of tools, and we're expanding into new categories like e-commerce, marketing technology, and data providers, and just really trying to make that search experience as they're discovering the tools they need access to way easier. Finally, we're using Workflows because in that real-time consumer experience, they already use big orchestration and e-commerce platforms, and we're going to use Workflows to take that data into downstream systems they already use, like SendGrid, Mixpanel, and HubSpot.
Makes a ton of sense. Integrations for security, integrations for a better customer experience, more integrations, more value. Thanks, Maureen. Diya, I want to come to you. Everything that we heard about, I'm sure people want to know when they can get ac cess to it. I know you have the answer.
The new integrations for customer identity are available in a new catalog on our Okta Integration Network. They're available right now for you to use and browse at okta.com/integrations. Ingesting risk signals is also available from our partners. It's in early access and available to our customers that use our adaptive multifactor authentication. The new workflows for customer identity is available as an add-on SKU. The integrations that Maureen talked about with Mixpanel, SendGrid, and HubSpot are available as workflow connectors.
Exciting stuff. Thanks, Diya. Also, thanks, Emeka. Thanks, Maureen. Really appreciate it. Let's turn it back over to the team at MunchBox to see a lot of what you just heard about in action. Demo team.
Hi, Danielle.
Hi again, Micah. Aren't you happy to hear from me? I was chatting with our execs over lunch, and now that they see that we can work so quickly, they want more, and we've got more work to do. First, they want the coolest e-commerce storefront out there. I'm sure you remember that our goal is a MunchBox on every single sofa, and they want proof it's the coolest, so we need to connect our analytics system to the registration and login experience to prove people are moving through smoothly. In other words, another low-key project for you. Are you up for it?
Wow, Danielle, so great to see you. This is a long list of complex requirements, and I can't imagine my team is going to be able to release this in any reasonable amount of time. I guess I got to go learn the HubSpot APIs and how they all work.
Don't you remember the last time? Use Okta, and this should take you much less time than it normally would. Especially with their new Okta Workflows for Customer Identity product. I've heard it'll help you set up these integrations without having to read all of those API docs.
Let's see. To make sure our customers have a smooth experience, we need to get their profile information into our CRM system, HubSpot. Okta does have a pre-built connector in Workflows for HubSpot. Looks like they've already done the hard work on understanding HubSpot's API, so I don't have to write any custom scripts or manage API tokens. I can just use the Create Contact action as part of a new snacker registration workflow or the Create Company action for our corporate clients. Now, I don't have to learn the HubSpot API.
That is super exciting, Micah. Super exciting. I was on a casual lunch with our CMO, who is also super excited, and he said that user registration and sign-ins are key KPIs to make sure we're converting customers and driving customer delight. I honestly think that driving customer delight is just so important these days, don't you? I want to make sure Okta is integrated with our analytics solution, Mixpanel, so we're capturing it all properly.
True to form, looks like Okta has a connector for that too. Again, I don't need to spend time reading Mixpanel's API documentation, and I can just use the Create Profile action to pass over the registration information that our execs are interested in. I've created a simple automated flow so that when new snackers register for MunchBox, we create their profiles within Mixpanel and HubSpot CRM. This ensures that customer records in those systems are always up to date and are in sync. Again, Okta's taken away a lot of the custom coding work I usually have to do when building integrations, and it looks like I won't have to do any integration maintenance as Okta just handles that for me. All right. Now I'm going to go munch on some snacks.
Oh, wow. Our marketing team just let me know that MunchBox has really become popular with the TikTok crowd over the past few weeks. Cool. We just launched a limited edition Pokémon MunchBox. It looks like its popularity has attracted a ton of bots. Our analytics solution, Mixpanel, just let me know that our conversion rate is going down. Ugh. Last time this happened, our customers got stuck while bad snackers squeaked through. This is exactly the opposite of what we want, and our exec team is going to kill me. I won't be able to have lunches with them anymore. Micah, can you jump on this and fix it ASAP?
Sure, Danielle. Okta can help with this fraudulent activity. I see in Okta's system log that we're allowing a ton of bad traffic, there's a few policies I can configure in Okta that will help. We'll use Okta's ThreatInsight, Okta's native capability to detect and automate threats, and integrate with our bot mitigation solution, Fastly. This will then feed into Okta's risk engine, we're adding invisible security to block these bots without impacting legitimate snackers. In fact, I was already integrating our bot detection solution, Fastly, as you can see here. The remaining steps could be done in this admin console, I prefer to do this via API. Let me pull up Postman, which simplifies interacting with APIs. You can see the endpoint I'm calling here and the payload that I'm sending to it.
Previously, I turned on ThreatInsight onto Audit mode to just log the suspicious activity that was occurring. Given this bot attack, I now want to change that to Block mode to automatically deny suspicious activity identified by Okta. We'll send that, and you can see here we're getting a 200 OK to indicate that the change has been made. Now I need to create a new risk policy that blocks the high-risk attempts, thereby catching bad snackers and minimizing security blind spots. I send that, and I get the 200 OK as well.
Let's head back to the Okta system log, and we can see that it's logged the ThreatInsight changes and added this new risk policy. We can also see risk signals from Fastly being regularly ingested into Okta, and we can see high-risk requests are now being blocked. I'm so glad I didn't have to defeat these bad snackers myself and was able to rely on Okta and Fastly's expertise to get the job done for me.
Thanks, Micah. Looks like the authentication errors are starting to go down, which means my exec lunches are going to go up. Let's check out TikTok and see how people are reacting.
Hey, everyone. It's Taejoo, your one and only average snacker, and I'm back today to review MunchBox's app. As you guys know, I've been waiting forever for these Pokémon MunchBox snacks to drop. Today, I'm going to review MunchBox's app, and next week, I'll review my snacks. Let's go ahead and get started. I've already downloaded MunchBox, and the first thing I see here, the Snack Special for $5 a month. Definitely want to add that to my cart, and I'm liking what I see so far. Yep, here are those Pikachu snacks that I wanted, too. Going to go ahead and add those to my cart, and I should be ready to check out here. Before I can check out, it looks like I need to create an account. Makes sense.
Probably just need to enter my name, email address, password, the usual stuff. Let me go ahead and do that now. Name, email, and oh, wait, no password. I can just verify my account through my email. Extra points for MunchBox on that one. Okay, I see the email from MunchBox now, and I'm one step closer to my snacks.
Now, before I can officially buy my Pokémon snacks, it looks like MunchBox is asking me for my favorite snack types, but I really just want to get straight to buying my snacks, I'm going to skip this for now, and I'm ready to check out.
Okay, guys. Far, I got to say five out of five for MunchBox. Impressed with the sign-up process, the UI, and I'm sure those Pokémon snacks will be great. As you guys know the deal, don't forget to subscribe average snacker Taejoo, and I'll see you next week.
Looks like Taejoo is a satisfied customer of MunchBox, and so is her TikTok entourage. Thanks to Okta, I was able to ensure a seamless passwordless customer experience, learn more about snack preferences during checkout to provide promos in the future, quickly set up e-commerce and analytics to monitor our conversion rates, reduce malicious logins with Okta ThreatInsight and the Risk API with our bot detection vendor, Fastly, all while saving hundreds of hours of developer effort.
Don't you just love when the PM lists out all of these results like that as if it was, one, their doing, and two, really easy? Normally, this would annoy me more. This time, I'll admit I'm ever so slightly humbled. Okta legitimately saved me months of time. I got the visibility I wanted. I'm getting promoted for owning this launch, and I was able to complete the project in less than half the time it would normally take. Now, lots of cheesy snacks.
I never get tired of seeing what the demo team pulls together. It's great to see and hear about all the incredible momentum Okta has when it comes to customer identity. I'm also really fired up about our workforce identity innovations that will push your businesses forward. Over the last 12 years at Okta, we've seen a fundamental shift in the role identity plays for organizations. It has been heard loud and clear, you require a single solution for every user type and every use case. You need it to work for not just apps, but also infrastructure, containers, and databases. You need to democratize and simplify how users gain resource access by empowering your business partners to determine requirements rather than centralizing with IT. You heard us talk about it in the documentary, I'm making it official right now.
Okta is breaking into both privileged access management and identity governance administration. These have both been big areas of need for your businesses, and we are not only delivering on those needs, we're doing it in the Okta way, simple cloud-based delivery with an emphasis on the features you need and use. I'm thrilled to introduce Okta Privileged Access and Okta Identity Governance. This is huge news for Okta and a really natural evolution for us and our platform, and for identity overall. When it comes to Okta Identity Governance, we've reimagined IGA for a cloud-first world where the number of resources accessed by your workforce has dramatically increased, and your workforce itself has transformed. For Okta Privileged Access, we're not building a product for the way people used to work and for the way infrastructure used to be.
We're building for the way infrastructure is today and will be in the future, cloud deployed and just in time, the way critical infrastructure access should be. Users, resources, and access policies are all the areas where Okta excels. One unified identity control plane is the best way to keep your organization secure and compliant while still keeping you nimble and innovative. With Okta Privileged Access and Okta Identity Governance built on our platform, you can have unified visibility across any type of user and any type of resource. For us, taking on more of your complexity and securely simplifying it is a natural step in giving you more freedom to grow and use technology. We're excited to tell you how we're doing it. I'll turn it over to the team to share more details.
All right. Huge news from Todd right there. I'm back here with Diya with a couple of new faces. First, George Kwon and Michael Chou, both Vice President of Product Management, here to talk about these new products. Diya, I want to start with you. I know you quite well. I know one of the things that gets you really excited is entering new markets, and we're doing that clearly with IGA and PAM. Let's start first with why is Okta uniquely able to do this?
Yeah, that's a great question, Ryan. If you look at organizations today, they are struggling basically to meet their security, compliance, and workforce productivity goals because they have limited resources. Now, they're trying to cobble together point solutions, but these point solutions cannot keep up with the dynamic nature of work and the speed of cloud modernization. Also, for many of these organizations, the cost of cobbling these point solutions together is extremely prohibitive.
What we want to do is we want to provide a unified identity platform that acts as a unified control plane that allows our customers to be able to manage their risk, their security, their policies, and also provides visibility across all types of users and all types of resources. While we do this, we really want to be able to bring the same principles we brought to our identity access management suite of products, which is cloud first, ease of use, and ease of deployment.
That makes a ton of sense, but I imagine it's more than just a control plane, right?
That's absolutely right, Ryan. We're building our privileged access management solution not just for resources in the past, but for how resources work today. What we're doing is we're adopting a cloud-deployed, just-in-time credential model that works not only for on-prem resources, but also for the ephemeral cloud resources of today. In addition, we're also broadening privileged access management, not just for servers, but for other resources like Kubernetes clusters, databases, et cetera. On the identity governance side, the Okta Identity Governance product is going to be able to redefine governance for the way it should be in the cloud world. Today, there are numerous applications that customers use. There are numerous types of workforce they have, so different types of users, whether they are your employees or your partners, or your contractors.
All these people need the right access to the right resources and the right governance to succeed. With Okta Identity Governance, we're trying to reimagine the identity and governance space for a cloud-first world, where organizations have many, many more resources that their workforce has to access. The definition of the workforce itself has changed. You don't just think about employees now. You think about partners and contractors. All these people need the right access to the right resources and the right governance for them to succeed.
With Okta Identity Governance, we're also providing the ability to have self-service access to resources via common tools like Slack. In addition, we will also provide an approval request for your more sensitive applications, data, and tools. With our Workflows tool, we're going to be able to provide you the ability to build customization and automation for your business processes so that you can move your business forward.
That's super clear. I love it. I want to turn to you next, George. George, you've actually been here so long, so long in fact that you launched our now famous Universal Directory product way back when. I want to hear from you, what can customers expect from the new Okta Identity Governance product?
That's right. I was here when we launched UD. It was a great launch. I think this might be more exciting. Okta Identity Governance is an end-to-end solution for customers to manage who has access to what. It starts with Lifecycle Management, which automates the lifecycle of all your users, employees, contractors. It automates provisioning to applications and infrastructure. On top of Lifecycle Management, we're going to introduce a new access request capability, enable self-service for all users requesting any resource, approval workflows, granular admin roles. Really allow you to delegate all those access requests to the business. On the governance side, we're going to release more reporting, the ability to enforce temporary access policies, as well as access certification campaigns, so that you can be successful in all of your compliance and security goals.
That's awesome. That does sound better than Universal Directory. I didn't think that was possible. I want to talk about what we've done with Lifecycle Management. We have pre-built integrations, low-code workflows, but specifically around governance. We have a lot of innovation there. Tell us about that.
Yeah. The challenge with self-service and access requests is delivering an experience that end users love and are willing to adopt, and getting rid of all those siloed access request processes that are sprouting up in the shadows. With Okta Identity Governance, we're going to deliver modern end-user experiences through mobile and chat, and we're going to make it possible for the business to define their own access requests, rules, and approvals, so they adopt a central platform. On the governance side, Okta sits in a unique place, in the middle of the directory, access management, identity governance, where we can provide unique context and visibility. We're going to provide a single pane of glass through reporting, and we're going to weave that context into our access request capabilities and access certifications, so we can really streamline the process. No more rubber stamping.
That makes a lot of sense. George, sum it up for us. Tell us about Okta Identity Governance and what customers can get from it.
Okta Identity Governance is going to help IT teams scale through more automation, delegation, self-service. It's going to drive better security and compliance outcomes, all while making the end-user experience better, making getting access to the things you need actually easier. Okta Identity Governance is going to be for organizations of all sizes, whether you are new to the governance game or whether you've been at it for a while and are looking to modernize. I'm super excited about this launch. I've been talking to so many customers. They've been pushing us in this direction for years, and now I get to look them in the face and say, "Help is on the way."
Very exciting indeed, George. A long time coming. Thanks for that. Michael, I want to turn to you. You're relatively new to Okta, actually. Before we talk about Okta Privileged Access, I'd love to get your take on the things that Okta had built in these two areas already in our existing products.
Yeah, absolutely. I think what's really impressed me the most, Ryan, is just how much investment Okta's already made in this area. George spoke about this, but with the Okta Identity Governance, this builds on top of our Universal Directory, it builds on top of our workflow capabilities, and also Lifecycle Management. With Okta Privileged Access, now we are leveraging the experience we've had in terms of securing infrastructure with our multi-factor authentication product and also our original advanced server access product. I think what's really special here is with Okta Privileged Access, our customers are now able to have a centralized control plane to control access to their Linux, their Windows servers, databases, and also Kubernetes clusters. Because identity is at the foundation, only Okta can really automate the lifecycle of accounts and also policies end to end, and then also insert governance inline [auth flows].
It sounds like a true end-to-end solution, and sounds like it's very much better for IT. One of the things I understand about traditional PAM products is that they're not a great experience for end users. Tell us about what that's like for Okta Privileged Access?
For our users, this is actually a really seamless and easy-to-use Single Sign-On experience, whether they are logging into a monitoring dashboard with their web browser or they're logging into a Windows server with their local RDP client. Behind the scenes, our customers now have flexible policies for role-based access, attribute-based access, and also time-based access to really deliver just-in-time, least privileged access. To meet the demands of compliance, we audit every single login capabilities, and we fully capture all the activity that's coming in your SSH and also RDP sessions. Now, with everything tied to identity and unified to a single platform, we've really made it easy for the security teams to compile their reports and to compile their regular audits.
That's super clear. The Okta Advanced Server Access product has been out there for a while, really successful with customers. A ton of customers are using it. Tell us about how Okta Privileged Access builds on top of what we already have with Okta Advanced Server Access.
That's a really good point, Ryan. With our Advanced Server Access product, we've really made it very easy for the users to use, but we've made it even easier to deploy, regardless of whether they're running hybrid cloud or they're running multi-cloud. We deliver these administrative controls as SaaS, just as you would expect from Okta. Now, just as a benchmark, we've had our customers deploy Advanced Server Access to hundreds of thousands of servers, and with other products, they weren't really able to do that. With Okta Privileged Access, our new product, we're able to help our customers protect even more resource types and layer on even more security and auditability.
That's very compelling, Michael. Very excited about Okta Privileged Access and Okta Identity Governance. I want to know when customers can get their hands on these products. George, let's start with you. When will customers be able to get Okta Identity Governance?
Yeah, Okta Identity Governance will be available in Q1 of 2022. It'll be available starting at $9 per user per month. Really excited about that. To remind you can go make use of Universal Directory, Lifecycle Management Workflows today, really implementing a lot of automation to start to solve some of those governance needs.
That's also a great reminder. You don't have to wait to get started. You can start now with a lot of the great capabilities in our Lifecycle Management products.
Yeah, that's right.
Michael, I want to come to you next. When can people expect to get their hands on Okta Privileged Access?
Okta Privileged Access is going to be available in Q1 2022 as well. Pricing starts at $45 per PAM unit per month. You don't have to wait until then to get started. With our Advanced Server Access product, our customers can secure their server fleet today. We've made a lot of improvements since the last Oktane for compliance with our SSH session capture. For our customers that have Windows environments backed by Active Directory, we have a lot of really great improvements coming there as well. We've heard from our customers that servers are the most important resources to protect with Privileged Access. We can get you on the right path today.
That's awesome. Two new products, Okta Privileged Access, Okta Identity Governance, both coming soon, but customers don't need to wait to get started. Actually, we talked a lot about these products, but what we want to do next is show you these products. Let's send it back over to the demo team to see them in action.
Hello, I'm Lance. I'm a site Operations Manager here at Atco Foods. I run a number of IT projects globally, reporting directly to our CIO.
Hey, what's up, Lance? I'm Aaron, a Security Analyst responsible for helping our compliance team assemble audit reports for FedRAMP, SOX, and PCI DSS.
Aaron, do you remember when we used to have separate systems for identity governance and privileged access management? It was really hard to execute access requests, meet compliance requirements, and control access to sensitive resources in a simple and orchestrated way.
You know what was also hard for me, Lance? Every quarter at audit time, you and all the other app owners called me the fun police because I pestered you all for audit logs. Then I had to spend weeks cleaning your dirty data for the compliance team.
That's about to change, Aaron. You see, because we're already using the Okta Identity Cloud, I was very pleased to see the new Okta Identity Governance and Okta Privileged Access products, which will help us unify key elements of our IT and business strategy. You know, when it comes to sensitive access, I want a process that is transparent, seamless, and agile. The new Okta Identity Governance integrates with our existing collaboration tools, such as Slack, making this process incredibly smooth. It is a simple, automated experience when users need access to any Okta app, for example, Zendesk. Don't take it from me. Let me ask Taejoo, who is new to the team. What does she think about this process? Taejoo?
You're right, Lance. I'll admit, I definitely came here for the MunchBox snacks, getting access to systems here at Atco has been great. As a Site Reliability Engineer, I typically need access to various resources like infrastructure in AWS, collaboration tools, and some on-prem tools that we use for ongoing maintenance. All of those apps were assigned to me on day one, let me tell you, the last company I worked with, it took weeks for me to get access to systems, while other full-time employees got access to apps much faster. I was definitely pleased when I came on board here to see everything standardized on Okta, and even built into the tools that I use day to day.
It's great that I can just pop into Slack to create these access requests instead of having to go through clunky old school systems. That reminds me, I actually do need to request access to Zendesk to monitor some of our internal security tickets. Because Zendesk wasn't assigned to me on day one, I'm going to go ahead and create a new access request with Okta. In the list here, I'll choose access to applications, and I'll choose Zendesk in the list, provide a quick justification like ticketing. All right, I'm going to go ahead and submit this request and see if it gets approved.
I got an access request. It's from Taejoo. Okta Governance notifies me in real time whenever someone asks for or is granted access to production systems. In fact, Okta just messaged me via Slack to let me know Taejoo requested access to Zendesk. Since all of our site reliability engineers should have access to this app, I'll go ahead and approve access for her.
Okay, great. It looks like my access to Zendesk was approved. That was super quick. I noticed at the same time that Atco's Okta review bot just pinged me asking to recertify my access to Dynatrace. I'm not really sure what this notification is about. I haven't seen it before, but I do still need access to Dynatrace to monitor some of our servers. I'm going to go ahead and choose yes here. In the justification, provide another quick justification like I did before, like server monitoring. I think that should be good enough, and we'll go ahead and submit that. Hey, Aaron, since I hadn't seen that notification before, could you tell me what it's all about?
What you saw was a smarter access review. It automatically prompts users to self-certify their access and is triggered by signals unique to Okta. In your case, Taejoo, the signal was inactivity. You just hadn't logged into Dynatrace over the past 30 days. This is less fatiguing on reviewers, and it saves time. The other benefit is that Okta captures these self-certification events for audits, and it even sends them to me via email. This is great because I no longer have to pester Lance to get any audit reports ASAP all the time. It's all right here.
I appreciate that, Aaron. You know what, a uditing and governance for applications is great, but it's not everything. We also need to ensure we can manage fine-grained access policies to infrastructure. Okta Privileged Access helps us manage access to more sensitive resources and adhere to the principle of least privilege. Let's see what that looks like for Taejoo.
Okay, I confirmed earlier that I do still need access to Dynatrace, and I was even able to connect to Dynatrace directly from Slack, which is cool. Now, oh man, I'm thinking I shouldn't have done that. I just gave myself more work. One of our database server CPUs is running at 0%. I should probably go and fix that. I think this has happened before, and all I need to do is restart SQL on that server. I'm going to pop back over to Slack now and create a new access request.
This time I'll choose to access servers. Yep, in the list here, I can see that database server that I need access to. I'll go ahead and request access for about, I think three days should be good enough to do some ongoing monitoring. Provide another justification, like I need to fix stuff. All right, that should be good enough. I'm going to go ahead and submit this. Now, that request is fired off. Let's see if it gets approved.
I got a new access request. It's from Taejoo. This looks like Taejoo needs access to one of our SQL database servers. Let's let her in. I love how this whole process is nicely integrated into Slack. It has helped us achieve widespread adoption of our privileged access processes. Among other things, I can see that this server is actually running in production. Before I approve, I do want to make sure I can see all of the relevant attributes of this server. Okta connects with our downstream infrastructure providers to pull in all of the resource tags required, making it really easy for people like me to know what are the right policies and what levels of access to apply without having to go through security every time. Here, in the Okta dashboard, I can actually see all the information I need about this server. Let's see.
It looks like this is a Windows machine running on AWS. It is tagged for sensitive data. Look, it is also tagged for PCI compliance. Because this is a PCI compliance system, I'll need to make sure Taejoo gets access only for a limited time. Slack is also telling me that Taejoo requested access for only three days. This actually complies with our PCI server policies, I'll go ahead and approve access for her as well. One more thing that I love about Okta is the ability to apply time-limited access to privileged systems automatically. This way, Taejoo can get to this task in her own time, I do not need to worry about removing access afterwards to meet compliance.
Okay, great. That was super quick. Just like my access to request to Zendesk from earlier, my request to that database server got approved. Thanks for that, Lance. Now I'm going to log on to that server directly from Slack. This is a Windows server, so I'll use my local RDP client to log in. That's already nicely integrated with Okta for Single Sign-On , so I don't need to enter any additional credentials, even for these Windows Server domain join machines. Of course, it looks like my actions on the server are going to be recorded. IT is always spying on me. I'll try not to break anything here, but no promises. I'm logged on to that server now. I'll go ahead and start up services. We'll find SQL here, give that a little kick, and okay, that's up and running. Phew, another fire was put out.
Doing these audits used to be really painful. Whenever I asked our business app owners for access data, they took weeks to copy this on USB drives or to print it on spreadsheets. Come on, do you still write checks at the grocery store, too? Fortunately, Okta eliminates the manual work of collecting access data and consolidates it under one umbrella. I can see who has access to our applications and infrastructure. For our more advanced compliance requirements, I can even view recordings of what people did in our Linux and Windows servers. Looks like Okta sent me a report that shows recent access requests. This report also details any privileged actions that users performed. Okta captures all privileged SSH and RDP sessions and dumps the logs into a secure S3 bucket in AWS.
Taejoo's latest session was on a Windows server, let's check out that video. All right. I can see Taejoo in the server. It looks like she's opening up the Services app, from there, she's restarting the database. So far, so good. It looks like she's closed the session. Perfect. Nothing suspicious to flag here. I love how this all came together. Standardizing all of our access and governance needs with Okta has really unified our security posture from auth to audit. All of our reports are generated and consolidated in one platform, I don't need to pester our team for updates anymore. From the looks of it, these jokers, I mean, dear coworkers, appreciate that.
With all our identity and access management requirements, including governance and privileged access, consolidated into a single platform, we are finally able to streamline access requests, meet compliance, and better control access to sensitive resources in a modern way using modern tools that do not hamper employee productivity or the pace of business. We are much better off now, thanks to Okta.
As we get ready to wrap this up, I just want to say a heartfelt thank you to the demo team, to the product experts you saw on the panel, and to everybody behind the scenes who made all this possible with these great product innovations coming your way soon. With that, I want to turn it back over to you, Todd.
I am very proud of the innovation we're bringing you today. From joining forces with Auth0 to launching Okta Privileged Access and Okta Identity Governance. As we roll out these new solutions in the coming months, you'll witness the benefits of incredible extensibility, security network effects, and a unified identity solution for every use case you can imagine. Everything the team does is about helping to push your organizations forward, whether that be for your own workers and their productivity and security, or for your customers who rely on your digital experiences to run their lives.
I believe that the future is at Okta, and that we're on the way to achieving our vision of enabling everyone to safely use any technology. I am extremely proud of what the team has accomplished this year and even more fired up for what's to come. Thank you for tuning in and thanks for being a part of Okta.
We have so much to look forward to with all of these exciting Okta platform innovations. It was really cool to hear about a ll of them from our incredibly talented Okta product leaders. Now it's time for a deeper dive as our breakout sessions are getting underway. Be sure to visit the Okta hubs and Partner Expo to get answers to all of your burning questions. Later today, the remarkable Julia Louis-Dreyfus will be performing feats of strength and delighting us all with her wit and insight in a conversation with our very own Sarah Schiff.
Good afternoon, and welcome to Okta's Virtual Investor Day. I'm Dave Gennarelli, and Head of Investor Relations here at Okta. We're in the middle of day two of Oktane 21, so I hope you were able to tune into some of the content so far, which really helps set the table for what we have lined up for you this afternoon. Now let's take a quick look at today's agenda. We have a great lineup for you with our CEO, Todd McKinnon, kicking things off.
We'll then head directly into a conversation between Todd and Eugenio Pace, the Co-Founder and CEO of Auth0. You'll also hear from Diya Jolly, our Chief Product Officer, Susan St. Ledger, our new President of Worldwide Field Operations, and Mike Kourey, our new CFO. Interspersed throughout that content, we have our Executive Vice Chairman, COO, and Co-Founder, Frederic Kerrest, hosting chats with three great customers.
The content will run for roughly two hours, which includes a short break. After that, we'll have plenty of time for Q&A. Of course, our attorneys would not forgive us if we didn't mention that we will make forward-looking statements in these presentations, so please see all of our risk factors, including the ones in our most recently filed Form 10-K. We have a lot of material to cover, With that, I'll turn it over to Todd to get things going. Todd?
Good afternoon. Thanks for joining us today. I'm proud of the big, bold moves we're making, from innovating across our platform, our new PAM and IGA products, and joining forces with Auth0. The past year has shown that we can grow, scale, and be more relevant than ever, driving the industry forward, even in the face of tough circumstances. Today, I wanted to share how I'm leading the company, the foundation for strength we've built, and our long-term growth strategy to become a primary cloud. We have a large addressable market. Our customer base has never been stronger, and our products solve many of the biggest challenges businesses pace today. The long-term secular trends, adoption of cloud applications, digital transformation, and deployment of zero trust security environments are in our favor.
Okta is central to both the digital experiences and the new ways of working the world requires that have only been accelerated by the pandemic, and we are growing and investing to capture the large opportunity in front of us. For me, the past year has been a powerful reminder of the ability of people to endure, persevere, and of businesses to remain flexible and adaptable. I've seen Okta's core values of transparency, integrity, innovation, and customer success at work every single day this year. I'm never more inspired than by stories of our customers, partners, and employees as they push the boundaries of what's possible to build and solve big problems. The world has changed, and with it, so have the priorities of people running businesses.
Okta increasingly addresses the key top-of-mind areas that CEOs and C-level executives care most about, from driving growth to reducing costs and future-proofing their businesses. Our solutions to these problems are the reason the world's largest organizations turn to Okta. They have to manage this new environment, implementing an identity solution that meets their complex technology needs. Yesterday, you heard from lululemon, Farmers Insurance, and The Trevor Project about how our commitment to their success drove their organizations forward.
Today, you'll hear from Zoom, ENGIE, and Fox about how Okta's platform is solving mission-critical business challenges. Our vision is to enable everyone to safely use any technology. We believe that identity is woven into the fabric of every digital experience. Identity is increasingly top of mind, from the boardroom to the spare bedroom, reaching people across every business team and critical to the top-line business objectives of every organization.
This vision is ambitious and long-term and requires a singular commitment to solving identity for the Internet and remaining independent and neutral. I believe that Okta has the potential to be the standard for how digital identity is built on the internet. What does this mean exactly? Two concrete things. Every organization uses this standard to validate and protect their workforce and customers, and every digital resource accessed by every person in the world is done via their Okta identity. We are an innovative company and a disruptor, and that disruption begins with the Okta Identity Cloud and the platform we're building. Our unified, extensible, and integrated platform is our foundation to build incredible new products and features, while also making those identity capabilities more accessible to everyone in an organization. Today, we're providing the foundation for seamless login experiences that are totally customizable.
It doesn't matter if our customers want out-of-the-box products or to build from scratch with our APIs and SDKs. The Okta platform is able to meet each end of the spectrum and everywhere in between. That's why the Okta platform is made up of core technologies that are flexible, programmable, and integrated to everything. By building a platform that is deeply connected to every technology and meets every identity use case, over time, we'll push the technology ecosystem, driving even more innovation and security. It is for this reason I'm so passionate about ensuring that Okta's platform enables us to be a primary cloud, able to address and unify large markets. In a cloud-centric world, identity has become even more important and strategic a choice than infrastructure or collaboration clouds. It's the epicenter of an organization's tech connections, and it offers freedom of choice to adopt any technology.
Choosing the right set of five or six primary clouds that serve the most critical business functions in an organization is one of the most important decisions CEOs and C-level executives will make today. Choosing an identity cloud is the most valuable because it facilitates choice and flexibility in all other technology. The announcements we've made over the last couple of days speed us toward this marker of becoming a primary cloud and expanding the problems we can solve for customers. We'll solve two new major customer requests with two new products, Okta Privileged Access and Okta Identity Governance. Both of these announcements represent further penetration in the workforce identity market. For Okta Privileged Access, we're not building a product for the way people used to work, nor for the way infrastructure used to be.
We're building for the way infrastructure is today and will be in the future, cloud deployed and just in time, the way critical infrastructure access has to be. When it comes to Okta Identity Governance, we're reimagining IGA for a cloud-first world where the number of resources accessed by an organization has dramatically transformed. Just as critically, the potential for customer identity is massive for every organization today. Everyone is moving their business online, and with that push comes the need not only to deliver safe and secure experiences, but to create meaningful ones for customers. That's why I'm so excited that we're joining forces with Auth0. The feedback from our employees, customers, and partners has blown me away. Not only do we share the same vision, our values of how we operate are tightly aligned.
We have the same worldview when it comes to the role identity plays in powering the internet. Each company has its own strengths and expertise. Coming together will give customers more choice to meet every identity need. Together, we'll accelerate our ability to become a primary cloud. We are going to maintain and invest in both platforms, and in the background, we'll be integrating our technologies over time to provide even more innovation. I have a deep amount of respect for what Eugenio and the Auth0 team have built, and you'll hear more from Eugenio in our Q&A shortly. Over the past year, we believe there has been a meaningful increase in our TAM related to expanded opportunities within enterprise customers, as well as our new product introductions that address more use cases. The workforce identity market has grown from $30 billion-$35 billion.
In addition, you heard the exciting news that we're expanding into IGA and PAM, which adds another $15 billion for a total workforce TAM of $50 billion. Looking at customer identity, that market has grown from $25 billion- $30 billion. We accelerated our penetration into this market with the complementary platform of Auth0. In total, it's a massive $80 billion market opportunity, and I believe we're still in the early days of what we can accomplish. In the following sessions, you'll hear from Auth0's Co-Founder and CEO, Eugenio Pace. Next, Okta's Chief Product Officer, Diya Jolly, will share our product strategy and roadmap. Susan St. Ledger, Okta's President of Worldwide Field Operations, will discuss Okta's FY 2022 go-to-market strategy and customer centricity. Mike Kourey, Chief Financial Officer, will share our strong foundation for growth at scale, our growing addressable market, and long-term financial model.
From my Co-Founder and COO, Freddy Kerrest, you'll hear conversations with Okta customers Harry Moseley, CIO of Zoom, Paul Cheesbrough, CTO and President of Digital Fox, and Claude Pierre, CIO of ENGIE. I'm extremely proud of what the Okta team continues to accomplish and can't wait to drive forward the future of identity. Thanks again for joining us today. Let's kick things off with a conversation with Eugenio Pace.
Now, I'm really excited to have joining me the CEO of Auth0, Eugenio Pace. Welcome, Eugenio.
Thank you for having me, Todd. How are you?
Excellent. Excited to have you, excited to have a conversation with you about Auth0 and Okta, and more importantly, about this amazing industry we're in. Why is now an important time for identity for organizations?
Well, as you know better than anybody else, identity is this connective tissue that connects everything. Every application, everything we interact with in our lives, needs identity. We are only scratching the surface, because if, I don't know your experience, but in my personal experience, from the moment I wake up to the moment I go to sleep, I know it can be much better than the experience that I get. When I look at statistics like only a 3% penetration or 4% penetration of cloud into the entire world of IT, and how critical identity is for that gives me an idea of how much we can do and how much more we can do.
We've known each other for a while now, and it's been amazing to see the progress and the growth of Auth0. What does Auth0 stand for to you, and what are its values? As it relates to Okta, what do you think about our shared vision and values together?
That's probably the most exciting aspect of this partnership because, yes, we know each other for a few years now, and I've been an admirer of you as a leader, as an entrepreneur, and the company that you built. Which I know how hard it is to do that from personal experience, so I really look up to you and what you achieved as an organization. I also look at the two things that you mentioned. One is the commonalities between the two of us, Okta and Auth0, and the complementary nature of our businesses as well. We do have shared values. We call them in a different way, right? We have three core values. We give a shit. N plus one is greater than N. One team, one score. When you go one level deeper into what they mean, they mean innovation.
They mean constant improvement. They mean collaboration. They mean empowering our teams. They mean care. Those are pretty much the same as Okta has listed as their core values. To me, that's a foundational piece of successful partnership. What we bring, and maybe on the more complementary aspect of our businesses, Auth0's DNA, the core DNA, it's around builders and developers, people who are building solutions in the world. We believe, I'm sure you've heard this many times from me now, we believe in a world that it's a software world. We believe that every company, it's a software company, even though they might not call themselves a software company, but it is because software runs everything.
Our value proposition is that we check the box on a big problem, a problem that it's pervasive, as I mentioned before, but it's also a big distraction from teams. If you go around building this yourself, not only the solution is not going to be as good as ours, it's going to be weaker, but it also detracts time and resources from what's actually valuable for your business, what makes you unique. That's what we are here for. We are here to make every developer in the world productive, rest assured that this is taken care of for them, and they can go on and move on into what's really, really important for their business.
Both of our platforms have thousands and thousands of customers, and they're really operating at scale. It's important that we continue to invest in and support both platforms going forward. Today in this conference, we're talking a lot about the innovation on the Okta side, and you have the same commitment to innovation in the future and helping customers on the Auth0 side. What do you think this joint innovation means for customers and for users?
Absolutely. We are certainly committed to supporting our tens of thousands of customers that we jointly serve. In many cases, we are actually serving the same customer today. In many ways, our platforms are already integrated. It is possible today, even before we announced this deal among us, it is totally possible for somebody to log in using Okta into an Auth0-protected application, and that's completely supported, real. We don't have to develop anything. That's doable today already. What it means to me and what really is exciting about partnering with you, it's that we can bring what we imagine the future will look like in five years or even beyond that, much faster. We can deliver that amazing future in a couple of years as opposed to waiting, or maybe months in some cases, as opposed to waiting a long time.
In Okta's world, you've been calling this the Identity Cloud. We don't use those words. We use the identity operating system. It's different labels for actually exactly the same thing, which is this broad, universal set of building blocks that our customers can use to deliver on more use cases and to build a comprehensive universal platform that they can use in a broad range of use cases, whether it's workforce or customer or devices, websites, mobile applications, any kind of app. We can do it faster, and we can do it more secure, and we can drive innovation and bring innovation to the market in ways that nobody else can, in the same level of quality. That's what's exciting.
Auth0 is very strong in terms of revenue mix internationally. How did you achieve that in the relatively early phase of the company?
Well, if I could tell you that it was very well planned, and I had all that strategy in my mind, but I would be probably lying if I said that. I think it was a little bit of serendipity, frankly, it's connected to our remote nature, perhaps. When we started the company, I was living as I'm living today in Washington State. Matias, Co-Founder of the company, was living in South America back then. I was not going to go back to South America, and he was not going to come to the U.S. We decided to make lemonade out of lemons and say, "Let's embrace and take advantage of the fact that we are far away, physically far away. Let's hire people everywhere.
Let's hire for talent, for time zone, and for zip code, kind of in that order. One of the side effects of that, and maybe the fact that it's being a developer company and everybody being able to go to the website and click on a button and get a trial account instantaneously without necessarily having to interact with a human. We have people all over the world. We have customers trying us out all over the world. All of a sudden, we found ourselves in a place where 40% of our revenue is generated outside the U.S. and/or outside Americas, I would say, and 60% is generated in Americas, most of it in the U.S. I guess the other, maybe corollary of this, which is obvious in retrospect, identity and access management is not an American problem, right?
It's every application in the world, any industry. It doesn't matter if you're a startup or a well-established company, if you're like a 200-year-old manufacturing company, finance, education, any dimension, any industry needs to know who the users are. There's some universality that makes us a global offering from day one.
After the transaction closes, you'll continue to be the CEO of Auth0. What are your initial priorities as you continue to lead the team and the organization?
Well, yes, that's the plan. The plan of record is to continue our journey. We have already a roadmap. We have a product roadmap. We have a growth business roadmap. The immediate priority is to deliver on that in the short term. Obviously the second priority for us is to find opportunities of acceleration. From a technical point of view, there's some very obvious ones that we can think of. Although we're going to take the time after the deal closes, hopefully soon. We're going to take the time to identify those and do those, with thinking about our customers first. What are the problems that they're trying to solve? Two obvious ones are, one is around the anomaly detection space.
Today we use a lot of signals from the world to identify whether somebody is who they say they are or is suspicious login or not. Now we can combine signals from your platform, from Okta platform, with ours, and we can make both platforms stronger by having more intelligence into whether it's location or devices or applications that customers are trying to login into. We can combine all of that and increase security just by the volume of logins that we both collectively process. The other one, it's clearly, I mentioned this in another session. It is possible today for a company to log in using Okta into an Auth0-protected application. That's completely supported. It happens all the time. We have a lot of customers with that specific use case. We want to make that relationship even easier to onboard. Today, it's done.
There's a standard for it. There's some documentation and protocols to enable that federation to happen. We can make it as simple as a LinkedIn invite for a business. That's something that I'm particularly excited about in the B2B world, with Workforce on one side and SaaS applications on the other side, where we can make that connection happen better, faster, and more secure.
We've been hearing great feedback from customers and partners in the market about us joining forces. What have you heard on your side?
Yeah, it's been the same, and as I said many times before, we have many customers in common actually today. We already are in places where they're using both platforms. In my conversations with existing customers, with prospects, and with our developer community as well, maybe a constituency that is maybe not as familiar with your platform necessarily. We've heard they all see this opportunity that we can unlock. That we can accelerate by working together. It's a big problem. It's a problem that is increasing as more and more systems get online, as our lives become more and more dependent on digital systems to do everything. 2020 was a good proof of that in terms of things that have moved to the digital world. Look, but it's crazy that we still have passwords around us.
It's crazy that we still need to deal with that. With the technology that we have today or around us, the experience that we can provide to our customers, and through them to their employees or their customers, it's way, way better than it is now. That's, I think, what everybody sees and that's what they're looking forward to, what's going to happen in the next few months with us together.
Well, thanks for joining us, Eugenio. On behalf of myself and the entire Okta team, I just want to express how excited we all are to get this transaction closed and move forward building something amazing for customers and an amazing company together. Thank you very much.
Very much looking forward to it. Thank you. Bye.
Hi, everyone. I'm super excited to be here with all of you today. You've had a chance to hear from Todd and Eugenio. What I'd like to do is take you through Okta's product strategy. Before we do that, it's really important to understand this concept of primary cloud that Todd just teed up and how identity has become a primary cloud for all organizations. Let's take a few minutes to do that. Organizations used to lead with business strategy, and technology decisions used to be an afterthought. The choice of technology didn't significantly impact the business outcome one way or the other. However, with digital transformation becoming key to powering a company's growth, every business executive I have talked to now considers technology as a critical enabler of achieving their business strategy.
CEOs are leaning on technology to be a primary growth driver for them in 2021 and beyond. The technologies that truly enable growth for organizations are the ones that have become primary clouds for organizations today. Primary clouds are a foundational part of today's technology strategy across organizations, large and small. Let's look at one example. More than a decade ago, infrastructure was not strategic to the growth of an organization. It was considered a cost center that was slow to innovate, and more often than not, was considered a bottleneck to innovation. Infrastructure decisions were largely left to mid-level managers and practitioners. Cloud infrastructure changed all that. Today, an increasing number of organizations perceive infrastructure as a service to be a growth enabler through benefits such as faster time to market, better customer experience, rapid innovation, and more.
Infrastructure as a service is a primary cloud that powers virtually every digital touchpoint and experience. Just like infrastructure, historically, identity wasn't a strategic priority for organizations. Workforce identity was considered a tactical technology project managed by mid-level IT practitioners looking after Active Directory. It was perceived to be a heavyweight effort that did not scale and limited innovation and growth. Customer identity was an afterthought, often developed in-house by development teams lacking specialization and identity. In the last couple of d ecades, disruptive technologies such as cloud, mobile, social, and IoT, as well as the move to highly personalized products and services, has transformed the dynamics of the digital world. These digital disruptions have marked a new era for us in both our personal and professional lives.
Think about how your own life has changed over the last 15 years or so, both at work and at home. We have observed a dramatic increase in the number of digital touchpoints we engage with daily. Now, take a minute to think about the role identity plays in each of these digital touchpoints. It's ubiquitous. Our workforce needs to be able to work from anywhere and needs instant access to tools, whether that's an office, a spare bedroom, or a coffee shop. As consumers, if we experience any friction in our digital engagement, it often leads us to abandon the engagement. This in turn leads to lost revenue for the organization that we were engaging with. Identity is a common control point in every one of our digital journeys. It drives the experience, it enables security, it safeguards privacy. As a result, the traditional view of identity has faded.
Identity has dramatically transformed into a primary consideration, just like infrastructure or CRM. This is because identity helps deliver higher productivity, consistent and frictionless experiences, and secure access. Let's look at how identity became a critical growth enabler for one of our customers. Today, Ally Financial is on a transformational journey with Okta. They work with over 18,000 auto dealerships across the U.S. and transact billions of dollars every month. Before Okta, the experience these dealers had was very manual and required a lot of call center interactions to support their transactions. This created a lot of friction in the dealer's experience with Ally, high call center costs, and lost time and revenue. With the Okta Identity Cloud, they are able to deliver a secure and frictionless experience to their dealers.
Their dealers can transact seamlessly, administer their own passwords, render new credentials for identity, and more, all from one place without the friction of interacting with the call center. The Ally Financial example is not a one-off. Companies large and small are leveraging identity as a foundational element of their business and technology strategy. It is because of this example, and so many others like it, that today identity has become a primary cloud. Okta has played a pivotal role in shaping the journey of identity as a primary cloud. The Okta Identity Cloud has helped our customers lead with identity to transform their business. Let's take a quick look at a couple of examples to show how identity is ubiquitous across workforce and customer experiences. For example, identity touches every aspect of the experience for an employee.
Let's take a typical workforce experience and the ways Okta orchestrates an employee access. A new employee joins the marketing department and authenticates into an Office 365 app for the first time. In the background, Okta starts detecting risk for that authentication. That means not only using Okta's device trust to verify that her phone is a managed device, but also relying on Okta Hooks to retrieve third-party threat feed data that provides more risk signals. While the employee only experiences a simple login, Okta behind the scenes provisions an Office 365 account just in time and automates access to the right license and role appropriate for the specific user. Beyond that provisioning, Okta Workflows triggers other actions for the new employee, like an automated company email tailored to new employees joining the marketing department.
Lastly, Okta gathers data about the user's behavior and authentication attempts and feeds it into user behavior analytics tools like Splunk through pre-built Okta integrations to ensure higher ongoing security. On the surface, it's a login attempt, but underneath, identity is the center of the employee experience. This is identity as a primary cloud. One unified cloud for SaaS, on-prem, and cloud-native apps. Secure and frictionless employee experience is just one of the ways that our customers like FedEx, NTT, Albertsons, and thousands more are leveraging the power of the Okta platform. Let's take a look at it from a customer identity perspective, where Okta is just as integral. A customer is considering whether she wants to buy exercise equipment and lands on a CrossFit equipment site. As she's browsing for a little while, she's prompted to create an account by just using her email.
No need to increase the friction by dealing with a password and account details. In the background, an Okta Workflows triggers a Marketo-enabled marketing campaign to kick off. She finds the perfect set of weights and adds a few items to the cart but ends up getting distracted. Thanks to the email registration, she gets a Marketo-generated email reminding her about the items in her cart. She comes back, and using just her email address, she's able to get an emailed link to easily authenticate without any friction. Back in her account, she goes to the cart and begins to complete the checkout process. The CrossFit site is using Okta for more than just registration and authentication. They want to make sure high-value transactions have a second layer of protection for customers.
Her cart value is above a certain dollar value, so she's prompted for MFA before she completes her transaction. While all of this is going on, Okta orchestrates multiple downstream backend processes that are triggered based on her evolving identity. For example, Okta is orchestrating how identity flows into the CRM system, which updates the user from a prospect to a customer. Okta also pushes the new customer's identity into the customer success system, assigning the new customer a virtual trainer to hit her fitness goals. These are just a few specific examples, but the automation and integration capabilities of Okta open up so many more. Once again, identity is more than just logging in. It touches every aspect of the customer journey.
Thousands of our customers, including MGM Resorts, CarMax, Major League Baseball, and more, leverage Okta's capabilities of progressive profiling, marketing integrations, step-up authentications, and many others to deliver a differentiated front-door experience for their customers. We talked about how primary clouds address a broad set of critical needs in an organization, which allows them to address huge primary markets. It is this characteristic that also allows primary cloud technologies to broaden into many more large adjacent markets. To explain what I mean, let's take Salesforce as an example. Salesforce started with their core cloud-delivered CRM offering with Sales Cloud. They broadened into the TAM for service and support software with Service Cloud. Subsequently, they broadened to the TAM for marketing software through Salesforce Marketing Cloud, and more recently, they broadened their TAM yet again to commerce-based software via Salesforce Commerce Cloud.
As you heard from Todd earlier, there is a significant TAM across workforce and customer identity. There is a massive future TAM represented by the adjacent markets of identity governance, privileged access, zero trust network access, privacy and consent management, and more in front of us. This is really very exciting. Okay, now let's talk about where we are going in the future. Because identity truly is a primary cloud, the breadth of use cases that identity touches is infinite, and the adjacent markets are numerous and large. A product or even a set of products will never be able to address all these use cases to become the growth enabler identity needs to be for organizations. At Okta, we firmly believe that the only answer to this is a platform approach.
An identity platform that not only provides the core identity foundation, but also the tools that empower our customers and partners to innovate and build solutions on top of Okta. This is why my team is acutely focused on continuously enhancing the value and capabilities of the Okta Identity Platform for our customers. I think about our platform across three core pillars. First, it's unified. Our platform consists of a set of modular components called Okta Platform Services, which can be combined to unlock new use cases, products, and resource types. This uniquely positions us and our customers to get to market faster in new business areas and to serve emerging use cases. It gives us a leg up over competitors with disjointed platforms. It's extensible. Every organization has unique needs, and even the most robust suite of identity products can't solve them all.
A flexible platform approach enables our customers and partners to extend and build on top of Okta beyond the use cases that we can solve today. We do this through our no-code, low-code, and pro-code capabilities. Finally, it's integrated. Every organization has and continues to build an ecosystem of tools, applications, and infrastructure that helps them grow. New SaaS applications, developer tool chains, analytics engines, infrastructure as code, et cetera. We have built a platform with over 7,000 integrations to enable customers to take an identity first approach. It is our maniacal focus on these three pillars that allows us to truly deliver a platform that allows an identity primary cloud that is a growth enabler for our customers. The customer success stories that we have, whether it is Ally, FedEx, CarMax, or others, prove that our strategy is working and benefiting our customers.
Earlier today, we made some key product announcements that will further strengthen our customers' ability to solve large new pain points using the Okta Identity Platform. We announced that we are entering two new markets, the identity governance market and the privileged access management market, with two new products, Okta Identity Governance and Okta Privileged Access, in the first quarter of 2022. The existing solutions in these markets were deployed during the legacy identity era and don't scale to today's challenges of hundreds of resources, ephemeral infrastructure, a global and remote workforce that also faces increased security threats. We believe that using our existing Okta Platform and cloud-centric approach, we can transform these markets the same way we did for access management.
As we broaden into privileged access management, we want to make sure that we don't just build for the way infrastructure used to be, but how it is today. Therefore, we are adopting a cloud deployed, just-in-time, user-based credential model that is built not just for on-prem, but also for today's cloud-based dynamic resources. We won't only restrict ourselves to servers, but also extend to secure other privileged resources such as Kubernetes clusters, databases, and more. The new Okta Privileged Access product will join Okta Advanced Server Access as part of our Privileged Access product portfolio. Customers will be able to pay more to upgrade from Advanced Server Access to Okta Privileged Access to avail of our full suite of Privileged Access capabilities.
With Privileged Access, customers will have access to enriched functionality like SSH and RDP session capture, attribute-based access controls, and new resource types, including databases and containers. When it comes to Okta Identity Governance, we are reimagining identity governance for a cloud-first world, where the number of resources accessed by an organization's workforce has dramatically increased, and the workforce itself has transformed. It's not just traditional employees. It's contractors, it's partners, and all of those unique user types that need access to the right resources and the right governance to succeed. Okta Identity Governance will make an organization more secure and more efficient by giving it self-service access via popular tools like Slack to its most common resources and apps, while still providing the right amount of approval for more sensitive apps, data, and tools.
All of this will be underpinned by customizable and automated business workflows that keep your teams working on pushing the business forward. The new Okta Identity Governance will join our Lifecycle Management products as part of our governance product portfolio. Customers will be able to pay more to upgrade from their investment in Lifecycle Management or Advanced Lifecycle Management to Identity Governance and will benefit from new functionality including access requests and certification and enriched reporting capabilities. Extensibility of our platform is our second pillar, and it is a really important pillar to allow our customers to be able to solve all their use cases on top of Okta. In addition to building the correct APIs, a key thing that defines extensibility of a platform is the developer experience on top of the platform.
How can developers quickly and easily build their apps, their integrations, their use cases using the Okta platform and on top of the Okta platform? That is why over the last year, we've put a tremendous amount of effort in reimagining the Okta Developer Platform and the Okta developer experience to speed up time to production for developers. We have launched new SDKs, new sample apps, new guides, and new best practices for developers. We built a guided developer onboarding flow as well as step-by-step instructions for developers to get their apps and their integrations up and running. We've also invested in enhanced developer support across key developer communities like GitHub, Stack Overflow, et cetera, and ensured coverage for every language and every geography.
We are also adding to our existing library of open source tools with tools that make it much simpler for developers to use Okta with popular app platforms. For example, Heroku and API Gateways, for example, Kong. All these changes were made available to developers a few weeks ago, and the feedback from them has been overwhelmingly positive. Finally, you all have heard the big news about Auth0 and heard Todd and Eugenio's conversation. This is very exciting for all of us. The combination of Okta and Auth0 allows us to provide customer identity solutions for developers and organizations of all types, and it accelerates our penetration of the $30 billion TAM for the CIAM market. Additionally, we share the same vision and the same values, and how we operate is tightly aligned. We are going to maintain and invest in both platforms indefinitely.
In the background, we'll be integrating our technologies over time to provide even more innovation. Finally, the third core pillar of our platform is integrations. As I discussed earlier with my CrossFit example, getting a customer experience up and running requires bringing together multiple different tools and technologies in the customer experience stack, like marketing tech stacks, commerce tech stacks, analytic tech stacks, and more. This is extremely hard and time-consuming, but it is very important for organizations to do well to build a seamless end-to-end experience for their customers. To solve this pain, we are deepening the Okta Integration Network for customer identity with purpose-built customer identity integrations across 40+ partners from multiple different categories: social login, marketing, e-commerce, CRM, and data and analytics platforms, and many more.
While doing this, we are adopting a best-of-breed approach that will allow organizations that use Okta to choose the technologies that are best suited for them. One additional key component of the customer experience is technology to assess risk, respond to fraud, and mitigate the risk of account takeover attacks. After all, users and their credentials are soft targets for threat actors. The solutions customers use to safeguard the customer experience are fragmented and often very difficult to implement with an in-place identity solution. Bringing web application firewalls, bot detection capabilities, and fraud solutions together with identity is far harder than it needs to be until now. We took our customers' feedback and are launching our Risk Ecosystem API to ingest third-party signals into our risk engine. We are launching this capability in early access, along with deep integrations with leading providers like Fastly, F5, and more.
Now our customers can get a unified view of the security posture of their users across a wide range of risk categories. Last year, we launched our no-code workflows platform service to help with the orchestration of business processes for our workforce customers. Earlier today, we announced the general availability of Workflows for Customer Identity. This will unlock new and valuable use cases throughout the B2B and B2C customer identity lifecycle. During customer registration and identity creation, organizations can easily automate an ID proofing flow for their B2C customers and accomplish identity verification through one of our partners, like Evident ID. This will allow a higher level of assurance, but at the same time, will allow a frictionless registration experience.
With workflows, organizations can now automate the sync of customer identities into their marketing, CRM, and analytics stack to ensure a 360-degree view of the customer without needing to write custom integration code. Customers can also simplify administrative operations like notification, reporting, and privacy and data deletion requests through workflows. This reduces the volume of tickets, error-prone manual work, and custom code and frees up resources to be employed in more strategic business areas. Providing pre-integrated no-code experiences to power these critical customer experience flows is extremely valuable to our customers. The feedback from the early access of our product has been resoundingly positive. As excited as I am about what we've talked about this morning, it's worth recognizing the groundwork we've laid at Okta for future innovation.
Our focus on having a unified, extensible, and integrated platform goes beyond just the ability of our customers and partners to customize and extend us. Today, we have partners that are building businesses from the ground up on the Okta platform. Productiv is a great example of this. They have leveraged an identity part foundation delivered through the Okta platform to build an enterprise SaaS management platform. This is just the beginning. We see a future with a robust ecosystem of third-party products that need identity and are built directly on top of the Okta platform.
These different categories of third-party apps will further drive the flywheel effect for Okta. It will provide our customers even more value through the Okta platform. We are in the midst of very exciting times to experience the next technology revolution, shaping the future of every organization. Identity is at the center of this. Thank you for joining me today, and I look forward to sharing more as we continue on this exciting journey for Okta. Now I'd like to pass it over to Freddy for our first customer conversation.
[Presentation]
All right. Well, thank you all very much for joining us. I am thrilled to be here this morning with our first guest, and that is H \arry Moseley, the Global CIO of Zoom. Zoom, for those of you who might have been living under a rock for the last year, is a Global 2000 video communication company that has obviously experienced explosive growth. Harry, welcome. I am thrilled to have you here. Thank you very much for joining us today.
Yeah, Freddy, thrilled to be here, and it's been a hell of a year. As we were just saying in the preamble, great vaccinations are here and there's light at the end of the tunnel. We just don't know how long the tunnel is.
I can't wait to get out of the tunnel. Let's start a little bit just with a quick overview. Tell us a little bit more about yourself and about Zoom and about all the transformation that you've brought there in your time at Zoom.
Yeah. It's been a hell of a journey. I joined Zoom a little over three years ago after a terrific career working as a CIO for KPMG, the U.S. firm Blackstone, Credit Suisse, and UBS. I joined Zoom three years ago. We were 800 people, now we're north of 4,000 people. We're processing in excess of 3 trillion annualized meeting minutes a year. We're hosting over 300 million daily meeting participants and maintaining our net promoter score, customer satisfaction, and service levels. It's truly, the way I characterize it is . It's testimony, if you will, of the architecture that our founder and CEO put in when he built Zoom 10 years ago, Eric Yuan, terrific guy, terrific leader, and a terrific technologist.
It's just been truly a transformative year, I think, for the planet, for enterprises around the world, every industry, every country, governments around the world, and education as well. We're now supporting 125,000 schools in 25 countries. Thrilled to be here with you, Freddy.
That's amazing. Congratulations on all that success, and thank you for all the hard work at Zoom, certainly. As the Global CIO of Zoom, you've seen what I think the understatement might be, a massive shift in technology within not only your own company, but as you said, a lot of the different organizations in the private and public sectors that Zoom supports. With the pandemic and the shift to remote work, it's brought on a completely new set of challenges for organizations of every shape and size. How do you see your role as CIO changing today, and what's your vision for IT at Zoom going forward?
Yeah. Clearly, as I reflect back on the last three years, every year has been different. God knows what's in front of us.
Right.
Continuing to focus on the mission and the vision that we established, that Eric established when he founded Zoom, which is our mission is all about empowering people to do more. That's not quote more meetings. That's empowering people to do more, whether it's bankers to help their clients, whether it's professional services to help their clients, medical practitioners to help their patients. It's all about the consequences of helping all those people that they can accomplish more. Our vision is clearly about making that virtual event, that virtual experience, as good, if not better, than the in-person event. We've been very focused on that, obviously, and continuing to focus on that.
When you think about, and I'm sure you're thinking about this at Okta, when you think about artificial intelligence and IoT and ML and AR and VR and 5G, all these things, we're only just barely scratching the surface of what they can do, and I think that in this new hybrid model that we believe, and many other organizations and surveys have clearly indicated as well, is, quote, "here to stay." I think that we're in for a very exciting technological future, to be honest.
Yeah, absolutely. Well, that's great. As you and I were talking about just off-camera previously, the first time you and I met was a dozen years ago, when I think it was just me and Todd and a [trick duck] in a garage.
I had a great PowerPoint. I had a great PowerPoint presentation.
You had a great PowerPoint. I think the quote for those of you who are going to be watching this was, when I walked out of the room, Harry said that he and his colleagues said, "Well, that was a great presentation, but we don't know what Frederic was actually talking about." I'm glad to know that we've made a little bit of progress over the last 12 years. Finally, you and I have had a chance to start working together two years ago, when Zoom first became a customer of ours. Tell me a little bit about how identity fits into your technology strategy, and then when you initially looked for an identity solution after you got your feet set at Zoom, what ultimately made you select Okta?
Yeah. Clearly, identity and access management has been a key topic since time began in the technology world, right?
Yeah.
Because it's fundamental, is that people should have access to data and access to the tools that they need to get their job done. As people join an organization, they mature in the organization, their roles change in the organization, the portfolio of applications change in the organization. It's fine when you're 10 people in a room, but when you're thousands of people spread across all continents, spread across all geographies, and people are moving and joining the firm, you really need a sophisticated solution like Okta to actually manage it. You think about the different devices we've got and the different operating systems that we've got. There's lots of choices out there, but Okta really, there's a phrase they say about Zoom, Freddy, and you know this too. Zoom, it just works. Okta, it just works. It's like, use it a dozen times a day. It's fantastic.
That's great. Well, yeah, no, I greatly appreciate that. I know that you have very much that modern approach to application and infrastructure portfolio, and obviously have such a broad swath of employees and contractors. It's been great getting to work with you guys as you've been deploying the Okta service. Obviously, you started just with some enterprise identity management around for your employees, but now you're starting to do some automation through Okta Workflows and things like this. As you started your journey with Okta's Workforce products, now you've recently expanded to some of our newer products. Advanced Server Access is one of those. Why did you select Okta for securing your identity infrastructure? How do you think about that? What value do you see in using a unified platform like Okta across multiple different use cases?
As we said right before, we were using for identity and access management for our employees, and so it was just a natural progression to sort of pull it into our server infrastructure. We went from early days, hundreds to thousands, and then now tens of thousands of servers running in 19 colos around the world.
Right.
Then you have more engineers, and you've got more DevOps resources, et cetera. Sort of, quote, "Managing this is extraordinarily complex." It started with sort of manually setting up some rules, replication of those rules. That got us so far. Then we went to LDAP. One of the most important things that we've all always said about security, is it's the trust and verify, right? The security officer establishes the rules of the road, and gives it out, and then verifies that the rules are being followed. With identity and access management, you now have a complete separation, right? Because you've got the onboarding with the profiles, you set up the profiles, you set up the access for those profiles. That's done by one group.
You've got a second group who are administering the profiles, and now you've got a third group who are enforcing the profiles. You've got all these separations. On top of that, you've got sort of the fact that if somebody does log on to a server, without going through the process, without going through the normal protocols, we get alerted, and that's super awesome, and you can create a ticket and document why they had to do that. Absolutely natural extension. It's like having one common platform. It's similar to Zoom, right? It's like, you do this all the time. You do one-on-one meetings, you do group meetings, you do large meetings, you do webinars with your employer. It's just easy, right? It's like, and you get used to how it works.
Yeah. Not only that, I love it when you guys bring out new features and functions. Sometimes I'm not the first to figure them out. I remember when you brought out the blurred background some weeks ago, and I got on a number of meetings, and people had this blurred background. I couldn't find it for the life of me in the settings. I actually had to call our CMO. He's like, "Do you have the latest version?" Of course I didn't. All the innovation that's coming in the Zoom platform is fantastic.
I personally really enjoyed also watching Zoom's incredible growth this past year. I've been fortunate to get to know Eric, the Founder and CEO, a little bit over the years. What you guys are doing is phenomenal, and I'm really excited to see what's coming next for your company. How do you think about the future of identity for Zoom, and what is next for you as you think about that infrastructure and security roadmap?
Yeah. As I said, identity is critical. Sort of security is critical, making sure that only the right people have access to their data and the solutions. We're going to continue this program that we've been on in the future as we have in the past. It's hard to sort of predict the future. If we go back 18 months ago, I remember January of 2020 being on a flight back from Zurich after Davos and reading the newspaper about COVID-19, and then like six weeks later, we shut the offices down, and then seven weeks later it's hard to predict what's coming next. Clearly, we are hopeful for more continued growth at Zoom. We work, as you know, in dealing with Amazon and Oracle.
Yeah.
I expect that we'll see more experiences in that vein.
That's awesome. Well, look, Harry, thank you very much, as always, for taking time out of your busy schedule to chat with us. I really enjoyed the conversation and appreciated the story. Of course, we appreciate your insight and look forward to more partnership in the future going forward with Zoom and Okta.
Thank you for joining us today. For those of you who don't know me, I'm Susan St. Ledger, President of Worldwide Field Operations at Okta. I've been in tech my entire career, starting as a computer scientist at the National Security Agency, and then embarking on three incredible high growth journeys. Joining Sun Microsystems when it was $1 billion, going to $22 billion. Salesforce at a little over $100 million to $8.5 billion. Most recently at Splunk, from $675 million to $2.35 billion. I am a self-proclaimed high growth junkie, and I can't imagine being at a company that was anything but high growth. Leading me to why I joined Okta. Todd and I spent a lot of time talking about the market opportunity. I definitely bought in to his vision of identity as a primary cloud. He made me think about identity differently. Think about your day.
Whether you're consuming information, streaming a video, executing a wire transfer, or simply trying to access your corporate applications and data. You expect every single one of those interactions to be on demand and tailored to you. Todd and Freddy recognized that identity was at the core of every interaction between people and technology, which makes this a very large market that will continue to grow. Add to that the tailwinds of the three mega trends that we're seeing, cloud and hybrid IT, digital transformation, and security. Now you've got a mega market, one that I cannot wait to pursue. Customer centricity is equally as important. Okta definitely embraces this principle through our core value of love our customers. I'll be speaking more about that in just a little bit in my FY 2022 go-to-market strategy.
Lastly, I feel very privileged to be asked to lead another high growth journey at a company as amazing as Okta. Okta's growth over the past few years has been very impressive, growing revenue to $835 million in FY 2021, with a 40% CAGR over the last three years. It's really just the beginning. As Todd explained earlier, in a cloud-centric world, identity has become an even more strategic choice than infrastructure or collaboration clouds. It's at the epicenter of an organization's tech connections and offers freedom of choice to adopt any technology. Understanding our customers will help you understand why identity has emerged as a primary cloud. Throughout my presentation today, I will highlight the agility, time to value, and the flexibility experienced by our customers who have centralized their identity framework on the Okta Identity Cloud.
One of the keys to being a primary cloud is the extensibility of our identity platform. As you heard from Diya earlier today, our platform continually unlocks new opportunities for both workforce and customer identity. Customer identity is the fastest growing part of our business, even prior to joining forces with Auth0. In my personal opinion, customer identity market may be underestimated at $30 billion because it's not well understood. Workforce is much better understood because the population of knowledge workers is understood, and it's a market replacement. If you think about customer identity, every human being can have many customer identities. Think about how many different digital services you're subscribed to as a customer. Add to that the fact that it is a market creation opportunity because most companies have no idea how much money they've spent over the years cobbling together customer identity solutions in many different ways.
With the explosion of the digital economy and the demand for digital experiences, they are now searching for more secure, standardized, and scalable solutions with a faster time to value. Customer identity solutions have a huge role to play in determining which companies survive and thrive in this new reality. Joining forces with Auth0 will further our ability to address even more use cases for customer identity, making our platform even more extensible with their developer-led approach. The Auth0 developer-led approach is very complementary to the Okta approach. Shift left has been driven by the explosion of native cloud microservices, and with the advent of ephemeral resources, it's critical for developers to build their applications with core services like identity and security. In addition to great technology, Auth0 has long mastered the art of remote work, which will be greatly complementary to Okta's pioneering of the dynamic work environment.
Lastly, I'm super excited about the international traction that Auth0 brings to the table. 40% of Auth0's revenue comes from international markets. There are many synergies with Auth0 and Okta's overall go-to-market strategy. The go-to-market strategy for FY 2022 is very straightforward. We're going to continue to build on the success to date, which makes a ton of sense because we're only 2% penetrated in workforce and 1% penetrated in customer identity. The foundation of our go-to-market strategy is definitely customer success. I learned in 2004 at Salesforce that high growth software as a service starts with anchoring on customer success. Okta anchored on customers from day one. Love our customers is in the Okta DNA. When new customers buy Okta, they're taking the first step in their roadmap to modernize their infrastructure.
We ensure that first step is fast and high value, and then we continue to build wins with them along their roadmap as they expand with us. From that anchor on our customers, our strategy then focuses on three key pillars, new logo acquisition, expanding with existing customers, and international growth. Lastly, I'm excited about the innovations announced by the product team, allowing us to enter into adjacent markets like PAM and IGA, which will continue to increase our TAM. As you know, capturing a large TAM is about having technology that everyone needs. I experienced this during my time at both Splunk and Salesforce, and it's very clear to me that everyone needs Okta. Looking at the breadth of Okta customers and the use cases is demonstrable proof that everyone needs Okta. Let's take a look.
I was impressed to see the team convert so many great new logos in FY 2021, over 2,000, despite the COVID-19 headwinds. We added incredible new logos like LVMH and Equifax as workforce customers, Alaska Airlines and Crate and Barrel as customer identity, and State of Iowa and Parsons as Okta Access Gateway customers. Landing new logos is critical to our success because they become expansion opportunities for years to come. Speaking of expansion, FY 2021 did not disappoint. This is where love our customers really comes into play, as evidenced by our strong net retention rates, 121% as of Q4. Customer success leads to expansion. You heard earlier from Freddy and Harry about the critical role that Okta played in Zoom's explosive growth, which led to an incredible expansion opportunity for Okta. Even more impressive is the breadth of customers that have landed and expanded with Okta.
We land and expand with legacy companies and digital natives alike. For example, 188-year-old McKesson is a great example of a mature company that needed to modernize. They were at the bleeding edge of understanding the value of a unified identity framework for their employees, suppliers, and customers. This unified identity framework allowed them to quickly adapt to the needs of the remote workforce, while at the same time securing McKesson's SupplyM anager platform to take the hassle out of medical supply ordering for customers like CVS and Walmart. Remote workforce and B2B supply chain are very common use cases we solve with Okta. Let's take a look at a digital native company, Kiwi.com, which is a European travel website. They have experienced rapid growth with greater than 3,000 employees, millions of users, and billions of searches.
Their customer service employees were experiencing tremendous friction trying to get access to a variety of apps in order to do their jobs. Kiwi.com selected Okta as a critical part of their zero trust strategy to securely and seamlessly access the technology needed for the employees to do their jobs more quickly, improving annual productivity by over 6,700 hours. Streamlining customer care is a common use case with Okta. Our land and expand motion includes SMB, enterprise, and Global 2000 customers alike. GitLab is an incredibly successful SMB customer. They have had a remote work strategy from their inception, and there are over 1,300 employees today across 67 countries.
They embarked on an eight-month journey with Okta to secure more than 120 cloud apps as a critical part of their Zero Trust strategy to allow their employees to work wherever and however they want it. Trusting Okta led to a 90% reduction in identity compliance costs and 35% reduction in employee onboarding. Shifting to look at the Global 2000, we have tremendous upside. We are only 25% penetrated in a cohort that delivers 6x the company average ACV. Let me share a couple of examples of our success within the Global 2000. T-Mobile initially deployed Okta to one of the largest retail fleets in any industry, simplifying access to retail point-of-sale applications for tens of thousands of employees. Next, T-Mobile put Okta at the center of their customer experience strategy. With over 200,000 customer-facing T-Mobile representatives, they needed to streamline their customer care process.
They needed to eliminate the need for their representatives to toggle between applications with separate login credentials, which was creating friction for employees and customers alike. Given the success in retail and customer experience, it was no surprise that T-Mobile then called on Okta to help them with their merger with Sprint, to onboard 30,000 employees to ensure success day one. FedEx is another great example. FedEx relies on Okta as a critical part of their Zero Trust strategy to quickly and securely deploy applications to its workforce of over 500,000. In early 2020, Okta helped FedEx deploy five critical cloud applications in 36 hours to enable their essential workers to deliver during the pandemic. FedEx quickly expanded and now has well over 350 SaaS applications with Okta, and many, many more to come. Our land and expand motion clearly spans all verticals.
Another great example is a healthcare tech company called athenahealth. Athena called on Okta to help them provide secure, cohesive, personalized patient experiences across 8,000 patient portals and 4 million patient accounts. Not to mention over 160,000 providers. Protecting patient data was a top priority, so they leveraged Okta's HIPAA Compliant Cell to meet those requirements. Once they had the strong identity foundation in place, they were quickly able to launch a telehealth solution in response to COVID-19. Like so many other customers, athenahealth recognized that once that strong identity foundation is in place, it frees them to focus on key innovations that improve the health of patients and productivity of its providers. As you can see, we have landed and expanded in legacy and digital natives, SMB and enterprise, across all verticals, and the Global 2000.
Since expansion is such a big growth lever for us, I want to share a few customer examples that show the various journeys that customers have taken with Okta on their expansion route. Thus far, we've covered customers in a wide range of industries, but I would be remiss if I didn't talk about public sector. This is a state agency who landed with us with a $1 million opportunity and expanded to $4.6 million, all in the span of one year. Despite COVID-19, they realized that they must continue to serve their millions of residents with a remote workforce. They replaced their custom-built identity system with Okta Workforce and Okta Customer Identity in order to secure access for 8,000 employees and millions of residents. The continued expansion came from onboarding contractors, additional employees, and additional digital services for their residents.
Next up, identity proofing fraud prevention for COVID-19 loans and unemployment benefits, which is a use case we've solved for several other state agencies already. Remote workers and digital citizen services became an imperative for many federal, state, and local agencies. Add the SolarWinds crisis to that, you have the perfect storm for agency modernization. The second customer journey I'll share with you today is a Global 2000 tech company with a lifetime value spend of $17 million. They're a highly acquisitive company focused on optimizing for M&A agility. They called on Okta to provide a single source of identity for all SaaS applications. They started with Okta in FY 2013 to secure its workforce, through continuous M&A, they expanded on both Workforce and Customer Identity.
They had three criteria: day one access, reducing IT burden, and providing seamless experience for end users for both workforce applications and B2B portals. The modernization journey for this customer continues. They're constantly looking at new ways to enhance the digital experience for their customers. M&A agility is a highly repeatable use case for Okta. It's clear that everyone needs Okta, regardless of their size, age, or industry. Now that I've covered customer success and our land and expand motions, let me touch on international expansion. We currently operate in 60 countries, but of course, we've tiered our markets to guide our investments and our route to market choices. For example, U.K., France, Germany, Japan, and ANZ are key international markets for us.
We've made investments in employees, real estate, marketing, and partnerships, a complete support infrastructure. However, the demand outside of our top markets is indicative of the broad-based horizontal opportunity that exists. We serve those other markets through partners. They're made up of regional resellers, distributors, and integrators. We're also investing in global distribution partners. For example, we recently launched our global partnership with AWS Marketplace to drive increased awareness and lead generation and accelerate the deal velocity from SMB to enterprise. While we're investing to expand our international market reach, we're also investing to ensure we can effectively serve our large global customers. As an elite AWS technology partner, Okta is now able to co-sell with AWS' over 9,000 sales reps to the Global 2000.
AWS recognizes Okta as an identity leader with an expansive application integration network and our ability to quickly and securely migrate on-prem workloads to the cloud. Okta's product leadership position and our partnership enables AWS to differentiate themselves in the marketplace versus other public cloud service providers. In addition, we continue to invest in our growing Global Systems Integrators network. We recognize that they are at the center of digital transformations for so many of our customers. PwC, Deloitte, and Accenture have all accelerated their Okta practices this year, all with high double-digit growth. We're seeing these investments pay off at mutual customers, including those shown here, and we're still in the early days. Of course, none of what I've talked about is possible without a great team. The key to my success my entire career has been hiring and developing exceptional talent.
I'm excited to share that we recently hired two exceptional leaders who have deep experience in driving revenue and brand growth. I've been fortunate enough to work with both of these leaders in prior companies. Steve Rowland, our new CRO, brings 20+ years of experience joining us from Splunk. Steve is not only an exceptional sales leader, but he's a business leader who brings operational excellence with a deep commitment to customer success. I'm confident he will help us accelerate our penetration into the growing identity market. Kendall Collins is our new CMO. He's a two-time CMO from Salesforce and AppD, where he led the cloud computing rebrand, the transition to multi-product, and global expansion. With the acquisition of Auth0 pending, Kendall's well-positioned to help Okta win the hearts and minds of developers and CXOs alike.
In addition, both Steve and Kendall are experienced global leaders who will accelerate our growth in global markets. I'm thrilled with the caliber of talent we're attracting and the strength of our existing Okta team. Okta is a destination company. With that, let's bring it back to my key priorities for this fiscal year. In closing, I'm very bullish on the opportunity that we have at Okta. The three mega trends I mentioned earlier, cloud and hybrid IT, digital transformation, and security, are definitely tailwinds. While we're all hopeful that the pandemic is nearing the end, the way in which companies work and how they serve their customers has changed forever.
These mega trends will continue at an accelerated pace. I am excited about the team and the opportunity to lead another high-growth journey at a company as amazing as Okta. I look forward to working with so many of you once again and meeting those of you that I haven't engaged with in my past. Thank you again for your time today. Now I'd like to pass it back to Freddy for another great customer conversation.
Well, thank you very much, Paul, for being here. We're thrilled to have you. Obviously, Fox is a Fortune 500 news, sports, entertainment company. Tell us a little bit more about the company and about your role and how both of those have changed over the past few years.
Well, Freddy, firstly, thank you. It's always a pleasure chatting to you and the Okta team. Our relationship with Okta goes back quite a long way, but I think the kind of concurrent theme with working with Okta has been transformation and media as an environment and being a technologist inside a media company throughout my career has been very focused on driving transformation, initially in the enterprise, which is where a lot of the disruption occurred with cloud computing and the shift towards software as a service and cloud-based platforms, and we were very early adopters of Okta during that time.
More recently, obviously very focused on direct to consumer and really making sure that our digital services and our content reach consumers however they want to receive the service itself. Streaming is a kind of key growth area for us, and we've really started to evolve the relationship with Okta into that space as well.
Yeah. That's great. As you mentioned, Fox has been a long time customer of Okta's. I still remember the breakfast that you and Todd and I had many years ago in San Francisco, and you kind of looked us both in the eye and said, "Are you guys for real? And is this thing serious?" You took a big gamble on us, and I'm glad that it paid off. Your first foray with Okta was obviously to help secure your workforce, so employees, contractors, consultants, partners. How does Okta help support Fox's zero trust strategy?
Well, the initial relationship and the problem we were trying to solve when we had that breakfast, Freddy, was really reducing friction for the employee. As we were deploying these cloud-based tools, authentication into those tools was complex, and you brought that solution to the market around Single Sign-On and just reduced that friction. It made the employee's life much, much easier and better, especially on a Monday morning when they came into work to log in. That evolved pretty quickly, and I think we see you as a highly strategic partner now on the security aspect of our business. You're on the front line of defense. You see a lot of activity, not just through our own business, but through all the businesses that you support, and you can give us a really strong aspect of security.
You've really facilitated the Zero Trust model that we've moved towards, and moved away from that hardline perimeter on the edge into something that's strength in depth around all of the platforms. I think without Okta, we just couldn't have done that, and done it in a way where employee satisfaction and the friction that the employees experience is minimal. Which again, you've got to balance those two things together. We're very, very forward-leaning on Zero Trust. We have been for a number of years. Our security team have been working closely with Okta to evolve that, and we've been very, very pleased with the platform.
That's great. I know that most recently, as Fox Corporation has spun off as an independent company, it also gave you an opportunity to rethink your infrastructure and how you reimagine building a company, frankly, without Active Directory at the core, right?
Well, we did this big transaction with Disney two years ago, almost to the day, actually, Freddy, we closed it. A big decision that we had when we spun the current Fox company out of that transaction was to leave our legacy systems behind. We were fairly aggressive on that front. Part of what we left behind was AD alongside our financial systems, a lot of the old, horrible client-server legacy.
I can sit here now today, and we've completed the projects where we've stood up a lot of greenfield applications with cloud partners, and we are now truly zero legacy and getting rid of AD has been a big part of that. We've managed to clean up the architecture for the enterprise through that. Again, just going back to the security point, security's really been a central part of the consideration there. We're in a very strong place now, Freddy.
Yeah, that's great. Switching from the workforce side, you also recently purchased Okta for customer identity. How is Okta supporting your customer identity needs, and why did you decide to replace the homegrown solution that you previously had with Okta for the go-forward strategy?
Well, again, this is a conversation, Freddy, you and I and Todd have had for a while. I think there's been a big opportunity here. The piecemeal solutions that have been out there on the consumer side are scalable, but they've not really been industrial-grade. Given that identity is your business, we feel, again, not just that we're buying a solution from you, but we're in a partnership with you. There's a lot of road to run around features, functions, and really the power of the platform on the consumer side, taking what you've learned on the enterprise side and applying it, but also putting additional building blocks and things like the Auth0 transaction that you're in the midst of at the moment are a big signal of intent to customers like us that you're serious about the consumer side.
We made the commitment a few months ago, as you know, Freddy, to work with you on that front. Just to give you some highlights of the sorts of things we're looking at doing. If any of you have tried to log in on your TV screens into the streaming product, you know it's a painful process. We're working with Okta to really make that a lot simpler whilst retaining security as part of that. Then across all of our Fox products, having one single platform at the center of it so our consumers can seamlessly move, not just between products, but between devices.
From an engineering point of view, this stuff is not that simple or easy. Unlike the enterprise where you can control a lot of the variables, the consumer landscape is a lot more mixed. We're excited about the partnership. We're at the beginning of it, but a lot of the power of what we see on the enterprise side is already delivering value on the consumer side, Freddy.
Yeah, that's great. We thank you very much for the partnership over the years. As you mentioned, certainly, you had a big impact and say on our product roadmap as we think about the customer's perspective and getting that feedback. I know that some of the things that is top of mind for you is not just security, but also performance, reliability, resiliency, throughput. You have these big bursting events that were top of mind as well. I'm glad that we were able to work with you on that. As this audience has heard throughout the day, we believe obviously that identity is becoming a primary cloud, and identity facilitates choice and flexibility, which you just talked about, while also enhancing security, which is important for all of our customers. What does choice and flexibility really mean to you as you think about it at Fox, Paul?
There's a couple of angles to that, Freddy. If you think about our employees, really treating them as consumers of technology. Best of breed is something that we've been very, very forward-leaning on. We've never really, as we've evolved into the cloud, thought about single-vendor solutions across the piece. We've gone very, very deep with individual partners and brought those together. A really simple example is we use Slack for collaboration, we use Office 365 for email, we use Box for file management, we use Zoom for video conferencing, and so on. Okta's that umbrella that brings that together into a cohesive experience. Without Okta, frankly, that would have been a very piecemeal experience.
As a purchaser of technology, Okta allows that flexibility to really plug those solutions together and to give employees that single starting point in a secure but also a usable way to do their work. Identity is at the center of that, and it carries into those apps and those products in a really coherent way. I think, again, it's the tip of the iceberg around what you're doing on the identity side, but there's a huge amount of potential that we see, especially in the workplace with Okta at the center of that. Security's one piece, but I really do think analytics, the whole breadth of things that I think you're placed incredibly well to evolve into.
Let's touch on that very quickly to wrap up our conversation here. We've talked a lot today about some of the value that we've been fortunate to help you with at Fox through the years, first on the workforce side, now most recently on the customer identity side. Let's talk also about the future, and how you're thinking about the future of identity for Fox. You mentioned a couple of things there around security, around continuous improvement for the identity experience, and around frontline positioning in your ecosystem for employees. What are some of the other things that are top of mind and what are you looking forward to with identity at Fox?
I'd love identity to be something that goes everywhere with you, but sits more in the background than in the foreground. If you think about a lot of the payments and e-commerce systems on the web at the moment, think about Affirm or Stripe or companies like that. They're able to take a lot of the friction around purchasing out of that purchasing process, but at a very high level of security in the background. I truly think that the evolution of Okta, it can be much more of a background process from an identity point of view, where it goes everywhere with you without interfering in the user experience.
For us, both on the consumer side and on the employee side, that's a win-win, because if you take the friction out of that experience on the front, which Okta have done a great job around already, I think there's a lot of technology evolutions with how you use data, how you use predictive, a lot of your product team are already looking at this, but how you use predictive analytics on understanding whether someone has the right to access a product or an app as a background process, and there's a huge amount of opportunity there whilst maintaining that security aspect of what you do.
Yeah. That's great. Well, Paul, thank you very much for the partnership over the years with Fox. We greatly appreciate it. Thank you very much for taking time out of your busy schedule to chat with us today. I know that this has been very insightful for me and probably for a lot of the audience. Thank you for taking time, and it's great to see you as always.
Thanks, Freddy. I appreciate the time.
You know something? The energy transition is underway. Better yet, it's gaining momentum. Because energy is one of its main levers, ENGIE decided to take its full place in this energy transition. Not just to be one player amongst others, but to become a world leader. To accompany this revolution and to respond better to our customers' demands, ENGIE has decided to refocus its activities on renewable energies, on ever greener gas, and on infrastructure. Today and more than ever, ENGIE is committed to an ambitious and solid strategy that resonates with the aspirations of society, and which, above all, makes us proud of what we accomplish every day.
Claude, it is great to see you. Thanks a lot for being here today. How are you?
I'm fine. Great to see you as well.
Great. I can't wait to come and see you in person sometime soon. This year, as promised. I'm very excited, everyone, to be joined here by Claude Pierre, the Deputy CIO of ENGIE. ENGIE is a Global 500 energy and services company. They have over 170,000 employees around the world. Claude, perhaps you can just start by telling us a little bit about the company and about your role there.
Yes, you're right. ENGIE is a world energy player and a world leader in the energy transition. ENGIE is a big group, more than 170,000 employees, as you mentioned. We operate 24 business units in 70 countries. ENGIE is focusing its strategy on renewables, networks, and customer solutions. I've been the Deputy CIO at ENGIE for over five years. In my role, I'm responsible for what we call the digital foundations, and I'm responsible for cybersecurity as well.
That's great. As the Deputy CIO of ENGIE, you've seen tremendous growth in the past few years across all the different business units. With so many users across the globe, what is your approach to technology and that digital foundation as you talked about? How do you think about that and what does that mean at ENGIE?
What does that mean? Over the past few years, we have been very focused on leveraging technology to transform the group, which is a very large group with a long history, introducing new ways of working based on digital tools. We have been moving from a siloed organization with a very fragmented IT landscape to a global distributed organization sharing common tools. To achieve this, to achieve this transformation at scale, we have chosen to build brand-new digital foundations on top of the legacy systems, and to make the new common tools available to the whole group through this digital foundation. As we further develop the common tools, the legacy ones locally got redundant and then decommissioned. The key component in this transformation is our digital foundations. It's key for addressing our needs, and it's key also for the future.
They have been built on the cloud, on the cloud only. It's a cloud-only solution, it combines various transversal services, serving the whole group in all geographies, as we say, from Santiago to Shanghai. It delivers network services, security services, and of course, identity and access services, which enable any users from any business units, whatever the location is, whatever the underlying technology is, to access the common tools from anywhere with any device with a consistent and secure user experience. This is the way we approach the transformation of the group through the technology.
That's fantastic. I love it. That's almost like a perfect Okta customer proposition. It works out great. You've been a customer for almost five years now. I was thinking back to the first times that I got to come to Paris, and meet you and spend time with you and your team. What initial challenges were you looking for when you thought about an identity solution, right? You didn't go out and you said, "Well, we're just looking to find identity." You had specific ideas of what kind of solution and how you were going to do that. I remember that very well. What were some of the key criteria that went into your decision when you decided to partner with Okta, beyond just being able to work with me, of course? What were some of the other key decisions that you had there?
Yeah. It was five years ago, we started our journey. We started our journey with Office 365. Our key challenge was to deliver to our 24 business units a consistent and reliable global solution. Office 365 being the most emblematic, of course. We had, at that time, a double challenge, I would say, because on one hand, the IT landscape was very fragmented, very diverse. We had no control over it. On the other hand, the leadership team gave us six months to deploy a global collaboration platform across all the geographies. We had to make sure that the solution would be accessible by our users from any site, whatever the local infrastructure is, Microsoft-based or not, connected to the corporate network or not. It has to work.
This relates directly to the other challenge that we had about identity and access management, how to make the system accessible from any users in a secure way with a great user experience, and make it accessible to any employee, whatever business unit he works for. Of course, as we are global, around the globe, it has to be reliable 24 hours a day, seven days a week. It has to be always on, and it has to be secure, of course. These are the key challenges we were facing at that time, and this is why we looked at an identity and access management tool. We looked at Okta, and I would say that Okta met some key success factors that we were looking at that time.
The first one was to be a neutral or independent platform, which means able to connect to any technology and to be a kind of agnostic platform as our landscape was very diverse. The second important point was the customer centricity of the team, because we had some specific challenges to integrate various environment. We needed Okta to develop some additional features and the Okta team and the Okta management team, you, Frederic, and the support team were very efficient in delivering those functionalities on due time to allow us to go live at the plan date. The last important key element that we are looking at was the ability of the system to work 24 hours a day, seven days a week, to be always on, as mentioned.
We started with Office 365, but we had to deploy the solution across the whole application portfolio. Here we are talking about 600+ application with some critical business apps. This is why we found with Okta, I would say, the key partner to help us in this journey.
Yeah. That's great. I remember it like it was yesterday. Five years have gone very quickly. I'm glad that we got started that way, and I'm glad that the partnership has gone so well over the years. You began the journey, obviously, as you just mentioned, with Okta for ENGIE's workforce. Really thinking about those 160,000, now 170,000 users. I think we tried to deploy 600 applications to get going, which went very well. Then now you're starting to expand from the employee side over to the customer identity for both partners and suppliers. That was kind of the second step. Actually, just recently, you're starting to implement Okta for consumer-facing applications.
Can you describe a little bit what led you to expand your use of Okta? Obviously, you had a certain amount of success and the level of comfort and support in the product and the platform and the company. You started with your employee set, you went to suppliers and partners, and now you're obviously going to the customer-facing piece. What value have you seen from using a unified platform to address all of these multiple use cases?
Yeah, we are engaging with the next step with Okta. As you mentioned, we are now starting to expand the use of Okta to our B2C market and starting with the French market, where we are a leader there. Just to give you an idea on the magnitude of the project, we serve, in France, 11 million of customers in the B2C market. We are dealing with different type of customers, of course. There are different segments, different type of services, and each has a different digital experience today. One of our key driver to expand Okta, the first one was to unify the customer experience across all the customer portals, all the customer apps, in an efficient and secure way. It was key for the business in order to improve the customer experience.
The other challenge that we are facing was related to security. We currently have different in-house identity management systems, and this leads to security challenge, of course, as you can imagine. We needed really to improve the security in a world where the threats are bigger and bigger. In Zero Trust world, we really need to rely on a solid platform for identity and access management. After having success with Okta for the B2E, for the B2B, for us, it was very logical to go to Okta for B2C, and it was a consistent improvement.
This was a very easy decision to make. It was just extending Okta as we are very happy with what Okta has been delivered over time. As mentioned before, we have really realized that Okta is always on. It's a no-brainer, I would say. The decision was very easy to make, and we are sure that it will bring us lots of value for the customer experience and for the security.
That is great. I'm very glad to hear the success that we're continuing to have together. We're obviously very proud of our partnership with ENGIE. I thank you and the entire team for all the work that we've done over the years together. It's really been a pleasure. I'm always thrilled to hear about the different ways that we continue to be able to add value for your organization. To wrap up the conversation, we've already talked here about the B2E part, the employees, the B2B part with your partners, the B2C part with end customers, but there's even more in the future. How are you thinking about the future of identity at ENGIE? You've obviously taken such big steps over the last five years, but I know that's not the end for you. There's a lot more beyond that.
We'll make sure that the B2C project will be a success. I'm quite confident about it. It should be live in the end of this year. This is not the last step because we are in a, I would say, in an open world, where interaction are key. We have to interact with our employees, with our customers, with our partners. In this digital world, we also have to interact more and more with things, with meters, with sensors. We are considering to expand the identity and access management to all the other things we have to interact with. This could be the next step for us, machine to machine or Internet of Things. This is the next move that we are considering at ENGIE.
That's awesome. The next frontier. I love it. Well, look, Claude, thank you very much for taking time out of your busy schedule to chat with us. We greatly appreciate it. Thank you also for sharing some of the ENGIE story, which is always great to hear. We're grateful for the partnership over the years, and we look forward to many more great years working with ENGIE and Okta.
Thank you, Freddy. My pleasure.
Thank you. [Non-English content ]
Thank you, Freddy, for that terrific conversation with ENGIE. Hello, everyone. It's great to be here with you today. It's been about a month since I officially started as the CFO at Okta, and I'm more excited than ever about the growth opportunity in front of us. Before I get into business content, I thought it would be helpful to highlight some of the reasons why I'm so excited about joining Okta as CFO, which I'm sure aligns closely with why you're excited about the company as well. First, as you heard from Todd and our other executives today, identity is becoming a primary cloud. Okta is a customer-first, cloud-first platform that is helping customers, large and small, with their workforce and customer identity demands. With this strong foundation, Okta is recognized as a global leader in the space.
Second, with this backdrop, Okta has the opportunity to grow into a multi-billion dollar revenue company over the next few years. I liken joining Okta now to joining Google in 2003 or Salesforce in 2010. With the pervasive need for identity and Okta's unparalleled solution and growing customer footprint, we believe there are significant tailwinds in the business as well as numerous growth vectors. Third, the team is exceptional. I've had a unique view of the business as Okta's audit chair over the past five years, and I've now had the pleasure of working much more closely with Todd, Freddy, and the entire management team at an operational level. I'm continually impressed with not only their operational acumen, but also Okta's culture of authenticity, transparency, and the winning DNA that's at the core of this company.
I'm delighted to be joining at such an exciting time for Okta and look forward to presenting at many more investor days to come. Let's get into the core content. In my presentation today, I'll be highlighting three key points. First, Okta has built a strong foundation for growth and at scale. We've demonstrated we can execute for our customers and other stakeholders across all the key facets of the business. We're building on this foundation as we go from approximately a $1 billion revenue company this year to a multi-billion dollar revenue company over the next few years. Secondly, the markets in which we participate are huge. We have multiple growth vectors as we broaden and deepen our solutions in the identity market.
While we have a massive addressable market in front of us, we are focused on ensuring that our investments have a great financial return. As I'll elaborate upon later, the financial profile for our business is very attractive. We'll start by discussing the strong foundation we've built. Here are just a few of the company's important financial accomplishments. One, revenue grew 43% last year, reflecting the robust demand for our products and Okta's continued solid execution. Two, RPO growth is very strong, with total RPO growing 49% as we exited FY 2021. Three, our dollar-based net retention was 121% last quarter and has been above our historical range of 115%-120% for the past four quarters. Four, our non-GAAP gross margin was 78%, increasing over 100 basis points year-over-year.
Five, our free cash flow margin was just over 13%, up over 700 basis points versus last year. While our spend was lower in FY 2021 due to the pandemic, this demonstrates how much operating leverage is in our model. Finally, six, we ended FY 2021 with over 10,000 customers, with record customer growth of 600 in the fourth quarter and an increase of over 2,000 customers for the year. This is a great start and provides a strong foundation, but it's just the beginning. Before I dive into more detail regarding our business, I'd like to highlight one key metric that may be relatively new to some investors.
I know most of you are experts on RPO, but for those of you who are newer to SaaS or cloud subscription software models, I'll briefly discuss RPO and why we think it's the more meaningful metric for us when viewed alongside revenue and billings. RPO provides the most complete picture of backlog as it includes all contracted, non-cancelable customer subscription dollars, both billed and unbilled. Current RPO, the portion of RPO that will be recognized as revenue in the next 12 months, is also important. Current RPO removes the effects of billings duration and timing variances and also removes the effect of contract duration. Lastly, while there are many positive attributes of RPO, it can be impacted by the timing of renewals. For example, even when we know that a renewal is coming, if it hasn't been contracted and signed, it won't yet show up in RPO.
Nevertheless, overall, RPO and current RPO provide a more predictable and consistent view of our business. As we noted in our last earnings call, we believe that on an organic basis, excluding Auth0, current RPO growth, a key leading indicator, will outpace subscription growth throughout fiscal year 2022. Speaking of guidance, as you have seen in our press release this morning, we reiterated our Q1 and full year FY 2022 guidance. As a reminder, these numbers are organic and do not include anything from the acquisition of Auth0. We'll provide you more detail regarding the combined company's outlook in our first earnings call after the transaction closes. With that, let me discuss the second reason why I'm so excited about Okta, the large addressable markets and the multiple growth vectors that we have within them.
As you heard earlier from Todd, Freddy, Diya, and Susan, identity is becoming a primary cloud driven by the three macro trends that have been and will continue to drive our business going forward. Continued cloud adoption and hybrid IT, digital transformation, and zero trust security. These factors have only been accelerated by the pandemic and are driving Okta's massive TAM opportunity. Over the past year, we believe there's been a meaningful increase in our TAM. The workforce identity market was $30 billion last year. However, increased use cases within enterprise customers have expanded our reach to a broader segment within our target companies, resulting in our TAM increasing to $35 billion. In addition, you heard the exciting news that we're expanding into IGA and PAM, which adds another $15 billion of market opportunity for a total workforce TAM of $50 billion.
Looking at customer identity, we had previously estimated this market at $25 billion. Due to increased utilization driven by our customers' digital transformations, we estimate that the market opportunity is now $30 billion. We're also excited about the prospect of accelerating our penetration into this market with the complementary platform of Auth0, and I'll get into that a little bit later. We're looking at a massive $80 billion market opportunity, and we're just scratching the surface. We have four key growth vectors that we believe will enable us to capture this large market opportunity. Innovation in our platform and network, our land and expand model, international expansion, and our growing partner channel. Let's take a look at innovation in our platform, the network effects that it creates as customers leverage the benefits of the Okta Identity Cloud, which spans across both workforce and customer identity.
One example that highlights the value of our platform is Okta ThreatInsight. This feature aggregates data across Okta's customer base and uses this data to detect malicious IP addresses that attempt credential-based attacks. With more integrations, more customers, and more users, we're able to capture more signals and detect more malicious activity, providing greater protection for the benefit of all of our customers. Over time, this growing customer base helps Okta become the identity standard that connects all the different pieces of applications and technology together. This platform to network is one of the main drivers of the other three vectors of growth for Okta. We've been successful with the second vector of landing and expanding with our customers, which is reflected in our dollar-based net retention rate.
I mentioned earlier that the net retention rate was above our historical range of 115%-120% for the past four quarters. This strong rate is grounded in high gross retention coupled with strong upsell and expansion across our products and markets. We're very proud of this result, especially when taking the pandemic into account. With our new products and offerings, we believe we will continue to execute well on our land and expand opportunity. Our base of large customers continues to grow rapidly as well. This is a result of both our focus on landing new large enterprise customers, where the initial lands are getting bigger, and our successful expansion strategy. We now have almost 2,000 customers with an ACV of greater than $100,000. Notably, both our $500,000 and million-dollar ACV customer cohorts grew over 50% last year.
We've made great progress with large enterprise customers, and at the end of Q4, 25% of the Global 2000 were Okta customers, up from about 20% last year. Looking forward, we clearly have the opportunity to further penetrate this customer category and also expand into 25% of the Global 2000 where we're already present. As Susan highlighted earlier, with an average annual contract value for Okta's Global 2000 customers at approximately 6x our company average, further penetration of this customer category represents another significant growth opportunity for us. Susan gave you a deep dive into a couple of real customer land and expand examples. To further illustrate this point, I think it would be helpful to give another example of how our land and expand motion works.
Many of you recall this slide from prior investor days, as it's a useful illustration of how successful Okta's land and expand motion is. This chart shows our top 25 customers in order of their initial purchase date. They span a wide range of industries, from biotech and healthcare to financial services and manufacturing. The gray box shows when the initial customer purchase was made. The multiple purple boxes indicate when there was an incremental increase in ACV from the prior quarter. As you can see, there are many purple boxes. Lastly, the green box indicates the quarter in which the customer exceeded $1 million of annual contract value. The customers that we landed back in FY 2014 and FY 2015 took 12-13 quarters to reach the million-dollar milestone.
Notice that more recently, we are consistently landing customers with an ACV of greater than $1 million from the very beginning. Even after we hit these $1 million milestones, we still have significant upsell opportunities with these customers. International is the third growth vector. With 16% of our revenue coming from international locations, this represents a significant growth opportunity for us and the reason it's a key focus area. Here's a perfect example of how big the opportunity is. I mentioned earlier that we count about 25% of the Global 2000 as customers. Of those roughly 500 customers, 61% of them are located in the Americas, while only 35% of all companies in the Global 2000 are located in the Americas. Conversely, just under 20% of our Global 2000 customer base is in the Asia-Pacific region, while 40% of the Global 2000 are there.
In key markets such as the U.K., France, Germany, Japan, and Australia, New Zealand, we will continue to invest in expanding our direct go-to-market motion. In other regions, we'll partner with resellers, distributors, and integrators to expand our reach. As we invest more in these international regions, we expect our extended global reach to be yet another growth tailwind. Our partner ecosystem is our fourth growth vector. Today, we operate in 60 countries with partners including regional resellers, distributors, and integrators supporting our international strategy outside of our key markets. We're investing in partnerships to ensure we're able to effectively serve our large and expanding global customer base. As Susan mentioned earlier, we're an elite AWS technology partner and are able to co-sell with AWS's over 9,000 sales reps. We also continue to invest in our growing global systems integrator network.
These GSIs are at the center of digital transformation for many of our customers. PwC, Deloitte, and Accenture accelerated their Okta practices last year, and we believe we are still in the early days of these relationships. Now let me talk a little about Auth0. There are many reasons why we are so excited about the pending acquisition. I'd like to highlight just a few of the compelling and significant synergy opportunities. First, the acquisition accelerates our penetration of the large, mostly greenfield, $30 billion CIAM market. Combined, Okta and Auth0 will be able to offer customers greater value. For example, the combination of security data will enable our products to provide more in-depth signals, enhancing the value of ThreatInsight. Additionally, together, we will be able to cover the spectrum of buyer personas, from the thriving developer community to the C-suite. Second, Okta and Auth0 have complementary products.
Auth0's developer focus results in a diverse toolkit that customers use to build apps the way they want with a high level of customization. This complements Okta's enterprise-focused products, which are geared more towards CIOs and CSOs, whose requirements include scale, easily accessible support, and certifications such as HIPAA and FedRAMP. Third, Auth0 has established a strong international presence and generates approximately 40% of their business outside the U.S. Together, we can leverage each other's strength in international distribution to further expand our reach. Fourth is the tremendous cross-selling opportunity. The vast majority of Auth0's business is focused on customer identity, so there's a large opportunity to sell our workforce products into their customer base. Fifth, Auth0 can be introduced into Okta's robust channel network, enabling even further reach and momentum with customers worldwide.
All this synergy is additive to Okta's strong organic motion, and we look forward to sharing more about the combined company's financial outlook following the close of the acquisition. Looking to our financial profile, the future has never been brighter for Okta. While we can't provide a combined company financial model until after the transaction closes, I want to give you more insight into how we think about our long-term financial profile, which is built upon three pillars. One, high growth in a recurring subscription business. Two, profitable customer economics. Three, disciplined capital allocation. I've already discussed Okta's high-growth subscription business. I'll now provide more insight into our customer economics. We have attractive customer economics and margins in our land-and-expand model.
Looking at the contribution margin for the cohort of customers that became new customers in FY 2018, the initial land has a lower contribution margin due to the investments we make to acquire these customers. However, that contribution margin significantly improves in year two and beyond. One reason for the improvement is our high level of customer retention. Another reason is that there are multiple opportunities for us to expand and grow our relationships with customers, whether it's new products or expanding usage within an organization, which you heard about in detail today. This is reflected in our strong dollar-based net retention rate. That is an attractive and fast ROI business model, and why we believe investing to acquire new customers generates a significant long-term, highly profitable benefit. Looking at our capital allocation priorities, our goal is to invest in the business while maintaining a strong balance sheet.
At fiscal year-end, we had just under $2.6 billion of cash and equivalents. Our investment methodology remains consistent with prior years. We'll continue to make investments both organically and inorganically that will extend our platform and product leadership. We'll also invest in key customer-facing roles and innovation to support what we believe can become a multibillion-dollar business. I'd like to now give you some additional detail on where we plan to invest in FY 2022 and beyond as we scale the business to become the next iconic cloud company. As we mentioned during our earnings call last month, FY 2022 is an investment year. The customer demand for our products is strong, and we have focused investments across a few key areas to capture this large market opportunity. The first investment area is go-to-market.
In addition to expanding our quota-carrying sales capacity, we are adding to our strong customer success teams to ensure we maintain our excellent retention rates. This includes expanding our sales engineering teams to assist in the further adoption of Okta's solution within large enterprise customers. Second is international expansion. We'll be expanding our global footprint, which includes growing our sales and customer success teams globally, as well as supporting infrastructure in many of our current and new international offices. The third area is innovation. We will continue to invest in product and engineering talent, as well as build out our cloud infrastructure to support the strong growth that we are seeing and anticipate. The fourth investment area is growth at scale. This includes back office and finance solutions that deliver increased efficiency in support of our strong growth over the coming quarters and years.
In fact, all of the investments we're making are to further enable our ability to capture the fast-growing demand for Okta's workforce and customer identity platform. Now let's talk about long-term growth against the backdrop of our large market opportunity. As you've heard throughout today's presentations, we are building Okta for long-term, durable growth. The new PAM and IGA offerings that we announced earlier today increase our opportunity even further and continue to build on our leadership position in the cloud identity market. We have a well-defined vision, market-leading products, and a pipeline of innovations to further fuel future growth. We also have a world-class go-to-market team that we're expanding both domestically and internationally. All of this is aimed at the $80 billion TAM that we are just beginning to penetrate.
This is a tremendous market opportunity for us to execute against, and we're confident that on an organic basis, we can achieve our current target of a 30%-35% revenue CAGR for FY 2020 to FY 2024. Again, on top of Okta's strong organic growth, the addition of Auth0 will accelerate our growth to greater than 35%. We'll share a more detailed financial view of the combined company on the first earnings call after the transaction closes. The modern identity market is still in its early stages. As the industry leader, Okta is well-positioned to build on our leadership position through innovation, customer success, and our expanding global reach. Part of building the company for long-term durable growth is ensuring that we are an exemplary corporate citizen. To this point, we are committed to continuing our progress on the environmental, social, and governance front.
Last year, we formally launched our ESG program and centralized information and disclosures on our new ESG webpage. We also conducted our first greenhouse gas emissions inventory to benchmark where we stand today and where we want to be in the future. We released our first diversity and inclusion report as we aim to provide transparency in this key area. We just announced that Okta is committed to achieving 100% renewable electricity for our global real estate footprint by 2022. This is a critical step in our journey to reduce greenhouse gas emissions and take a long-term action on climate change. We'll continue to share our progress on ESG topics as we go forward as this is a key priority for the company.
As you've heard throughout the presentations today, we believe identity is becoming a primary cloud, and Okta has built a strong foundation as the leader in identity. We'll finish this year with over $1 billion in revenue, and we believe we are still in the very early stages of this market. I'll conclude by reiterating the three key takeaways from today. We've established a strong foundation for growth at scale, we have large addressable markets with multiple growth vectors, and we have a very attractive long-term financial profile. With that, thank you for joining Okta's Investor Day. I'll now turn it back over to Dave, who will open things up for Q&A. Dave?
Hey, great. Well, welcome everybody to the Q&A portion of Investor Day. I hope you all had a chance to tune in to the Okta team content this morning where we shared a lot of exciting news. For this session, we have all the executives that you just heard from. Before we start taking questions, I want to cover a couple of ground rules to help with the Q&A process. The first one is to make sure you rename yourself in the Zoom tool with your name and your firm name. To do that, you simply click on the participants button at the bottom of the screen, hover over your name, click on More, and then select Rename. To indicate you have a question, please click on the raise hand icon at the bottom of the screen.
I'll announce you when it's your turn to ask a question, and you'll have to unmute yourself at that time. In the interest of time, please limit yourself to one question and one follow-up question. With that, we'll get underway and start taking questions. First up, I see [Ittai Kidron] from BofA. Ittai. We just have to get him moved over to Will, can you promote Ittai to a panelist?
All right. Can you hear me now?
Loud and clear. Sounds great.
All right. Very good. Guys, thank you very much for today. It was fantastic. A lot of great information. Of course, congratulations on the announcements. Very exciting. I had a question with regards to the two announcements of PAM and IGA. Will it be fair to think that your first opportunity of upselling into those categories would come from existing Advanced Server Access customers and Lifecycle Management customers? Maybe you can tell us, I know you have 10,000 customers, but maybe you can tell us how many of those specific product customers do you have so we can think about the immediate opportunity there?
Yeah, we're really excited about PAM and IGA. As you heard in the presentations, it's a $15 billion TAM added to our TAM from these products. The genesis of these products, first of all, it comes from customers. Customers have been asking about these categories for many years. As you mentioned, we have a nice foothold and a nice start in each of these categories with our Advanced Server Access product as a foothold and a step into the PAM market, and then our Lifecycle Management product with our step into the, in the past, our step into the IGA product. These are new products, so they really round out these critical use cases for customers. On the PAM side, it's all about additional types of resources, so containers and databases and the advanced security checks you need on those kind of critical resources.
On the IGA side, it's about full workflows around attestation, reporting, and broad comprehensive reports on governance. The other thing that's important here is that we're fitting into the way these customers want to work in a modern world, whether that's a highly dynamic cloud-based infrastructure or that's a lightweight governance process that doesn't slow down or bog down the pace of business. These are customer-driven. We found in the past, all of our best innovations, whether it was customer identity or others, have been when they've come from things that were broadly requested from customers. It's big news. It's really going to help customers, and we're excited to get after it and have success with customers with these products.
Very good. Todd, maybe you can talk about what percentage you think of your install base could these solutions apply to. You need a certain maturity from a security and identity standpoint. You probably need to be a company of a certain size as well. How do you think about the applicability of these solutions to your existing install base, which ranges from small to large?
I think they're applicable to every customer. Every customer has privileged accounts. Every customer needs some type of identity governance. I would say privileged access probably tends to be more applicable to smaller customers, but not exclusively. Every company wants to make sure their governance requirements are met and that they can do it in a flexible, easy way.
Got it. Very good. Congrats, guys. Good luck.
Ittai, I would just add to that. One thing that I think is very interesting here is this is another very good example of how modern cloud solutions can actually expand applicability. I think if you look at traditional identity governance and attestation, it's been very heavyweight, very on-premise, a lot of services, very tricky to maintain and upgrade a long time. I think what you're actually going to see with modern IGA products, starting with ours, is you're going to see the applicability. It's going to go much further downstream. You're going to have mid-market companies, even small companies are going to get a lot of benefit just from understanding what happened, the governance and the attestation parts. I think it's actually going to expand the market for our modern cloud solution.
Excellent. Good stuff, guys.
Okay. Next up, we'll go to Michael Turits at KeyBanc.
Hey, guys. How you doing?
Hey, Michael.
Two questions, one for Mike, one for Todd. First, for Mike, just some clarification. The 35% with Auth0, is that 35% now that's the CAGR, or is that the out year? Around that, there was a news article talking about over 30% growth in each of the next three years. I just wanted clarification on these long-term guides.
You bet. That's a great question. Thanks for asking it. Yeah. We will grow 30%+ for the next few years.
Organically.
Organically. Our range organically is 30%-35% on the CAGR for 2020 to 2024. Yes, we are stating that we will grow 30%+ each year. That's organically. With Auth0, we're saying that we'll be growing over 35%, so greater than 35% with Auth0. You're going to hear a lot about all that once we have closed the deal and we do our first guide with Auth0. That's-
That 35% is in each of the next three years, you're saying?
We haven't given that level of guidance yet. That's a great question. It's not a bad inference. I'll just leave it at that for today, if you don't mind.
Thanks, Mike. Todd.
I do think it's important to be clear, though. 30%-35% range organically is each of the next three years.
Okay.
The inorganic part is the stuff we're going to get to later.
Okay.
That's correct. Which is greater than 35%. That's right. Thank you.
Todd, for you, just the two platforms. I think you said that you would be maintaining both of them and investing both of them indefinitely. Why? Is it not something you should be bringing together? Is it efficient economically? Does it make sense for customers? Why are you keeping two separate platforms?
Well, first thing to understand about these companies and these platforms is they're complementary. There's some overlap, but starting from developers like Auth0 has and building from the CIO, the CISO down, results in some things that look similar, but the details and the differences on the surface are significant. It's not like there's redundant functionality across the board. There's some redundancy, but by and large, they're distinct complementary platforms. By the way, they're both at scale. The Okta CIAM business is about a quarter of our revenue, growing very quickly. On the Auth0 side, at the end of this year, it's going to be $200 million+ in ARR. They're both at scale, both having tremendous customer success. That doesn't mean we won't integrate them. We're very excited about the capabilities and the potential to integrate these two platforms and get synergy.
One great example that's really easy to grok for customers and for both companies is combining our threat data with their threat data. We call it ThreatInsight. Auth0 has a similar capability. We can combine those quickly and get better experiences for all customers across both platforms by doing that integration. The examples of this type of integration go on and on. We really get the best of both worlds with complementary platforms and combinations of integrations that can really take us a long way. Eugenio is joining us here today, and he can give his perspective on this as well.
Yeah. To what Todd said, the beauty of software as a service, as you know, is that the implementation details are up to us. The customer consumes an experience. How we solve their problem is really our problem, and that's what we're going to be focused on. There's many possibilities of integration. The threat intelligence and being able to combine signals from both platforms gives us a better chance to protect our customer's customers, our customer's employees as well.
There's few others that come to mind, which are obvious, which actually, in some cases, we deliver today because we already have customers that are using both platforms. It is completely possible today to log in into an Auth0 protected application using an Okta originated identity, and that's something completely supported. Can we make it easier? Of course, we can make it really easy. That's what we would like to focus on.
Thanks, guys. Great. Next off, we're going to Rob Owens at Piper.
Thanks, Dave. Good afternoon, everybody. Todd, I think throughout your history, we've talked a lot about the appropriate time to pivot and when we might start to see some of these swim lanes blur. Obviously, you're going to start splashing water in the pool at this point, just to continue the analogy. Why here? Why now? Is there something in the market? Are you at a scale where you think it should happen? If we look at your customer count, it's been impressive, but it's still only at 10,000. There's a long ways to go. Why would you add that risk at this point in time?
I think that the main reason is that the platform is ready to support it. We've been working really hard on our platform, these basic capabilities that give us a great launching point in these two new categories of IGA and PAM. That's a big, important reason. The second reason I would say is customer demand. These trends we've been talking about, cloud adoption, the customer experience moving online, every company having to get in touch with their customers online, and identity being such a key part of that, and security. These are really washing over every organization in the world. Along with that comes not only the core requirements we've met, identity access management, customer identity, but also these governance requirements and even more poignantly, I would say, in terms of everyone trying to be a digital business are these privileged access requirements.
Every company is trying to get online. That means critical resources and servers and databases and containers, and the time is right to make it clear to the market that there's a better way to do this. There's a better way to do this privileged account than some of the privilege access managements for these privileged accounts than some of these legacy technologies, and we're here to support them to do that. I think those two reasons, Rob, which is a pretty insightful question you asked.
Great. Second for Freddy, as you think about the partner network, and I think you guys were early to go after the GSIs and be very strategic and look at identity as a strategic area. Although it's still early, products aren't coming out until the first part of next year. What's been the early response from that partner network?
Absolutely. Good question, and nice to see you, Rob. Thank you for the question. I will certainly answer that. I just want to add a little bit to the previous answer that Todd gave around why now is the time. I would just say it's also not a step function. It's not like we're going from zero to one and now introducing these products. If you think about Advanced Server Access, it's been out for a couple of years. It's done very well in the market. Okta Privileged Access is going to integrate Advanced Server Access, and there's going to be more for customers to buy. It's a natural transition where we're going. Same is true for IGA. If you think about what governance and attestation actually is, it's lifecycle management, so provisioning, deprovisioning, change of role, change of profile.
It's entitlement management, it's a workflow engine, and it's reporting. As you know, we GA'd Workflows last year. That product did extremely well in hundreds of enterprise customers now, well deployed. You add in all the Lifecycle Management stuff we're doing, you add that in. You can see how when you add just a reporting layer or fine-grained entitlement on top of that, you're naturally getting into an IGA product. What I would just add to what Todd said is that second piece, customers have been asking us for it. They are saying, look, IGA, first of all, in a cloud world, you could argue that every access is privileged access just because of what you can do now. In particular on IGA, they're saying, look, IGA is second order data. It's derivative data off core identity information and access information.
If I have all my access information in the public cloud already, why am I going to take all the reporting off that, bring it back on-prem to do heavy duty reporting, and then hand it over to my auditors? It doesn't make sense. As you know, because we've been talking for years now, we are in the very early stages of these mega trends. The switch to hybrid IT, which is going to become cloud, it's going to happen for five, 10, 20 years. As it starts to move more, you're going to get more of that data in the cloud, so it's a natural place to do these things. Finally, when it comes to the GSIs, as you said, we have invested early.
We've seen a lot better traction earlier on in our life cycle than we did at Salesforce at the same time, and I know because I was there. What I would say again is we're just getting started. You look at what PAM and IGA are, now we're starting to really broaden out what can be done with the platform and integration. That means bigger deployments at bigger customers. That means more opportunity for GSIs. If you look, we are continuing to invest in our professional services for organizations as expert services, but that percentage of revenue from PS as overall is going down slightly because we're really pushing a lot of services out. Now there's hundreds of certified consultants from Accenture, from Deloitte, from PwC, and the list goes on, and they are experts in all of this.
It's going to be a big opportunity for us, and in particular, international. You heard Susan mention in her prepared remarks just a little bit ago, the focus on international. There's no better way to get into these large organizations around the world than with these partners.
Great. Thanks for the color, guys.
Yeah.
All right, next question from Hamza Fodderwala at Morgan Stanley.
Hey, guys. Good afternoon. Thank you so much for taking my question. Maybe first question for Todd and Freddy, just when you think about you guys breaking into privileged access management versus identity governance, where do you see the more immediate opportunity, as in, where do you think would be more easier to break into? The second part is, what does this mean for your partnership with SailPoint on the governance side?
I think they're both very interesting and exciting. If you just look at the first step in each of these respective markets, we've talked about the Advanced Lifecycle Management and then the Advanced Server Access. Advanced Lifecycle Management, it's been around longer, or the Lifecycle Management's been around longer, so it has more of a foothold, more customers than Advanced Server Access. I think that's probably a good indication of maybe the short-term uptake. We're very excited about both. The thing about both these products is that the market is dynamic and evolving quickly. We're excited to see how it plays out in the market with customers having success with them. I think one of the things about partnerships in general is that it's in our DNA. We innovated and we brought to market, 10 years ago, this concept of this Integration Network.
Companies like SailPoint are in there, and we'll continue to partner with them. SailPoint's a good company. They have a lot of successful customers. I think we'll continue to partner with them. We think we can do this in a modern way that's going to be the exact right balance between every bell and whistle and every feature and function than traditional vendors have taken to the space and meeting the minimum requirements in a modern cloud way. We think we can do a great job. It's integrated to our platform, and we do this with other companies, too. There's multi-factor solutions that we partner with, but we have our own multi-factor solution. There's precedent for us to be successful in this model.
That makes sense, and I'll jump in as well. I agree with Todd. I don't think we have to choose. We have Advanced Server Access. We have Lifecycle Management. We have a ton of customers on them. We've got Workflows that, honestly, if you think about it, goes across both products. You need access requests in both products. You need access certification in both products. Workflows will be powering this. Really, I don't think we have to choose. Our demand is very, very high.
There are a bunch of customers that we have that are using Advanced Server Access that would love the capabilities on databases and Kubernetes clusters that already have been working with us on designing that and the features and functionality we need. Same on Lifecycle Management. Given the state our platform is in, these are not super hard to light up, and the demand from the customers is there.
Thank you.
Great. Next question from Matthew Parron at JP Morgan.
Hey, guys. It's Matt on for Sterling. Thanks for taking the questions. I believe when you guys originally launched the Advanced Server Access solution, that was primarily geared towards the cloud virtual servers. I'm curious as to, you talked about databases and containers and servers. Which part of the PAM market will you not try to address? Where do you see your focus being relative to some of the other players in the market?
That's a good question. Okta Advanced Server Access works across on-prem, it works for servers hosted in the cloud, virtual machines, et cetera. It goes across both, and that's the way we built it, Linux, Windows, et cetera. We are going to broaden into databases, both production databases as well as BI databases that BI tools touch. We're also going to broaden into Kubernetes clusters. Our resource coverage will look very similar. I think the way to think about this is we're bringing a modern approach to the market, which is more just-in-time credentials, than having necessarily shared credentials where you use a vault.
At least in the near term, we will partner with companies that actually have a vault and for resources that need shared credentials. I think of it that way, which is we want to bring a cloud-forward, user-based view, which is what our customers are asking us. That's the lens we're taking versus the resource lens.
Got you. That's very helpful. Just one follow-up, maybe for Mike. With regards to margins, I know you guys are not commenting on Auth0, but given the expansion into these two adjacent markets, I noticed you guys didn't really guide to a longer-term margin framework. How should we think about how you play around with the investments in the different buckets in the business going forwards?
Yeah. Great question, Matt. Thank you. First of all, we are very Rule of 40 focused with a bias to growth. With this huge $80 billion TAM now with IGA, with the expansion of Core Workforce, the expansion of CIAM, it's toe in the water. Like Susan said, we're a couple of percent penetrated in Workforce, and even with Auth0, once it closes, we'll be just under a couple of percent in CIAM as well. Big opportunities there. We guided, of course, as you recall in the last call, that in FY 2022, we're making investments in AEs and SEs, full sales capacity, marketing capacity, CSMs, and of course, a lot in the area of product and dev. Huge opportunity. We're making some real tangible investments.
Because the opportunity is there quite candidly. That's what we're doing. That's why we guided the way we did for FY 2022. By the way, when Bill gave that guide, this was very much in our roadmap and thought through at that point in time. As far as we get out to the midterm here, we do continue to believe that 20%-25% FCF margin is the right objective. The exact timing, we'll go through things post Auth0 closing that kind of puts it all together.
As both Todd and I touched on, that takes the growth rate over 35%. That's what's going to happen. That's the way to think about it. It's a balance. There is operating leverage in the model. If you look at FY 2021, we did a 13% operating leverage with FCF margin. It's there. It's a decision. We're making these proactive decisions as we go. With the growth opportunity the way it is here in FY 2022, we're leaning in.
Great. Thanks, Mike. Next, we're going to go over to Alex Henderson in Needham.
Thank you very much. It's great to see you guys, Todd, Eugenio, Frederic, and the like. I have just a clarification question to start with, if I could. The commentary about 30%-35%, going above 35% with Auth0, is that a pro forma calculus or is that above 35% would then be the growth rate, with that being somewhat of an inorganic calculus because of the obvious benefit of bringing in that additional revenue upfront?
I didn't know there was going to be calculus on this call. That's a great question. When we gave that guidance, that includes, you didn't ask this, but just to be clear for everybody, that is net of what the expected deferred revenue haircut. That's one thing to keep in mind. Clearly, in this year, it's TBD as to exactly when it closes. We continue to expect Q2. Yes, it's a compare. It's not pulling, right? It's a compare against an FY 2021 that didn't have Auth0 in it at all. This year will be a partial year. That's also true from that perspective. As Todd followed up on me at the beginning, we expect that over 35% growth rate in those subsequent years as well. In this year, it is a close year.
Got it.
That's also expected going forward.
Thanks for all the great content today. It seems like this presentation today was extremely shifted left, much more so than previous years, and specifically addressing a lot of DevOps and coder-centric type of technology integrations. In that context, you mentioned HashiCorp a number of times, obviously one of the premier companies in the shift left movement, code as infrastructure arena, and talked about integration with it. On the other side of the coin, they have a vaulting technology. Somewhat addressed this a little bit with a prior question from Morgan Stanley. They're pretty much an integrated real-time realization of identity as well. How do you compete with the vaulting product of HashiCorp, and simultaneously, are you partnering more with the Terraform side? Does it matter? How does all of that boil out? Is it a cooperation-competition situation or what?
Yeah. We actually partner very closely with HashiCorp, both on the Terraform side. We have official integrations that we work with them on so that you can configure a bunch of organizations in Okta, et cetera. On the Vault side, as you're bringing up, I already brought this up, we're not looking to go to shared credentials. There are a number of partners, HashiCorp with their Vault being one of the premier ones that we partner with. On the other side, they don't have an identity provider, right? They use us as an identity provider. It's actually a very seamless partnership. What you'll see is we're both very, very deeply integrated in each other's solutions. It's not by chance. It's very proactive because we work with them so much.
I'll just add to that, Diya. I happen to be on the HashiCorp board. I can attest to the partnership and how bullish both companies are on continuing to expand that partnership.
Perfect. Thank you very much. Great stuff.
Alex, did we answer your question about the growth rates and the calculus?
Sounds like you're assuming that you're going to continue to grow 35% or better-
Better, yeah.
even when that's in the base.
That's correct. Over 35% when in the base. That's a good summary. Thank you.
All right. Let's go to Andy Nowinski at D.A. Davidson.
Great. Thanks. Thanks for hosting a great event. I just had two questions on the new solutions. I think you said that customers can upgrade from Okta Advanced Server Access and Lifecycle Management to the new solutions. I'm wondering if you could just give any more color on the revenue uplift that you might see on a per user basis when they upgrade.
As we said, our Lifecycle Management has capabilities for servers as well as they have capabilities for access. We have a bunch of customers that want more advanced capabilities like SSH and RDP session capture. They want attribute-based controls. They want obviously more resources we talked about, and those are the customers that are going to upgrade. From a revenue capture perspective, I think these are products you would upgrade to. If you have Okta Advanced Server Access and you want all these capabilities, you would have to upgrade to these capabilities, and there'd be additional SKUs you'd buy. On the Okta Identity Governance side, as we said, we're doing a lot of the provisioning, deprovisioning capabilities, the entitlements, all that stuff. Really what you're missing today is things like access requests, making that easier.
What I've talked about in my presentation was we're doing things like how do you provide self-service access with the right level of intelligence so that you don't increase the risk, but also provide deeper access requests for things that are more sensitive. Access requests is one, certification is another, reporting is another. If you want those suite of capabilities, you basically end up buying that product and that SKU in that portfolio. Does that answer your question?
I guess. Are you offering any sort of bundles when customers buy all three solutions or any incentives to buy all three upfront?
Yes. Regular pricing. If you're asking about a pricing structure, it'll be if you buy the whole portfolio, you get a bigger discount, basically. As the rest of our structure works for the rest of our pricing. It's not very different.
Okay, thanks.
Okay, next up we have Brian Essex at Goldman.
Yeah, thanks, Stephen. Thank you all for taking the question. Maybe just to follow on Andy's question, kind of similar, but maybe to put a finer point on it. Potentially for a customer that does not currently have IGA and PAM, is it 2x lift, 75% lift to pricing what you might have on an ASP per customer?
Yeah. That's a great question. On PAM, it is $45 per user per PAM unit. The way a PAM unit is defined is a different set of bundles of servers and databases and Kubernetes clusters, and we can go into detail there, but it's not as relevant. On IGA, if you want to buy this new capability, or these new set of capabilities, it's $1.09 per user on top of the existing Advanced Lifecycle Management and Lifecycle Management.
Got it. Brilliant.
The like for like there is per user per month.
Got it. Very helpful. Thank you. Then maybe just to follow to on the IGA side, where are you seeing the most demand? Is this similar to what SailPoint might say that you have these legacy customers that want to pursue digital transformation efforts and some of the legacy vendors are bottlenecks to that transformation process? Are they looking for other cloud-native alternatives, particularly at the lower end of the market, where there may not be something scalable cloud native to address that platform?
I think it's both. I think there's some companies that are using legacy solutions that will want to move off them and use something more modern. I also think there's a big market for net new, especially on the privileged access side. If you look at our success, we think the success with Advanced Server Access will be an indicator of this. A lot of these customers we've had with Advanced Server Access didn't have an existing privileged access product. Now that we've rounded it out, I think you could see that trend be even stronger to net new customers to the market didn't want to go ever with the legacy technology leaning big into first our, prior to our Advanced Server Access now with our Privileged Access product. Good example is Zoom.
It's a big customer with who you saw the interview with the CIO there at Zoom. They were never going to install a privileged access product from a legacy vendor. That Okta Advanced Server Access was a net new purchase for them, not replacing an existing vendor. Zoom is obviously a standout exception, but there's a lot of companies that are building software, wanting to be more modern, and are looking to cover these critical accounts and this big security issue with a modern solution.
I would just add, though, even in speaking with Fortune 500 companies, I think it's going to be very similar to what has happened over the last five years with our core access management products with Single Sign-On , Lifecycle Management, UD, MFA, which is effectively, look, they've been running Oracle, in that analogy, they've been running Oracle or IBM, TIM and TAM or Oracle Identity and Access Management, and they're running that on-premises for all their legacy infrastructure. When we talk to them, they say, "Look, that thing's fine, but it's just running, it's doing maintenance, and what I really need is I need you to help me solve these key modern, critical projects that are high value, high importance, high security, get them up and running quickly, one quarter, two quarters, three quarters," which we do.
That allows us to go back and talk to these CIOs and CTOs and CSOs and say, "How was that experience?" They say, "It's phenomenal." Great. Now let's talk to you about the plan to rip and replace your Oracle and your IBM over the next 12, 24 months. I think it's going to be very similar, for example, with IGA. They're going to have their legacy IGA on-premises product that's running for a bunch of mainframes and a bunch of other things they need to do. They have all these modern products. They're not going to plug that legacy on-premises infrastructure into Workday and ServiceNow to figure out how they're going to actually do IGA in those products. They have to because those things are starting to become critical into their infrastructure.
What they're going to do is they're going to use our products, they're going to integrate all that stuff, it's going to go very quickly, and then they're going to turn around, they're going to say, "That's great. Now show me the roadmap to turn the lights off on the old legacy on-premises infrastructure." I think that's a very similar path. Again, we're not making that up. It's good experience that we have over the years doing that, and I think we're just going to be expanding out the footprint inside these large organizations.
Very helpful color . Thank you.
Thank you.
All right. Next, let's go over to Josh Tilton at Berenberg.
Hey, guys. Thanks for taking my questions. Can you hear me?
Yeah, loud and clear. Josh, go ahead.
All right. The first one is kind of a follow-up on the pricing for the new IGA and PAM offerings. I know they're not out yet, but do you guys have any indication on maybe their relative attractiveness to what companies are paying for their incumbent solution or other cloud and PAM IGA solutions that exist today?
I don't know all the details around the license management and how they're doing the procurement around on-premises software. I assume it's largely perpetual and it's largely recurring maintenance, as you've seen with a lot of these legacy on-prem products. I know that some of the legacy vendors in both PAM and IGA have tried to move into the cloud because they realize that that's where the future's going. It seems as though they're having some tough times doing that. It's very hard, right? When you have such a core center of gravity that's focused on this on-prem product and maintenance and doing upgrades to it's hard to get this other motion going with the cloud. Which is why we've taken the opposite approach, obviously, over the last decade, cloud-centric, cloud-focused.
We're going to where the future is. I'm a hockey guy. We're going to where the puck's going, not to where it was. Over time, we're going to make sure that we can integrate all the existing on-prem infrastructure so they can bring it along with them. When they want to turn the lights off, we're going to give them the full suite of what they can do in the modern world as well.
Just as a quick follow-up, there have been a lot of announcements pretty recently of the acquisition of Auth0, and you're going to develop new IGA and PAM solutions. Can you just walk us through what the decision was to acquire in customer identity, but maybe develop in-house in PAM and IGA? Why not acquire somebody in those markets as well?
Yeah. The CIAM market is a big, strategic, important market for us. I think that one of the reasons why we're so excited about the combination with Auth0 is because the TAM we talk about is really a couple different sub-markets. There's the CIO-led, CISO-led market Okta is really good at attacking. What's become clear is that the developer market is somewhat distinct and somewhat complementary. When you start with a developer focus like Auth0 has from the inception of their company, you end up with a pretty different product and a pretty different go-to-market motion on how to capture it, and that's why we're so excited about the combination. Eugenio is here to add color on that side.
Yeah. Even for us, with all the progress that we made, we are also scratching the surface on what's possible with developers. We only touched single-digit percentage of all the developers around the world, right? Our focus has always been on the empowering developers to build faster, more secure, and to essentially address the huge opportunity cost, which is the time that now it's being wasted on building stuff that we can do better for them so they can focus on what's really important, which is their own apps.
Yeah. It's very well said. One of the analogies that I used internally to talk to the team about this, and as we were thinking about our approach here, was helpful was the following analogy. If you look at Oracle relational database and you look at MongoDB, you could say, "Oh, they're both databases. They're not complementary. It's just zero sum. A database is a database, a database." They're actually quite different. If you're a developer or you're a user or systems administrator, at a high level, you store data in them, you query them, you back up the data. On the details, they're pretty different. A document database is pretty different than a relational database. They're quite complementary, and they're two valuable platforms that can address different use cases in the same bigger market, which is data management.
I think it's not perfect, but it's a helpful analogy to understand that while on the surface, yeah, they're both identity management products and platforms, but the details matter a lot. When you get into the details, they're quite complementary and can give customers a good amount of choice and flexibility and value. I think your question is like, why now? Why did you buy? Realizing that over the last few years is really the reason there, and also the reason why I'm pumped up about to close the transaction hopefully soon and move forward, building something great for customers together.
Josh, just following on the last part of your question there, hey, why not do some M&A in IGA and PAM? I think it's, first of all, a follow-on to what I said earlier, which is, we've been building basically these products for the last few years. People are looking at ASA from the side and saying, "Is that a modern PAM product?" They're looking at Lifecycle Management and Workflows and saying, "When can I replace my SailPoint legacy on-prem infrastructure?" We just have to say, "Yes, we're doing it, and here's when it's coming." Frankly, it's a huge sigh of relief. I know that when I talk to customers in the coming days, they're going to be like, "Finally, thank you. Now I at least know what to put into my roadmap." That's the first thing, is we've been building this.
Second of all is, remember, we are an organic product and engineering development company. That's what we are. That is what our core is. We have this amazing opportunity with Auth0 to partner and make the world better and get in front of customers even more quickly, which Eugenio and his team have done a fantastic job of doing. At our core, we are an organic product and engineering company. That's why you see how all these products are doing. When we GA something, it doesn't have a whole bunch of bugs in it takes off. What I would say is, we're not done. There are certainly going to be things that we'll continue to look at as we enhance our IGA and PAM offerings. As we look at other adjacencies, there's a ton to do in customer identity and access management.
We have nothing planned right now, obviously. We have our hands full with Auth0 and making sure that that integration transaction is wildly successful, which I have no doubt that it will be. Those products are already off and running. As we find things that would make sense to enhance them, we will also take advantage of those opportunities, though.
Thanks, guys. That was very helpful.
Yep.
Next, we're going to go to Gray Powell at BTIG.
Hey, great. Thanks for taking the questions. Can you hear me okay?
Loud and clear, Gray. Go ahead.
All right. Yeah, I guess, with Auth0 operating as a separate company underneath Okta, how do you manage the two separate sales teams and just make sure that an Okta rep that's focused on customer identity isn't actually competing against an Auth0 rep, and just that everybody plays nicely together?
Well, first, let me start with this. First of all, we are in this period of time where the transaction is not closed. We are actually operating as we were before we announced this. We don't control when it's going to be done. Hopefully, it's going to be done soon. By that time, we will be working together. In the meantime, we serve two different audiences, really. We have different and complementary go-to- markets as well. I think we mentioned as well that we also have a different geography coverage as well. Auth0 has 40% of its revenue out of the U.S. and 60% in the U.S. There's many things that we need to figure out, and that's what Susan and the rest of my team will be working on as soon as we close.
For sure. I'll just jump in on that. One thing's for sure is we'll be very prescriptive with the customers based upon their requirements about which solution is best for them, as Eugenio talked about. They're two very different approach. One's a very low-code approach, one's a very pro-code approach. We'll make sure that we just lean in on our customer requirements. In most cases, I think they're going to be pretty clear. There are certain things like the private instance that Auth0 brings to bear is something that I think is going to be very exciting for many of our customers.
There are things we're further ahead in FedRAMP. In terms of the government market, that'll be a clear Okta lead. There are all of those things that we're already thinking about, but we'll get together post-close and really make sure that we're clear based upon customer requirements, what we should be leading with our customers. We're not going to confuse them.
Yeah. One of the things, I'll jump in here quickly, pops into my mind is that, first of all, this integration, we know it's going to be a lot of hard work, and we have a lot of focus on making sure it goes extremely well. We don't underestimate the amount of work it takes. The guiding premise is that these are two high-growth companies. The first order of business is making sure we both continue to grow rapidly, and then the second order of business is the integration and the sales integration and the product integration when it makes sense, and making sure it's all done under the framework of customers being successful. Yeah, I'm excited to-
Maybe to add some color. Our quarter ends in Q1 for us, ended in March. We announced this deal at the beginning of March. It was a good test to see how our customers would react to our proposal. Well, we had a fantastic quarter. We beat our results, our plan by 10%, and every single customer I spoke with regards to the future and our future together, saw this as an immensely positive thing, which is awesome to see.
Got it. All right. That's great color. Thank you very much.
Okay, next question from Jonathan Ho at William Blair.
Hi there. I just wanted to start with one question for Diya. When we think about Okta as a primary cloud platform, what do you think has to happen in order for us to see more sort of standardization on a single cloud provider? Maybe what largely stands in the way of seeing that penetration rate of 2% becoming a bit higher?
A couple of things. We've talked about this a little bit, which is really the provider or the player that can help companies stitch together their basic backend ecosystem of tools, et cetera, both on the customer identity side as well as the workforce side, is going to be the provider of choice, right? Because identity flows through everything. Really, our job is not just to provide an authentication and authorization service, but our job is really to help our customers bring together this stitching of identity across the different solutions so that they can bring together the experiences that they need for their employees, their workforce, as well as their customers.
I think our approach of being multi-cloud, of being open and neutral across what tools our customers use, our Integration Network, the extensibility we are building on our Platform that allows them to customize, make it more flexible. That's the approach that I think that's going to work.
Yeah, Jonathan, we call it primary cloud, making sure identity is a primary cloud. We talk about that a lot in the presentations we just went through. That really, at a high level, informs our whole platform strategy, whether it's more integrations, as Diya mentioned, whether it's breaking the product into these platform services that can be reused and flexible, whether that's making the whole system more extensible and customizable, and whether that's building new products like PAM and IGA. It's how do we solve more of these use cases?
How do we make sure that the Identity Cloud and identity specifically is elevated to the status of primary cloud? It's that critical for customers. It's going to drive choice across all of their technology, thousands and thousands of technologies, and the other five or six major clouds like collaboration or infrastructure or data that they're going to inevitably settle on.
Makes a ton of sense. You also referenced the Fastly partnership that was announced today. Can you talk a little bit about what this could mean from a go-to-market and lead gen perspective as well? Thank you.
Yeah. As you saw, we continue to build on the Okta Integration Network, which is the premier catalog and is a great example of what Todd was just talking about, just really making sure that we have the best integration to everything that's out there. We started that as an application catalog a decade ago. It's become an integration catalog because of all the pieces of technology. What you're seeing is more and more of the leading organizations of modern technology providers, Fastly is a great example, are really leaning in in terms of how we can do more jointly for our customers.
We outlined a number of different groups that we have improved across the Okta Integration Network, both on the workforce identity and access management side, as well as the customer identity and access management side. You're just going to see more and more of this in the time ahead. Diya, you can maybe talk about some of the reasons that we were specifically working with Fastly, and why they leaned in and how that works, similar to some of the HashiCorp commentary you gave earlier.
Yeah. Thanks, Freddy. Exactly the same way, a bunch of our customers came to us and said, they're working with Fastly, they're working with F5, HUMAN, et cetera, and said, "Hey, we're having to stitch you guys together. Okta has one set of threat information, Fastly has another set of threat information." Basically, we both got a ton of demand across the board on our side and connected with each other and realized that we could partner together and build a solution that was way better, that was integrated. We both see different events and different data that help us lead to the threat conclusion that we make. That's essentially what happened.
Thank you.
Great. I want to sneak in a question from the buy side that came in. The question is, on IGA, how will you approach the more complex setup required at the enterprise level to get the right access across all users and applications, both in the cloud and on-prem? I've heard that it takes 6-12 months or longer with SailPoint. Will you outsource that to partners or do it internally?
I like the sneaky buy side getting their question in via Dave. I'm happy to answer that. Certainly, I think this is another perfect example of how legacy integration infrastructure in the past, in this specific case, IGA, so governance, where they're pulling in different data about login information, authentication requests across their different systems. How the legacy on-prem version, it took 6- 12 months just to get the servers up and running. In our case, we actually already have the service running. As Todd said, though, I want to be really clear, we're not going to spend the next five years replaying every bell and whistle that the legacy on-prem providers have created in IGA. Frankly, our customers are asking us to do exactly that. Don't start rebuilding all of the different bells and whistles.
I don't use many of them, and in fact, if you do that, I'm just going to end up staying with my legacy processes and my legacy ways of doing things. Half the reason that these large organizations are so excited about coming to work with us, of course, they're using our products. They get up and running. You see the ROI, the TCO, the time to value. It's not by accident we can get these kinds of customers to come and talk to you about their case studies. Also, they're looking for innovation. They're asking us to come in and help them understand what the future looks like. Where's the roadmap? How should IGA work? What do I really need to do? Look, their auditors are changing at the same time. Auditors are not sure what to do in this modern cloud world.
We are certainly not going to start by replicating every bell and whistle that a SailPoint or the other on-prem providers have had. In fact, you can see what we're already doing with our workflow connectors. I think that's a perfect example. GA'd Workflows about 16, 18 months ago now. It's flown off the shelf like hotcakes, and people are really using it end-to-end for identity governance across their entire systems. If you just put a nice little reporting engine on top of that, you have a modern IGA solution. The final piece about that was, are you going to do it with partners or internally? We're going to continue to do exactly what we've done, which is we're going to invest to make sure that we have expert services.
At the end of the day, when you go talk to a FedEx or an ENGIE, or you go down the list of these large organizations, T-Mobile, that trust us with all their identity infrastructure, they're going to want to know that someone from Okta, who's an expert on the topic, is overseeing what's going on. That being said, not only the GSIs, which we touched on earlier, there are starting to be some boutique security and identity SIs out there that are developing both regionally and practice-wide that are focusing entirely on Okta. They're starting to build around Okta. Same kind of thing we saw at Salesforce 10-15 years ago with Appirio and Bluewolf and Astadia and Model Metrics and all these other guys. This is starting to happen now at Okta, and those folks are deep into identity. They've been doing it for 25 years.
In a lot of cases, they built the original products, so they know exactly where we're coming from. I think the opportunity is huge going forward. People want that modern roadmap, and that's what we're very excited to deliver. The final thing I'll just say is, again, with cloud, we're not in the big bang business. The reason we have dollar-based net retention of north of 120% quarter after quarter after quarter is because our business is about getting these customers up and running, making them successful, and then we become their trusted partner by virtue of the success they're having with us, and they ask us to do more and more. Same thing's going to happen with IGA. Yeah, do you have 50 things plugged into your legacy IGA provider? Probably. Are those 50 critical? Probably not. There's probably five that matter.
We'll nail the first five, and then we'll slowly get the roadmap to ship them off the rest, and it's going to be the natural same motion that we've had today. We're going to continue to build fantastic relationships with these large organizations, and I'm thrilled about this.
As you can tell, Freddy was a vocal proponent of us entering this market.
All right. Next, we're going over to Keith Bachman at BMO.
Hi, thank you. Susan, I wanted to come back to you if I could. I understand when we're talking about Auth0 and Okta, the customers can decide, but what I want to be more focused on my question is, will there be a consolidated go-to-market effort between the two organizations? In other words, will there be one global account manager? For a firm like Bank of Montreal, we have a lot of the companies, ForgeRock, Okta, Auth0, calling on us. I'm just trying to understand, well, if R&D is kept separate, but will the go-to-market all be unified between the two companies?
It'll be a collaborative approach, Keith. I'm not going to say that there's going to be one person, but it'll be a collaborative approach. We have a lot to obviously work out come day one. As I said, the key is going to be focus on customer requirements, customer success, and make sure that we have an incentive plan in place that will allow the team to work that way.
Maybe my follow-on question is on the financial side. We talked about the TAM increasing as a result of the inclusion of PAM and IGA, and the growth rate improves from something like 30% or north to 35% or north. Should we infer that the net retention rate will also get a bump during this process as you have a richer opportunity to sell into your install base?
Clearly, Auth0 themselves, they already have a great net retention rate, as you know. We also have a great retention rate. These are two first-class companies coming together. As far as guidance on a bump, et cetera, all those kinds of things we'll contemplate and discuss in the earnings call following the closure of the combination. They're in very good shape as well with both their gross and net retention as we are.
Okay, perfect. Many thanks. Congratulations.
Thank you.
I will just add that we do think there's a lot of upsell opportunity with our new products and between Auth0 and Okta.
Right.
There's the numbers and the guidance and the expectations, but we do think there's a big upsell opportunity.
Fair enough. Thank you.
Okay. I'm going to go next to a question that came in through the Zoom tool. How does Okta see the device management partnerships like CrowdStrike integrate more with a newly expanded risk engine? Will ThreatInsight be allowed to integrate with threat intel from partners?
Yes, absolutely. That's the whole purpose of the risk engine. That's essentially what we announced today. What we are also building is in beta right now, is the ability for us to be able to use our Devices SDK and device platform to exchange signals directly from the device, and feed it into the threat intelligence. For companies like CrowdStrike, other EDR vendors, there won't just be one path to integrate. There'll be multiple paths to integrate, and we'll be able to feed all of this into our risk engine to be able to get much better risk analytics than any one of us could alone.
Excellent. All right. Next, let's go to Gregg Moskowitz at Mizuho.
All right, thanks. Can you guys hear me?
Yeah. Sounds good, Gregg.
Perfect. First, a clarification for Diya, if I may. Once Okta Privileged Access is GA, is ASA going to be superseded, or do you expect to continue to sell it as a more slimmed-down offering? For Mike, can you say what Customer Identity represented as a percentage of ACV exiting fiscal 2021 and how fast it's growing? I believe it was at 23% of total as of the end of fiscal 2020.
Yeah. I can start that real quickly, and then we can go to the other part of the question. Yeah, what we reported is that Q4 was 25% of the business at the end of Q4 of FY 2021, and we're in Q1. We will periodically give that breakout.
On your question around ASA and privileged access management, we think of it as a suite, as a portfolio. You can start with Advanced Server Access and start with basic access management, and as you get more and more sophisticated and need more privileged capabilities, you buy the additional SKUs in the portfolio to upgrade to the functionality you need.
All right. Perfect. Thank you.
Okay, next we're going to go to Shaul Eyal at Cowen.
Thank you. Hi, everybody. Great to be here. Congrats to everyone. Eugenio, great to see you. Freddy, Todd, Mike, Diya. Actually, my question is for Susan. Many of us here on the call vividly recall the great achievements that you had at Splunk. If I'm not mistaken, I think we actually met you during that Analyst Day 2017, maybe 2016. Again, what happened right after that, two, three quarters after that, with the entire product messaging, the go-to-market strategy opened up. Aside from the great TAM opportunities, which we can see at Okta, without a doubt, at Splunk, where do you see areas that you believe you could be importing some of the Splunk's best practices into the Okta and Auth0 platform right now?
Sure. Thank you, Shaul. Thank you for the nice comments, first of all. As you said, it really is about the market opportunity, and Todd being a great salesperson. He says he's not on the go-to-market side, but he really is. I will definitely be leveraging a lot of what I learned there, and quite frankly, a lot of what I learned at Salesforce. While not everything's the same at each company, the net of it is that high-growth motion is something that is highly repeatable when you have this type of market opportunity.
It's really about coming up with repeatable motions, it's about hiring great talent, and it's about running an incredibly interconnected go-to-market strategy across all the different functions. I can already tell you that Diya's become my best friend, just like Tim was at Splunk, and I think that's the magic. It's really about bringing that cohesive approach to go to market, not just a sales-led approach.
Thank you.
Good luck.
Thank you so much.
Okay, next we'll go to Taz at Guggenheim. Taz?
Hey, guys. Thanks for taking my question. I have a clarification to start off with. The GA for PAM and IGA, you said Q1 2022. I believe that's Q1 calendar 2022, right? Not Q1 fiscal 2022.
Yeah, it's three quarters from now.
Thanks, guys. For Mike, you're investing more in sales. You have more TAM now with the IGA and PAM products. If you look at your mid-term CAGR guide of 30%-35%, that's not changing from what you gave us at the last Analyst Day. Any more color on why, given the investments, given the increased TAM, you don't think the top-line momentum should be higher now?
Clearly, it's a bigger opportunity. When we had that discussion, this was in our thinking as far as for our forward guidance, albeit at a modest level. Yes. Does this give us more growth vectors, more upside? Certainly, it does. At this point, we're guiding the 30%-35% organically and the greater than 35% with Auth0.
Got it. The second question, I'm just trying to get a sense of the deal sizes for CIAM versus Workforce. If I look at Auth0 today, the run rate, I think the ARR is $200 million, but they have about 8,000 customers, which is similar to what Okta has at a much bigger run rate. It looks like the average deal size for CIAM or Auth0 is a bit lower than what Okta has today. Any more color on if that's driven by pricing being different, deal sizes are different because customers are smaller? Any more color on the different deal sizes between Okta and Auth0 would be helpful.
Yeah. Maybe just on our side, we have 10,000 paying customers, of which 20% of those are enterprise customers. These are customers with more than one year contract minimum, typically two, three, or more years. Our ratio between total contract and annual revenue, it's about 2.7 for us, 2.6 for us. It's not uncommon to see customers in that range committing to longer-term contracts. The other 80% of our paid customer base is what we call self-service customers. These are customers that pay with a credit card on demand as you go, month by month.
They go anywhere between $30 per month all the way to maybe $1,000 per month. For enterprise customers, the minimum contract is $25,000 of ARR. We also have 20,000 non-paying customers because our go-to-market is primarily f reemium. That's the top of the funnel for us. Overall, we have 30,000 customers that use our system in production. 20,000 free, 10,000 paid, 2,000 enterprise. Make sense?
Then Taz, I'll just add on the Okta side, and nice to see you, thanks for the question. I'll just add on the Okta side. It's a very broad range. You have examples of smaller organizations, I'll take Major League Baseball, right? Centrally, Major League Baseball is not the 32 teams. It's just central Major League Baseball. It's 1,000 employees or something like that. They're a giant customer, identity and access management customer of ours. Why? Because there's 60 million consumers every year who log in to stream MLB games, whether it's the World Series or the playoffs or anything else. That's the example of a smaller business that is actually a giant CIAM customer.
I'll flip it around, and you got to remember that when we talk about the market opportunities, and we get that question a lot, we haven't gotten it here, but just to remind people. People always say, "Well, which one's bigger?" First of all, I don't know. They're both tens of billions of dollars, okay? They're both growing fast. Secondly, we're barely penetrating either one. What I would also say is, you take an organization like McKesson, Fortune 8. We've talked about them on previous earnings calls. Now, McKesson ships 1/3 of all pharmaceutical drugs in North America every day, large organization. They've got 100,000, 125,000, something like that, employees. Okay. They've standardized on Workforce, on Okta, on the Okta Identity Cloud for their Workforce identity and access management, Universal Directory, Single Sign-On , Lifecycle Management, MFA, and some of the newer products as well.
That's great. As we come out with newer products, IGA, PAM, perfect examples, and they are starting to use ASA, that'll be a natural upsell to the conversations earlier. As we come out with new products, they're going to buy them, they only have one Workforce. That Workforce is 125,000 employees. There's 125,000 seats of each of these products that we're going to come out with. They have N number of customer identity and access management initiatives. They have supply chains. They have B2B. They have B2C. They have B2B2C because they have N patients, they have N clinicians, they have business partners who distribute the drugs. Each of those is a CIAM opportunity. There you've got a Fortune 8 company, where it's obviously a very large organization in terms of revenue, and they've got N number of CIAM opportunities.
Each of those might be smaller, but when you roll them up, it could be a big opportunity. I wouldn't say there's one stamp fits all. I would say there's a lot of opportunity out there. Frankly, again, if you look at the macro tailwinds that we're riding here of hybrid IT, everyone's got to move to cloud. Digital transformation, the most overused term in the industry by far, what it really means is everyone just needs a better interaction with their customers, partners, vendors, suppliers. Small company, big company, public institution, private organization, anywhere in the world. This is across geographies, and that's why we're so excited about this opportunity working with Auth0.
Cool. Very helpful, guys. Thank you very much.
Okay, we have time for two more questions. The first one's another online question. It's from Jackie Glynn at Glynn Capital. Given the tremendous new product flow and Auth0 coming on board, how do you think about net retention rates, and should those end up north of where they are sustainably from today?
Great question. Thank you, and thank you for conducting that, Dave. Clearly, again, as I mentioned earlier, we have two companies with great net retention rates. We have these organic launches of these new products. Yes, that is a tailwind going forward. We're certainly very early on all of these activities, so we're not guiding something different today. We're very happy with where we are from a gross and net retention. As you know, it was 121% last quarter. We also know that Auth0 operates at over 120%, and we do have these tailwinds for upsells. We're excited.
Excellent. Okay. Final question for this afternoon, back to Michael Turits at KeyBanc.
Hey, guys. Thanks, Dave. Thanks for working me back in. I just wanted to make sure that I'm clear, given the number of questions there have been about what happens with the sales integration. Todd, how much do you guys really stay separate organizations, and how much do you become one organization? If you tell me where that happens in each functional area, I think maybe that'd be a great clarification.
I applaud your ability to get back in the queue. It's impressive.
Don't know how it happened, but whatever.
I look at this in a couple phases. It really starts when the transaction closes. That's phase one. I think, like I said, the first year or so, the priority is both teams need to hit their plans, grow, grow. I think how we actually integrate over that period will be probably on the go-to-market side, will be the most integration and the most collaboration. As Susan mentioned, the first thing is just some basic communication and collaboration and clarity for the customers that might be involved in a deal with both companies. Then on product, there'll probably be very little integration as they have roadmaps and they have things they're working on both sides for the first year. I would imagine that over the course of that year, the sales teams will figure out how to integrate more closely, more quickly, but we don't know.
We haven't figured out the integration, and the priority is going to be maintain growth, maintain a great customer experience, maintain the respective cultures of both teams. So the first year will be largely independent. I think we will make a lot of progress on our plans, and as we get through the close and into some of the analyst communications and some of our opportunities to speak, we'll have more details as we get through that first year in terms of how we're doing the integration, because we do think the integration is very important, and the execution on that integration is a key driver in how this works out over the next five or 10 years. So we're laser-focused on making sure it's effective.
Thanks, Todd.
All right. Well, that's it for this afternoon's meeting. We appreciate you attending. There's more Oktane content tomorrow, so tune into that. If you have any follow-up questions from today, you can email us at investor@okta.com. That's it for our show. Thanks for tuning in. Bye.
Goodbye, everybody.
Bye.
Thank you.