Applies to: Okta
Summary
This article provides instructions for setting up Okta integration with Cloud Portal.
IMPORTANT: This process requires coordination between the Cloud Portal
Administrator and the Okta IT Administrator.
Setting Up Okta
Cloud Portal Admin: Prepares the Files
To prepare files in Cloud Portal:
- Log in to Cloud Portal.
- Navigate to Settings > Organization settings
- Click the Identity providers tab.
- In the Option section, select the radio button for either Auth (SSO) only or Auth & Provisioning.
Refer to Okta: Overview and Policies to understand which option best fits your organization.
- In the SAML configuration section, click Download to save the metadata file.
The metadata file contains the audienceURI and singleSingOnURL needed to set up SAML in Okta.
- Send the file to the Okta IT Administrator.
Okta IT Admin: Creates the SAML Application
To create SAML application in Okta:
- Log in to Okta and go to the Admin page.
- In the navigate bar on the left, click Admin Console > Applications > Applications.
- Click Create App Integration.
- In the Sign-in method section, select the radio button for SAML 2.0, then click Next.
- Enter App name and click Next.
- Configure SAML Settings using metadata.
Single sign-on URL: Found in the SAML.txt file from the Cloud Portal admin
Audience URI (SP Entity ID): Found in the SAML.txt file from the Cloud Portal admin
Name ID format: EmailAddress
Application username: Okta username
- Click Finish.
-
Click the Sign On tab.
- Select View IdP metadata from the Actions drop-down menu.
A new browser opens displaying the raw XML code.
- Click anywhere on the page, select Save as (or press Ctrl + S), and save the file as an XML document.
- Send XML file to the Cloud Portal Admin.
Cloud Portal Admin: Uploads Okta Metadata
Upload the XML file to the Okta integration page in Cloud Portal. Ensure the file is under 1MB.
Cloud Portal Admin: Applies and Verifies Integration
To apply and verify integration:
- Ensure all uploaded and generated information appears correctly on the Cloud Portal screen.
- Click Apply.
Additional Settings for Provisioning
Cloud Portal Admin: Generates SCIM Credentials
IMPORTANT: If you selected the Auth (SSO) only option, skip this section.To generate SCIM credentials:
- In the SCIM configuration section, click Download to download the SCIM.txt file.
- Share these credentials securely with your IT Administrator.
Okta IT Admin: Enables Provisioning
To enable provisioning:
- Click the General tab > Edit.
- In the General > App Settings section, select the SCIM radio button and click Save.
- Navigate to Provisioning > Integration and click Edit.
- Enter your credentials.
SCIM connector base URL: The SCIM endpoint URL from the SCIM.txt
Unique identifier field for user: userName
Supported provisioning actions: Check the following options (Import New Users and Profile Updates, Push New Users, and Push Profile Updates)
Authentication Mode: HTTP Header
Authorization: The SCIM Token from the SCIM.txt
- Click Test Connector Configuration to complete the test, then click Save.
-
In Provisioning > To App, click Enable for the following: Create Users, Update User Attributes, and Deactivate Users.
- Click Save.
Cloud Portal Admin: Applies and Verifies Integration
To apply and verify integration:
- Confirm all uploaded and generated information appears correctly on the Cloud Portal screen.
- Click Apply.
Your Okta integration is now complete.
Comments
0 comments
Please sign in to leave a comment.