Set up Okta as an identity provider
Before you begin
Create an Okta developer account.
To integrate Okta as an IdP in SIA and create an internal application in Okta for authentication:
-
Download and deploy an identity connector. For more information, see Create and download an identity connector.
-
Add AD to SIA. As part of this process, make sure you assign the identity connector you created to the directory. For more information, see Add a directory.
-
Assign the directory that you created in SIA to the Okta IdP. For more information, see Assign AD to the Okta identity provider.
-
If this is the first Okta IdP that you are creating in SIA, add domains to the SIA network configuration that are specific to Okta. For more information, see Add identity provider domains to an exception list.
Import Active Directory (AD) users and groups into Okta
To import AD users and groups into Okta and assign specific AD user and groups to the application:
-
Log in to the Okta development portal.
-
Click Admin to access the main Administration UI.
-
Import users and groups from the AD. Select Directories > Directory Integrations > Add Active Directory.
-
Follow the on-screen instructions to install and approve the Okta AD Agent onto a host in your AD domain.
-
Select the users and groups to sync from AD to Okta. Optionally, select the username format to use during Okta login.
-
Select the AD user attributes to import to Okta.
-
Import users. Click Import > Import Now > Full import.
-
When you import AD users for the first time, you need to create associated Okta accounts. Select all imported users and confirm the assignments.
-
Activate the new user accounts. Select Directory > People.
-
Filter the list. Select Pending Activation.
-
Activate all of the new accounts. Your People list shows the AD users in an active state.
Next steps
Create a new application in Okta.
Create a new application in Okta
Before you begin
Import Active Directory (AD) users and groups into Okta.
To authenticate with Okta, create an internal application in Okta and configure SAML:
-
In Okta, navigate to the Applications tab and click Applications.
-
Click Add application > Create new app.
-
In the dialog, select SAML 2.0 as the sign on method.
-
Click Create.
-
In the General Settings, enter an application name and add an optional logo.
-
In the App visibility section, make sure the options are deselected so the application is visible to end users within their Okta portals.
-
Click Next.
-
On the SAML Settings page, enter this URL into the Single sign on URL and Audience URI fields:
https://<hostname>/saml/sp/response
.where <hostname> is that hostname that you plan to use for the IdP in SIA. This hostname is used for the URL of the login portal.
-
In the Name ID format menu, select EmailAddress.
-
Click Show Advanced Settings. Apply these settings:
-
In the Response menu, select Signed.
-
In the Assertion Signature menu, make sure Signed is selected.
-
In the Assertion Encryption menu, select Signed.
-
In the Authentication context class menu, select PasswordProtectedTransport.
-
-
Do not enter settings into the ATTRIBUTE STATEMENTS (OPTIONAL) area.
-
In the GROUP ATTRIBUTE STATEMENTS (OPTIONAL) area, enter this information:
-
In the Group Name field, enter
Group
. -
Do not specify a group filter. Leave the filter field blank.
-
-
Click Next.
-
Confirm that the app you're creating is internal.
-
Click Finish. After the Okta application is created, click the Identity Provider metadata link to download the
metadata.xml
file.
Next steps
-
Assign imported users or groups to the application your created:
-
In the Assignment tab of the application you added, click Assign.
-
Select Assign to People or Assign to Groups.
-
Enter the people or groups that you want to authenticate with the Okta IdP.
-
Click Assign.
-
Verify the attributes, and click Save and Go Back.
-
Click Done.
-
Add Okta as an identity provider
This setup might fail without parameter values that are customized for your organization. Use the Okta Administrator Dashboard to add an application and view the values that are specific for your organization.
To add Okta as an IdP in SIA:
-
In the Threat Protection menu of Enterprise Center, select Identity & Users > Identity Providers.
-
Click the plus sign icon
-
Configure basic IdP settings:
-
In the Name and Description fields, enter a name and description of the IdP.
-
In the Provider Type menu, select Okta.
-
Click Continue.
-
-
Complete the IdP general settings:
-
Go to the General settings section or click the General tab.
-
For Identity Intercept, select Use Akamai domain.
-
Enter an external hostname that you want to use for the URL of the login portal.
-
In the Akamai Cloud Zone, select a cloud zone that is closest to the user base.
-
-
Complete these steps in the Session section:
- For the Session Idle Expiry setting, enter a time that is 35 minutes or more.
- Use the default settings for the Limit Session Life and Max Session Duration settings.
-
In the authentication configuration area:
-
Go to the Authentication section or click the Authentication tab.
-
In the URL, enter the Okta subdomain.
-
In the Logout URL, copy and paste this URL into this field. To get this information, you need to sign in to the Okta Admin Dashboard to generate this variable.
-
If Okta requires a signed SAML request, select Sign SAML request to send the signed SAML assertion to Okta.
-
If Okta sends encrypted SAML responses to SIA, select this Encrypted SAML response checkbox to use certificates to encrypt responses. In the Certificate for IDP to encrypt responses field, use the provided certificate that's required to encrypt responses.
-
Upload the
metadata.xml
file that you downloaded from Okta. Click Choose File and then select the file.
-
-
In the Advanced Settings, select Enable Authorization.
-
Click Save.
Next steps
-
Download and deploy an identity connector. For more information, see Create and download an identity connector.
-
Add the directory to SIA. As part of this process, make sure you assign the identity connector you created to the directory. For more information, see Add a directory.
Assign AD to the Okta identity provider
Before you begin
Add AD to SIA. For instructions, see Add a directory.
To review the process of setting up Okta as an IdP, see Set up Okta as an identity provider.
To assign AD to your Okta IdP:
-
In the Threat Protection menu of Enterprise Center, select Identity & Users > Identity Providers.
-
Click the name of the Okta IdP.
-
Click the Directories tab.
-
Click the link icon and select the AD that you added.
-
Click Associate.
Next steps
-
Deploy the IdP:
-
In the SIA IdP configuration, you can click the icon next to the Ready for Deployment status. A deployment icon also appears next to a failed deployment status in case you need to deploy the IdP again. This action starts the deployment process.
-
Deploy IdP configuration changes in the list of Pending Changes. For instructions, see Deploy configuration changes.
-
-
If this is the first Okta IdP that you are creating, add the Okta IdP domains to an exception list. See Add identity provider domains to an exception list.
-
Associate the IdP with a policy that's enabled for authentication. For more information, see Require authentication to access a website or web application.
Updated over 1 year ago