Audience: Administrators
Overview
Okta is an Identity Management Platform, which allows customers to access their web apps in one location.
The following article provides guidance for configuring SSO within Okta, so that you can successfully integrate with OrgChart.
Creating an SSO Integration
1. Log in to your Okta Admin Dashboard.
2. Click on the Applications dropdown menu in the (left side panel), and then select the Applications option.
3. Click on the Create App Integration button.
4. Select SAML 2.0 from the list of app integration options, and then click Next.
5. Enter a name for the application (i.e. OrgChart).
6. Optionally, choose an app logo to display on the OrgChart tile, as well as your app visibility options, and then click Next.
7. Configure the SAML settings as seen below:
Single sign on URL |
https://{SERVER NAME}.theorgchart.com/saml/sso_acs?entityID=YOUR_ENTITY_ID |
Recipient URL |
https://{SERVER NAME}.theorgchart.com/saml/sso_acs?entityID=YOUR_ENTITY_ID |
Destination URL |
https://{SERVER NAME}.theorgchart.com/saml/sso_acs?entityID=YOUR_ENTITY_ID |
Audience URI (SP Entity ID) |
https://{SERVER NAME}.theorgchart.com/saml/sso_metadata?entityID=YOUR_ENTITY_ID |
Name ID Format | EmailAddress |
Application username | Okta username |
Note
YOUR_ENTITY_ID refers to your Okta generated entity ID, and is also referred to in Okta as the SAML Issuer ID.
This value is generally formatted with your Org External Key. If you do not know your org external key, temporarily populate each URL in the General SAML Settings section, click on Next > I'm an Okta Customer > Finish.
On the Sign On tab, scroll to the SAML Signing Certificates section, click on the Actions button (for the Active certificate), and then select View Idp Metadata.
Your Okta Entity ID appears after the entityID indicator in the first line of the XML. Copy the entire key (without the quotation marks), and then paste this value into a separate document.
Click on the General tab, edit the General SAML Settings, and then paste your Okta Entity ID into each URL, replacing the YOUR ENTITY ID text.
8. Click on the Advanced Settings hyperlink.
9. Ensure that Advanced SAML Settings are configured as seen below:
10. Optionally, configure Attribute and/or Group Attribute Statements. Reference the Okta SAML Attribute Mapping article for more information.
11. Click Next.
12. Select the following options on the Okta feedback page, and then click on Finish.
-
I am an Okta customer adding an internal app
13. Once you've finished, assign the application to the desired users, and then configure SSO in OrgChart.
Configuring SSO in OrgChart
1. Click on the Settings button in the bottom right corner, and then select the Account Settings option from the list.
2. Select the Authorization option from the top panel and scroll down to the SSO Configuration heading and click on the +Add SSO Configuration button.
3. The SSO Configuration panel is displayed.
4. Enter the Okta Entity ID into the SSO Entity ID text box.
5. Click on the Metadata Type dropdown menu, and then select the Remote option.
6. In Okta, open the OrgChart app that you've created, and then click on the Sign On tab.
7. Scroll to the SAML Signing Certificates section, click on the Actions button (for the Active Certificate), and then select the View IDP Metadata option. An tab containing a link to the metadata XML is opened.
8. Copy the URL.
9. Paste the metadata URL into the Metadata Location text box in the OrgChart SSO Configuration panel.
10. Click on the NameID Handling dropdown menu, and then select the Main SAML Assertion option.
11. Optionally, add SAML Attribute Handling to use Okta data to update user information or map security groups. Reference the Okta SAML Attribute Mapping article for more information.
12. Check the SSO Enabled checkbox to enable user to sign in to OrgChart from Okta.
13. Optionally, check the Auto-Provision checkbox to automatically create new users if they do not already exist in OrgChart.
14. Optionally, check the Single Logout checkbox to automatically sign users out of Okta when signing out of OrgChart.
15. Click on Save.
Comments
0 comments
Please sign in to leave a comment.