jump to content

Okta SSO

Configure SAML SSO between Okta and platform, including domain verification, attribute statements, relay status, group-based access, and troubleshooting.

Show as Markdown

This guide guides you through setting SAML Single Sign-On between Okta and the platform.

  • Okta administrator access
  • the platform organization administrator access
  • Your platform domain (for example, probo.example.com)
  • Access to DNS settings for domain verification

Before you set up Okta, collect the following details about the platform’s service provider:

Field Value
ACS URL https://your-probo-domain.com/api/connect/v1/saml/2.0/consume
Entity ID https://your-probo-domain.com/api/connect/v1/saml/2.0/metadata

Replace your-probo-domain.com with your actual platform domain.

Before you set up anything else, you need to check the domain property:

  1. Log in to the platform as an organization administrator
  2. Go to Organization Settings → Authentication → SAML
  3. Click Verify Domain (If there are no configurations yet, this option will be available)
  4. Copy the provided TXT record value
  5. Add a TXT record to your domain’s DNS settings:
    Type: TXT
    Name: _probo-domain-verification.your-company.com
    Value: [Verification token from Probo]
    TTL: 300 (or your DNS provider's default)
  6. Wait for DNS propagation (usually 5-15 minutes)
  7. In the platform, click Complete Verification
  8. In case of success, the domain status will be displayed as "Verified"
  1. Sign up to you. Okta Admin Console

  2. Go to Applications → Applications

  3. Click Create App Integration

  4. Select SAML 2.0

  5. Click Next

  6. Configure the general settings:

    Field Value
    App name Probo
    App logo Upload the platform logo (optional)
    App visibility Check desired options
  7. Click Next

  8. Configure the SAML settings:

    Field Value
    Single sign on URL https://your-probo-domain.com/api/connect/v1/saml/2.0/consume
    Use this for the recipient URL and the destination URL ☑️ (Check this box)
    Audience URI (SP Entity ID) https://your-probo-domain.com/api/connect/v1/saml/2.0/metadata
    Default Relay State [SAML Configuration ID] (optional - see note below)
    Name ID format EmailAddress
    Application username Email

    Important: The Default Relay State is optional, but if you want to support the connection streams initiated by IdP, it must be set to your exact SAML configuration ID (not a locholder). If the setting is incorrect, SSO will not work. You will get this ID after creating the SAML configuration in the platform. You can initially leave this ID empty and you can update it later with the exact configuration ID.

  9. Add the following attribute statements:

    Name Name format Value
    email Unspecified user.email
    firstName Unspecified user.firstName
    lastName Unspecified user.lastName
    role Unspecified user.role (optional)
  10. Click Next

  11. Select I am an Okta client adding an internal application

  12. Set App type A: Internal Application for Employees

  13. Click Finish

  14. Mergeţi la Sign On Camp of your platform application

  15. Click View SAML setup instructions

  16. Save these values Pentru configurarea platformei:

    • Identity Provider Single Sign-On URL
    • Identity Provider Issuer
    • X.509 Certificate
  17. Mergeţi la Assignments tab

  18. Click Assign → Assign to People or Assign to Groups

  19. Select users/groups that should have access to the platform

  20. Click Assign and Done

  1. Log in to the platform as an organization administrator

  2. Go to Organization Settings → Authentication → SAML

  3. Click Add SAML Configuration

  4. Configure the basic settings:

    Field Value Notes
    Email Domain your-company.com Your organization’s email domain
    Enforcement Policy OPTIONAL Recommended for initial setup
  5. Configure the identity provider settings with the values in Okta:

    Field Value Notes
    IdP Entity ID [Identity Provider Issuer] Copy from Okta setup
    IdP SSO URL [Identity Provider Single Sign-On URL] Copy from Okta setup
    IdP Certificate [X.509 Certificate] Copy from Okta setup
  6. Configure the attribute mappings:

    Field Value Notes
    Email Attribute email Maps to user email
    First Name Attribute firstName Maps to user first name
    Last Name Attribute lastName Maps to user last name
    Role Attribute role Optional; values OWNER, ADMIN, EMPLOYEE, or VIEWER
  7. Configure user settings:

    Field Value Notes
    Auto Signup Enabled Allows new users to automatically register through SSO
  8. Click Save Configuration

  9. Copy the SAML Configuration ID which appears after saving (for example, saml_config_1a2b3c4d)

Go back to Okta to activate the login initiated by IdP:

  1. Access the platform application in the Okta Admin Console
  2. Click General tab → Edit SAML Settings
  3. In the Default Relay State field, enter your SAML configuration ID
  4. Click Next → Next → Finish

“SAML assertion audience mismatch” Error

“SAML assertion audience mismatch” Error”
  • CauseDisappearance of the audience URI between Okta and the platform
  • SolutionMake sure that the audience URI in Okta matches exactly with the entity ID:
    • Should be: https://your-probo-domain.com/api/connect/v1/saml/2.0/metadata

“User not assigned to application” Error

“User not assigned to application” Error
  • CauseUser not assigned to the platform application in Okta
  • SolutionAssign a user to the app in the Octa's Assignments tab
  • Cause: Incorrect attribute statement names in Okta
  • Solution: Verify attribute statement names match exactly: email, firstName, lastName
  • Cause: Incorrect Default Relay State configuration
  • SolutionMake sure the Default Relay Status is either empty or set to the exact SAML configuration ID on the platform
  1. Go to Okta Admin Console → Reports → System Log
  2. Filter by application name (platform)
  3. Search for authentication errors and error details

To map additional Okta user attributes:

  1. In Okta, add custom attributes to user profiles
  2. Add attribute statements to the SAML application configuration
  3. Mapping these attributes in the SAML platform configuration

Control access using Okta groups:

  1. Creating groups in Okta for access to the platform
  2. Assign users to appropriate groups
  3. Assigning the platform application to groups instead of individual users
  4. Use group filters for fine-grained access control

For detailed troubleshooting and advanced configuration options, see SSO Overview guide.

Ultima actualizare: