Okta SSO
Configure SAML SSO between Okta and platform, including domain verification, attribute statements, relay status, group-based access, and troubleshooting.
This guide guides you through setting SAML Single Sign-On between Okta and the platform.
Prerequisites
Section entitled ‘Prerequisites’- Okta administrator access
- the platform organization administrator access
- Your platform domain (for example,
probo.example.com) - Access to DNS settings for domain verification
Prepare the platform Information
Section entitled “Prepare the Platform Information”Before you set up Okta, collect the following details about the platform’s service provider:
| Field | Value |
|---|---|
| ACS URL | https://your-probo-domain.com/api/connect/v1/saml/2.0/consume |
| Entity ID | https://your-probo-domain.com/api/connect/v1/saml/2.0/metadata |
Replace your-probo-domain.com with your actual platform domain.
Domain Verification
Section “Domain Verification”Before you set up anything else, you need to check the domain property:
- Log in to the platform as an organization administrator
- Go to Organization Settings → Authentication → SAML
- Click Verify Domain (If there are no configurations yet, this option will be available)
- Copy the provided TXT record value
- Add a TXT record to your domain’s DNS settings:
Type: TXTName: _probo-domain-verification.your-company.comValue: [Verification token from Probo]TTL: 300 (or your DNS provider's default)
- Wait for DNS propagation (usually 5-15 minutes)
- In the platform, click Complete Verification
- In case of success, the domain status will be displayed as "Verified"
Configure Okta
Section entitled “Octa Configuration”-
Sign up to you. Okta Admin Console
-
Go to Applications → Applications
-
Click Create App Integration
-
Select SAML 2.0
-
Click Next
-
Configure the general settings:
Field Value App name ProboApp logo Upload the platform logo (optional) App visibility Check desired options -
Click Next
-
Configure the SAML settings:
Field Value Single sign on URL https://your-probo-domain.com/api/connect/v1/saml/2.0/consumeUse this for the recipient URL and the destination URL ☑️ (Check this box) Audience URI (SP Entity ID) https://your-probo-domain.com/api/connect/v1/saml/2.0/metadataDefault Relay State [SAML Configuration ID](optional - see note below)Name ID format EmailAddressApplication username EmailImportant: The Default Relay State is optional, but if you want to support the connection streams initiated by IdP, it must be set to your exact SAML configuration ID (not a locholder). If the setting is incorrect, SSO will not work. You will get this ID after creating the SAML configuration in the platform. You can initially leave this ID empty and you can update it later with the exact configuration ID.
-
Add the following attribute statements:
Name Name format Value emailUnspecified user.emailfirstNameUnspecified user.firstNamelastNameUnspecified user.lastNameroleUnspecified user.role(optional) -
Click Next
-
Select I am an Okta client adding an internal application
-
Set App type A: Internal Application for Employees
-
Click Finish
-
Mergeţi la Sign On Camp of your platform application
-
Click View SAML setup instructions
-
Save these values Pentru configurarea platformei:
- Identity Provider Single Sign-On URL
- Identity Provider Issuer
- X.509 Certificate
-
Mergeţi la Assignments tab
-
Click Assign → Assign to People or Assign to Groups
-
Select users/groups that should have access to the platform
-
Click Assign and Done
Configure the platform
Section entitled “Configure the platform”-
Log in to the platform as an organization administrator
-
Go to Organization Settings → Authentication → SAML
-
Click Add SAML Configuration
-
Configure the basic settings:
Field Value Notes Email Domain your-company.comYour organization’s email domain Enforcement Policy OPTIONALRecommended for initial setup -
Configure the identity provider settings with the values in Okta:
Field Value Notes IdP Entity ID [Identity Provider Issuer]Copy from Okta setup IdP SSO URL [Identity Provider Single Sign-On URL]Copy from Okta setup IdP Certificate [X.509 Certificate]Copy from Okta setup -
Configure the attribute mappings:
Field Value Notes Email Attribute emailMaps to user email First Name Attribute firstNameMaps to user first name Last Name Attribute lastNameMaps to user last name Role Attribute roleOptional; values OWNER,ADMIN,EMPLOYEE, orVIEWER -
Configure user settings:
Field Value Notes Auto Signup EnabledAllows new users to automatically register through SSO -
Click Save Configuration
-
Copy the SAML Configuration ID which appears after saving (for example,
saml_config_1a2b3c4d)
Update Okta Relay State
Section entitled “Update Okta Relay State”Go back to Okta to activate the login initiated by IdP:
- Access the platform application in the Okta Admin Console
- Click General tab → Edit SAML Settings
- In the Default Relay State field, enter your SAML configuration ID
- Click Next → Next → Finish
Troubleshooting
Section “Troubleshooting”“SAML assertion audience mismatch” Error
“SAML assertion audience mismatch” Error”- CauseDisappearance of the audience URI between Okta and the platform
- SolutionMake sure that the audience URI in Okta matches exactly with the entity ID:
- Should be:
https://your-probo-domain.com/api/connect/v1/saml/2.0/metadata
- Should be:
“User not assigned to application” Error
“User not assigned to application” Error- CauseUser not assigned to the platform application in Okta
- SolutionAssign a user to the app in the Octa's Assignments tab
Attributes Not Mapping
Section titled “Attributes Not Mapping”- Cause: Incorrect attribute statement names in Okta
- Solution: Verify attribute statement names match exactly:
email,firstName,lastName
“Invalid RelayState” Error
Section titled “Invalid RelayState” Error”- Cause: Incorrect Default Relay State configuration
- SolutionMake sure the Default Relay Status is either empty or set to the exact SAML configuration ID on the platform
Debugging Steps
Posts Tagged ‘Debugging Steps’Check Okta System Log
Section titled “Check Okta System Log”- Go to Okta Admin Console → Reports → System Log
- Filter by application name (platform)
- Search for authentication errors and error details
Advanced Configuration
Section “Advanced Configuration”Custom Attributes
Posts Tagged ‘Custom Attributes’To map additional Okta user attributes:
- In Okta, add custom attributes to user profiles
- Add attribute statements to the SAML application configuration
- Mapping these attributes in the SAML platform configuration
Group-Based Access
Section “Group-Based Access”Control access using Okta groups:
- Creating groups in Okta for access to the platform
- Assign users to appropriate groups
- Assigning the platform application to groups instead of individual users
- Use group filters for fine-grained access control
For detailed troubleshooting and advanced configuration options, see SSO Overview guide.