Enable Oomnitza users to use Okta Single Sign-On (SSO) to authenticate and log in to Oomnitza.
Planning the integration
Before you create the integration, you must configure your Okta instance. To do this, you log into Okta as a super organization administrator and complete the following actions:
- Add the Oomnitza application to Okta. On the Browse App Catalog page, add the Oomnitza integration.
- Configure the general settings for the Oomnitza app. Add a label to identify the instance such as Oomnitza Production and add the subdomain of your Oomnitza instance.
- Get the embed link of your Okta instance. On the General tab, copy the embed link.
- Generate and download the SAML signing certificate. On the Sign On tab, go to the SAML Signing Certificates section and generate and download a certificate.
To sync Oomnitza with Okta, you require:
- The embed link for your Okta instance
- The SAML signing certificate that you downloaded
Creating the integration
- In Oomnitza, click Configuration > Integrations > Overview.
- Click Block view
.
- On the Integrations page, scroll down to the SSO Integrations section.
- Click the Okta tile.
- Click CONNECT.
- Paste the embed link of your Okta instance for Oomnitza as your SSO URL.
- Upload the SAML signing certificate that you generated in Okta.
- Optional. Select JIT Provisioning. JIT provisioning automatically creates a user account the first time that a user log in to an application. If disabled, you must add a user account for each new user in Oomnitza. If you select JIT Provisioning, you must also select a default role such as Employee. This is the Oomnitza role that is assigned to new users. The name identifier is set to the email address of the user.
- Optional. To enforce single sign-on, select SSO Only.
- Optional. Select Enable multifactor authentication.
- Click FINISH.
Verifying your SSO login
- Navigate to the Oomnitza login page.
- Click Sign in with Okta. Your Okta login page should appear.
- Follow the prompts to verify your identity with Okta and log in to Oomnitza.
Troubleshooting
You will get a 401 Unauthorized response when you log into Oomnitza if the Okta user is not a valid user in Oomnitza.
Comments
0 comments
Please sign in to leave a comment.