How to configure SAML 2.0 SSO with Okta ?

SAML 2.0 authentication allows members of your organization to access all the Scaleflex VXP and Portals using using single sign-on (SSO).

The Scaleflex VXP also support SCIM provisioning of users and groups from Okta. See How to configure SCIM 2.0 provisioning with Okta ?

Prerequisites

  • Okta IAM administrator access
  • Scaleflex VXP Administrator access
  • SAML 2.0 SSO is included in any VXP license

Supported features

The Okta/Scaleflex (VXP, Portals) SAML integration supports:

  • IdP-initiated SSO
  • SP-initiated SSO

Configuration steps

  1. In Okta, navigate to Applications > Applications section in the Okta Admin Console
  2. Click on Browse App Catalog
  3. Search for Scaleflex VXP and select the app once found
  4. Click on Add Integration
  5. Update the Application label or leave it as it is, and click on Done
  6. Navigate to the Sign on tab and copy the following 4 values from the Metadata details:

  7. In the Scaleflex Hub, navigate to Settings > Organisation > General and click Add connection in the Access management section
  8. Click Next on the first screen of the wizard and then paste the 4 copied values and click Next

  9. Enter the list of email domains that should trigger SSO (you can enter multiple emails):

  10. Save the configuration and make sure the toggle is on.

SP-initiated SSO

  1. Navigate to https://hub.scaleflex.com
  2. Enter an email address with a domain matching the list of domains configured for SSO (step 9 above)
  3. You will be redirected to Okta for authentication
  4. Once authenticated in Okta, you will be logged in to the Scaleflex VXP Hub.

Troubleshooting

New users must be invited to join the VXP from Settings > Organisation > Users before they can SSO into the Hub or Portals via Okta:

Note: the VXP username needs to match the user's email address in Okta for SSO to function.

If you have any questions or issues, please feel free to contact our Software Support team and mention the following details:

  • Token
  • Short description of the issue (including URLs, screenshot, short video if available)
  • Steps to reproduce the issue

Your SAML setup is now completed. You can now enable SCIM provisioning as well. See How to configure SCIM 2.0 provisioning with Okta ?

 

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.