Role Required: SDAdmin
- Log in to your Okta domain.
- Go to the Applications > Add Application.
- Click Create New App.
- From the displayed dialog box, choose SAML 2.0 as the sign-on method.
- Click Create.
- In the next window, provide a Name for your application.
- Upload the Logo of the application and click Next.
- In the displayed page, enter the Assertion Consumer URL of AssetExplorer under Single Sign-On URL.
- Enter the Entity ID in the Audience URI field and choose transient as the Name ID format. Currently, AssetExplorer supports Transient, Persistent, and Email Address as Name ID formats.
- To log in using your username and domain, select Transient or Persistent.
- To log in using your email address, select Email Address.
- Select the Application username from the drop-down menu. Login names of new users will be mapped based on the specified format. If the user belongs to a domain, Okta will use the <domain name\user name> format.
- Click Advanced Settings.
- To enable the SAML logout service, select Allow the application to initiate Single Logout.
- Provide the Single Logout URL and add the entity ID in SP Issuer.
- In Signature Certificate field, click Browse and upload the SP Certificate of AssetExplorer.
- Click Next.
- Choose the option, I'm a Software Vendor. I'd Like to integrate my app with Okta.
- Click Finish.
- Go to the Sign On tab and click View Setup Instructions.
- Another tab with the IdP configurations such as Login URL (Single Sign-On URL), Logout URL (Single Logout URL), and the certificate file will be displayed. Use these to integrate with the IdP.
- Assign the application to people/groups from the Assignments tab, as shown below.
You have now configured AssetExplorer as a service provider in Okta.
Go to the SAML configuration page in AssetExplorer and provide the IdP details to complete the integration.