About Okta SAML Integration
Single Sign-On with Okta (SAML) in Iru Endpoint lets you set up SAML-based SSO integration with Okta for users accessing Iru Endpoint through their Okta credentials.How It Works
Okta SAML integration lets users authenticate to Iru Endpoint using their existing Okta credentials. Once configured, users can access Iru Endpoint through a single sign-on experience. The integration works by establishing a trusted relationship between Iru Endpoint and Okta, where Okta acts as the identity provider (IdP) and Iru Endpoint acts as the service provider (SP). When users attempt to access Iru Endpoint, they’re redirected to Okta for authentication, and upon successful login, Okta sends a SAML assertion back to Iru Endpoint confirming the user’s identity.Setting Up the SAML Connection
Navigate to the Account Menu Button
Access Authentication Settings
Add New Connection
Add Authentication Method
Create Connection
Configuration Information
Copy Required URLs
Keep Tab Open
Configuring Okta Application
Log in to Okta
Navigate to Applications
Create App Integration
Select SAML 2.0
Configure App Details
Configure SAML Settings
Set Entity ID
Configure Identity Settings
Continue Configuration
Set App Type
Complete Setup
View SAML Instructions
Copy Issuer Information
Copy Sign-On URL
Download Certificate
Assigning Users to the Okta App
Navigate to Assignments
Assign to People
Search for User
Complete Assignment
Verify Assignment
Configuring Iru Endpoint SAML Connection
Return to Iru Endpoint
Set Connection Name
Configure Sign In URL
Add IdP Entity ID
Upload Certificate
Configure User Attributes
- Set IdP attribute to Subject.
- Leave Attribute name blank.
- Set User attribute to UPN.
Configure Signing Settings
Set Request binding
Save Connection
Allow for Tenant Authentication
Once you have configured the SAML connection in Iru Endpoint and your identity provider, you can allow its use for tenant authentication. For step-by-step instructions, please refer to the Allowing Tenant Authentication and Managing Connections section in our Single Sign-on support article.Enforcing Single Sign-On
Once you have configured at least one Single Sign-on connection, you can disable Passkey, Google Social, and Microsoft Social connections. Disabling these connections will disable the ability for Iru Endpoint administrators in your tenant to authenticate via those methods. Please refer to our Single Sign-on support article for step-by-step instructions.Testing the Integration
Add Test User
Configure User Information
Submit User
Close Invite Window
Refresh Access Page
Test SSO Login