> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Single Sign-On with Okta (SAML)

> Configure SAML-based SSO between Okta and Iru Endpoint. Create the SAML application in Okta and map user attributes for admin authentication.

### About Okta SAML Integration

Single Sign-On with Okta (SAML) in Iru Endpoint lets you set up SAML-based SSO integration with Okta for users accessing Iru Endpoint through their Okta credentials.

#### How It Works

Okta SAML integration lets users authenticate to Iru Endpoint using their existing Okta credentials. Once configured, users can access Iru Endpoint through a single sign-on experience.

The integration works by establishing a trusted relationship between Iru Endpoint and Okta, where Okta acts as the identity provider (IdP) and Iru Endpoint acts as the service provider (SP). When users attempt to access Iru Endpoint, they're redirected to Okta for authentication, and upon successful login, Okta sends a SAML assertion back to Iru Endpoint confirming the user's identity. SSO can be used for [Iru Endpoint Web App](/en/endpoint/getting-started/foundation/admins-and-access) sign-in and for [Require Authentication with Automated Device Enrollment](/en/endpoint/enrollment/configure-require-authentication-for-enrollment).

<Tabs>
  <Tab title="Iru Web App Configuration">
    ### Setting Up the SAML Connection

    <Note>
      You'll need to complete the initial setup in Iru Endpoint first to get the configuration information required for Okta. After copying the Entity ID and ACS URL, switch to the [**Okta Configuration**](#okta-configuration) tab and continue with [**Configuring Okta Application**](#configuring-okta-application).
    </Note>

    <Steps>
      <Step title="Navigate to the Account Menu Button">
        In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu).
      </Step>

      <Step title="Access Authentication Settings">
        Click the **Access** option in the menu.

        <Frame>
          <img src="https://mintcdn.com/iru/8BYPjuKZa-zyEEf_/assets/media/images/iru-nav-access.png?fit=max&auto=format&n=8BYPjuKZa-zyEEf_&q=85&s=466fdf5fb47efd6bab8b450a5a1e8302" alt="Screenshot of the account menu with Access option highlighted" width="562" height="1040" data-path="assets/media/images/iru-nav-access.png" />
        </Frame>
      </Step>

      <Step title="Select Admin and Authentication">
        Select the **Admin and authentication** tab (selected by default) and scroll down to **Authentication methods**.
      </Step>

      <Step title="Add Authentication Method">
        Click **+ Authentication method**.
      </Step>

      <Step title="Enter Display Name">
        Enter a display name for the SSO Connection.
      </Step>

      <Step title="Select Authentication Method">
        Select **SAML** for the Authentication method.
      </Step>

      <Step title="Create Connection">
        Click **Create**.
      </Step>

      <Step title="Configuration Information">
        Click **Configuration information** if that section is not already expanded.
      </Step>

      <Step title="Copy Service Provider Entity ID">
        Copy the **Service provider entity ID** into a text document for later use. You'll need this for the Okta configuration.
      </Step>

      <Step title="Copy ACS URL">
        Copy the **Assertion consumer service (ACS) URL** into a text document for later use. You'll need this for the Okta configuration.

        <Frame>
          <img src="https://mintcdn.com/iru/Qq59wQ8jCPy0XJe9/assets/media/images/iru-support-google-saml_11-08-26.png?fit=max&auto=format&n=Qq59wQ8jCPy0XJe9&q=85&s=7d56d5b22f71fb05dd59c83555c02430" alt="Configuration Information, Service provider entity ID, and Assertion consumer service (ACS) URL" width="2166" height="940" data-path="assets/media/images/iru-support-google-saml_11-08-26.png" />
        </Frame>
      </Step>

      <Step title="Keep Tab Open">
        Keep the Iru Endpoint configuration modal open, then switch to the [**Okta Configuration**](#okta-configuration) tab to continue with [**Configuring Okta Application**](#configuring-okta-application).
      </Step>
    </Steps>

    ### Configuring Iru Endpoint SAML Connection

    <Note>
      After completing the Okta configuration, return here to finish [**Configuring Iru Endpoint SAML Connection**](#configuring-iru-endpoint-saml-connection) in Iru Endpoint. You'll need the Single Sign-on URL, IdP Entity ID, and certificate from Okta.
    </Note>

    <Steps>
      <Step title="Return to Iru Endpoint">
        Go back to the Custom SAML modal in Iru Endpoint.
      </Step>

      <Step title="Set IdP Attribute">
        Set **IdP attribute** to **Subject**.
      </Step>

      <Step title="Set Attribute Name">
        Leave **Attribute name** blank.
      </Step>

      <Step title="Set User Attribute">
        Set **User attribute** to **User Principal Name (UPN)**.
      </Step>

      <Step title="Configure Sign In URL">
        Paste the Single Sign-On URL you copied from Okta into the **Sign In URL** text field.
      </Step>

      <Step title="Add IdP Entity ID">
        Paste the **Issuer** information you copied from Okta into the **IdP Entity ID** field.
      </Step>

      <Step title="Upload Certificate">
        Upload the Okta certificate you downloaded earlier.

        <Frame>
          <img src="https://mintcdn.com/iru/rklQKFJvStbahPGs/assets/media/images/okta-saml_14-32-10.png?fit=max&auto=format&n=rklQKFJvStbahPGs&q=85&s=950b5d9781122a1f90b9cd635ed4e1c5" alt="Iru Endpoint upload Okta certificate" width="1626" height="628" data-path="assets/media/images/okta-saml_14-32-10.png" />
        </Frame>
      </Step>

      <Step title="Set Protocol Binding">
        Set the **Protocol Binding** to **HTTP-POST**.
      </Step>

      <Step title="Set Request Algorithm">
        Ensure that the **Request Algorithm** is set to **RSA-SHA256**.
      </Step>

      <Step title="Set Digest Algorithm">
        Ensure that **Sign Request Algorithm Digest** is set to **SHA256**.
      </Step>

      <Step title="Enable Sign Request">
        Ensure that **Sign Request** is enabled.
      </Step>

      <Step title="Set Response Signature Verification">
        Set the **Response Signature Verification** to **Assertion**.
      </Step>

      <Step title="Set Destination">
        Leave the **Destination** field blank.
      </Step>

      <Step title="Set Allowed Signature Algorithm">
        Set **Allowed Signature Algorithm** to **RSA-SHA256**.
      </Step>

      <Step title="Set Allowed Digest Algorithm">
        Set **Allowed Digest Algorithm** to **SHA256**.
      </Step>

      <Step title="Save Configuration">
        Click **Save**.

        <Frame>
          <img src="https://mintcdn.com/iru/rklQKFJvStbahPGs/assets/media/images/okta-saml_14-34-49.png?fit=max&auto=format&n=rklQKFJvStbahPGs&q=85&s=880c2165e29ad89ac1a2f0d4c2f6ad98" alt="Iru Endpoint Save for SAML configuration" width="1622" height="730" data-path="assets/media/images/okta-saml_14-34-49.png" />
        </Frame>
      </Step>
    </Steps>

    ### Allow for Tenant Authentication

    Once you have configured the SAML connection in Iru Endpoint and your identity provider, you can allow its use for tenant authentication. For step-by-step instructions, please refer to the **Allowing Tenant Authentication and Managing Connections** section in our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on).

    ### Limit Authentication to Domain

    When configuring the SAML connection, you can optionally limit authentication to one or more domains. This can be useful when the SSO connection could authenticate to multiple domains. You can limit the authentication to your Iru tenant to a subset of the available domains.

    ### Enforcing Single Sign-On

    Once you have configured at least one Single Sign-on connection, you can disable Passkey, Google Social, and Microsoft Social connections. Disabling these connections will disable the ability for Iru Endpoint administrators in your tenant to authenticate via those methods. Please refer to our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on) for step-by-step instructions.

    ### Testing the Integration

    <Steps>
      <Step title="Add Test User">
        Add a test user to the **Admin Team** in Iru Endpoint by clicking **New User**.
      </Step>

      <Step title="Configure User Information">
        Fill in all of the corresponding user information. This user must exist in Okta and must be assigned to the Okta SSO app in your Okta tenant.
      </Step>

      <Step title="Submit User">
        Click **Submit**.
      </Step>

      <Step title="Close Invite Window">
        Once the invite is submitted, close the Invite User window.
      </Step>

      <Step title="Refresh Access Page">
        Refresh the Access page in Iru Endpoint. You should see the user who was added.
      </Step>

      <Step title="Test SSO Login">
        Go to the user's email to accept the invite and log in with the new SAML SSO connection.
      </Step>
    </Steps>
  </Tab>

  <Tab title="Okta Configuration">
    <Note>
      Before starting the Okta configuration, complete [**Setting Up the SAML Connection**](#setting-up-the-saml-connection) in the [**Iru Web App Configuration**](#iru-web-app-configuration) tab to get the Service Provider Entity ID and ACS URL. You'll need these values to configure the Okta application.
    </Note>

    ### Configuring Okta Application

    <Steps>
      <Step title="Log in to Okta">
        In a new browser tab, log in to the **Admin Console** in your Okta tenant.
      </Step>

      <Step title="Navigate to Applications">
        On the left-hand side, click the reveal triangle next to **Applications**, then click **Applications**.
      </Step>

      <Step title="Create App Integration">
        Click **Create App Integration**.

        <Frame>
          <img src="https://mintcdn.com/iru/rklQKFJvStbahPGs/assets/media/images/okta-saml_13-26-18.png?fit=max&auto=format&n=rklQKFJvStbahPGs&q=85&s=f8146d267d8a186da4ddf0649f059130" alt="Okta Admin Console Create App Integration" width="3130" height="1672" data-path="assets/media/images/okta-saml_13-26-18.png" />
        </Frame>
      </Step>

      <Step title="Select SAML 2.0">
        Select **SAML 2.0** as the app integration type.
      </Step>

      <Step title="Click Next">
        Click **Next**.

        <Frame>
          <img src="https://mintcdn.com/iru/rklQKFJvStbahPGs/assets/media/images/okta-saml_13-28-11.png?fit=max&auto=format&n=rklQKFJvStbahPGs&q=85&s=c5f498d6a75888be8c10b376323734c1" alt="Okta Select SAML 2.0 and Next" width="1868" height="1068" data-path="assets/media/images/okta-saml_13-28-11.png" />
        </Frame>
      </Step>

      <Step title="Configure App Name">
        Enter an **App name**.
      </Step>

      <Step title="Configure App Logo">
        Upload an optional **App logo**.
      </Step>

      <Step title="Click Next">
        Click **Next**.

        <Frame>
          <img src="https://mintcdn.com/iru/rklQKFJvStbahPGs/assets/media/images/okta-saml_13-32-06.png?fit=max&auto=format&n=rklQKFJvStbahPGs&q=85&s=bd0664aac1802e385033206fdf2c846f" alt="Okta App name and App logo and Next" width="2094" height="1114" data-path="assets/media/images/okta-saml_13-32-06.png" />
        </Frame>
      </Step>

      <Step title="Configure SAML Settings">
        In the **Single sign-on URL** field, paste the Iru Endpoint Assertion Consumer Service URL that was copied earlier.
      </Step>

      <Step title="Set Entity ID">
        In the **Audience URI (SP Entity ID)** field, paste the Iru Endpoint Entity ID that was copied earlier.
      </Step>

      <Step title="Configure Name ID Format">
        Ensure that the **Name ID format** is set to **Unspecified**.
      </Step>

      <Step title="Configure Application Username Format">
        Ensure that the **Application username format** is set to **Email**.
      </Step>

      <Step title="Configure Update Username On">
        Ensure that **Update application username on** is set to **Create and update**.
      </Step>

      <Step title="Continue Configuration">
        Select **Next**.

        <Frame>
          <img src="https://mintcdn.com/iru/rklQKFJvStbahPGs/assets/media/images/okta-saml_13-40-151.png?fit=max&auto=format&n=rklQKFJvStbahPGs&q=85&s=3417543a36150419dda2889ee02ccf1d" alt="Okta SAML Single sign-on URL Audience URI and Next" width="2156" height="1600" data-path="assets/media/images/okta-saml_13-40-151.png" />
        </Frame>
      </Step>

      <Step title="Set App Type">
        Select **This is an internal app that we have created**.
      </Step>

      <Step title="Complete Setup">
        Click **Finish**.

        <Frame>
          <img src="https://mintcdn.com/iru/rklQKFJvStbahPGs/assets/media/images/okta-saml_13-43-00.png?fit=max&auto=format&n=rklQKFJvStbahPGs&q=85&s=c54fbf65096003a3d5dd948952a38d9a" alt="Okta This is an internal app and Finish" width="2076" height="916" data-path="assets/media/images/okta-saml_13-43-00.png" />
        </Frame>
      </Step>

      <Step title="View SAML Instructions">
        Back at the **Sign On** tab, find the link to **View SAML setup instructions** and open it in a new browser tab.

        <Frame>
          <img src="https://mintcdn.com/iru/rklQKFJvStbahPGs/assets/media/images/okta-saml_13-45-18.png?fit=max&auto=format&n=rklQKFJvStbahPGs&q=85&s=bdeb7c5068ba8e7fb099a545e6094ab6" alt="Okta Sign On tab View SAML setup instructions" width="3058" height="2354" data-path="assets/media/images/okta-saml_13-45-18.png" />
        </Frame>
      </Step>

      <Step title="Copy Sign-On URL">
        Copy the **Identity Provider Single Sign-On URL** and save it in a text document for later use in Iru Endpoint.
      </Step>

      <Step title="Copy Issuer Information">
        Copy the **Identity Provider Issuer** information and save it in a text document. You will paste this into the **IdP Entity ID** field in Iru Endpoint.
      </Step>

      <Step title="Download Certificate">
        Download the certificate file and save it for use in Iru Endpoint.

        <Frame>
          <img src="https://mintcdn.com/iru/rklQKFJvStbahPGs/assets/media/images/okta-saml_13-47-00.png?fit=max&auto=format&n=rklQKFJvStbahPGs&q=85&s=e5e5021c4bc0b8256e2fa5764ad59385" alt="Okta SAML setup instructions and download certificate" width="2062" height="2548" data-path="assets/media/images/okta-saml_13-47-00.png" />
        </Frame>
      </Step>
    </Steps>

    ### Assigning Users to the Okta App

    <Steps>
      <Step title="Navigate to Assignments">
        Go back to the Okta app and click the **Assignments** tab.
      </Step>

      <Step title="Assign to People or Groups">
        Click the **Assign** dropdown menu and click **Assign to People** or **Assign to Groups**.

        <Frame>
          <img src="https://mintcdn.com/iru/KQpJNroyGoFGl4ii/assets/media/images/okta-saml_13-55-10.png?fit=max&auto=format&n=KQpJNroyGoFGl4ii&q=85&s=3be7abfecc7a23a3effde48b5311a025" alt="Okta app Assignments tab with Assign dropdown for Assign to People or Assign to Groups" width="2798" height="1630" data-path="assets/media/images/okta-saml_13-55-10.png" />
        </Frame>
      </Step>

      <Step title="Search for User or Groups">
        Search for users or groups to assign.
      </Step>

      <Step title="Click Assign">
        Click **Assign** next to the user or group.

        <Frame>
          <img src="https://mintcdn.com/iru/rklQKFJvStbahPGs/assets/media/images/okta-saml_13-58-48.png?fit=max&auto=format&n=rklQKFJvStbahPGs&q=85&s=93e304ba1203c3ffb673aea3a7840500" alt="Okta Assign next to user or group" width="1362" height="1264" data-path="assets/media/images/okta-saml_13-58-48.png" />
        </Frame>
      </Step>

      <Step title="Click Save and Go Back">
        Click **Save and Go Back**.

        <Frame>
          <img src="https://mintcdn.com/iru/rklQKFJvStbahPGs/assets/media/images/okta-saml_14-00-00.png?fit=max&auto=format&n=rklQKFJvStbahPGs&q=85&s=c235f7969d9350a6a92c0cf4105b9af7" alt="Okta Save and Go Back after assigning user" width="1366" height="498" data-path="assets/media/images/okta-saml_14-00-00.png" />
        </Frame>
      </Step>

      <Step title="Complete Assignment">
        Once the user is assigned, click **Done**.

        <Frame>
          <img src="https://mintcdn.com/iru/rklQKFJvStbahPGs/assets/media/images/okta-saml_14-02-18.png?fit=max&auto=format&n=rklQKFJvStbahPGs&q=85&s=8a055702fccba88985abc0519ff12816" alt="Okta Done to complete user assignment" width="1354" height="1222" data-path="assets/media/images/okta-saml_14-02-18.png" />
        </Frame>
      </Step>

      <Step title="Verify Assignment">
        You should see the users or groups that you have selected in the list.

        <Frame>
          <img src="https://mintcdn.com/iru/rklQKFJvStbahPGs/assets/media/images/okta-saml_14-03-12.png?fit=max&auto=format&n=rklQKFJvStbahPGs&q=85&s=8ee91dec080ae455a26743047a8924ad" alt="Okta Assignments list showing assigned users or groups" width="2068" height="1468" data-path="assets/media/images/okta-saml_14-03-12.png" />
        </Frame>
      </Step>
    </Steps>

    <Note>
      After completing the Okta Configuration, return to the **Iru Web App Configuration** tab to finish setting up the SAML connection using the SSO URL, Entity ID, and certificate you copied from Okta.
    </Note>
  </Tab>
</Tabs>
