---
name: azion-configure-okta-saml-for-sso
description: >-
  Connect an Okta SAML 2.0 app integration to Azion as the identity provider of your account, so users sign in to Azion Console with their Okta identity.
---

# Configure Okta SAML for SSO

You can make an Okta custom SAML application the identity provider (IdP) of your Azion account, so users sign in to Azion Console with their Okta corporate identity and no separate Azion password. The work alternates between the Okta Admin Console and Azion Console. For the Azion side alone, or for an Open ID provider, refer to [Configure an identity provider for SSO](/en/documentation/guides/platform/account-and-billing/sso/).

---

## Prerequisites

- Administrator access to the Okta Admin Console.
- Access to Azion Console as an **Account owner**. To sign in, refer to [Access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).
- Every user of the account registered in Azion. The IdP and Azion hold the same users, and a user that does not exist in Azion cannot sign in. To add users, refer to [Manage users](/en/documentation/guides/platform/account-and-billing/users-management/).
- A text editor to hold the Okta values until you enter them in Azion Console.

---

## Create the SAML app in Okta

Okta requires a single sign-on URL and an audience URI before it saves the app. Use `https://sso.azion.com` for both now, and replace them with the Azion values later.

To create the app integration in the Okta Admin Console:

1. Sign in to the [Okta Admin Console](https://login.okta.com/).
2. On the homepage, under **Applications**, select **Applications**.
3. Select **Create App Integration**.
4. In the modal, select **SAML 2.0** and then **Next**.
5. Enter a name for the app. For example: `Azion SAML`.
6. Select **Next**.
7. In the **General** section, enter `https://sso.azion.com` in **Single sign-on URL**.
8. Enter the same URL in **Audience URI (SP Entity ID)**.
9. In the **Attribute Statements** section, set **Name** to `email`, **Name format** to *Basic*, and **Value** to `user.email`.
10. Select **Next**.
11. Fill in the **Feedback** section as required, and select **Finish**. The app details open.
12. Select the **Sign On** tab.
13. Under **Metadata details**, select **More details**.
14. Copy the **Sign on URL** to your text editor. Its format is `https://account-name.okta.com/app/app-id/sso/saml`.
15. Copy the **Issuer** to your text editor. Its format is `http://www.okta.com/app-id`.
16. In the **SAML Signing Certificates** section, find the active certificate, or generate a new one.
17. For the certificate to use with Azion, select **Actions** > **View IdP metadata**.
18. Copy the value inside the `<ds:X509Certificate>` XML tag to your text editor.

Your text editor now holds the sign on URL, the issuer, and the certificate for the Azion form.

---

## Create the identity provider in Azion Console

The **Create Identity Provider** form takes the Okta values. Azion then generates the values that Okta needs back.

To create the identity provider:

1. **Open SSO Management**

   Access [Azion Console](https://console.azion.com/) and, in the account menu, select **SSO Management**.

2. **Open the create form**

   Select **Add Identity Provider**. In **Select the Identity Provider**, select *SAML*.

3. **Name the identity provider**

   In the **General** section, enter a **Name**. For example: `Okta IdP SAML`.

4. **Enter the Okta values**

   In the **SAML Configuration** section, enter the Okta **Issuer** in **Identity provider's Entity ID URI** and the Okta **Sign on URL** in **Sign-in URL**.

5. **Add the certificate**

   In **X-509 Certificate**, paste the certificate, including the `-----BEGIN CERTIFICATE-----` and `-----END CERTIFICATE-----` tags.

6. **Select Save**

7. **Copy the Azion values**

   In the **Identity Providers** list, select the identity provider. In **Edit Identity Provider**, copy **Assertion Consumer Service URL** and **Service Provider's Entity ID URI**.

The identity provider appears in the **Identity Providers** list. Do not set it as active until the Okta app carries the Azion values.

---

## Complete the SAML app in Okta

The Azion values replace the temporary `https://sso.azion.com` entries.

To finish the app in the Okta Admin Console:

1. In the [Okta Admin Console](https://login.okta.com/), open the app for Azion and select the **General** tab.
2. In the **SAML Settings** section, select **Edit**.
3. Select **Next**.
4. In **Single sign-on URL**, paste the **Assertion Consumer Service URL**.
5. In **Audience URI (SP Entity ID)**, paste the **Service Provider's Entity ID URI**.
6. Select **Next**.
7. Select **Finish**.

The Okta app points at Azion.

---

## Assign users in Okta

Each assigned user signs in with the email configured in Okta. That email must match the email of the user in Azion.

To assign users to the app in the Okta Admin Console:

1. In the [Okta Admin Console](https://login.okta.com/), open the app for Azion and select the **Assignments** tab.
2. In the **Assign** dropdown, select **Assign to People**.
3. In the list, select **Assign** next to each user to add.
4. Select **Save and Go Back**.
5. Repeat the steps for every user who signs in to Azion through Okta.

> **Tip**
>
> To manage single sign-on for many users, create an Okta group for Azion users.

The assigned users can reach the app.

---

## Set the identity provider as active

To activate the identity provider:

1. **Open SSO Management**

   Access [Azion Console](https://console.azion.com/) and, in the account menu, select **SSO Management**.

2. **Set the identity provider as active**

   In the row of the identity provider, select **Set as active**.

3. **Select Confirm**

Every user of the account, except the Account owner, signs in to Azion Console through Okta. While Okta is the IdP, Okta verifies multi-factor authentication (MFA) instead of Azion. When the account goes back to the Azion login, each user keeps the MFA status that was last active.

---

## Next steps

- [Configure Google SAML for SSO](/en/documentation/guides/application-security/access-and-compliance/sso-google-saml.md): Use a Google custom SAML app as the IdP instead.
- [Configure Microsoft Entra SAML for SSO](/en/documentation/guides/application-security/access-and-compliance/sso-microsoft-entra-saml.md): Use a Microsoft Entra enterprise application as the IdP instead.
- [Configure an identity provider for SSO](/en/documentation/guides/platform/account-and-billing/sso.md): Add any SAML or Open ID provider in SSO Management.
- [Manage users](/en/documentation/guides/platform/account-and-billing/users-management.md): Register every user who signs in through the IdP.
