Configure Okta SAML for SSO
Connect an Okta SAML 2.0 app integration to Azion as the identity provider of your account, so users sign in to Azion Console with their Okta identity.
You can make an Okta custom SAML application the identity provider (IdP) of your Azion account, so users sign in to Azion Console with their Okta corporate identity and no separate Azion password. The work alternates between the Okta Admin Console and Azion Console. For the Azion side alone, or for an Open ID provider, refer to Configure an identity provider for SSO.
Prerequisites
- Administrator access to the Okta Admin Console.
- Access to Azion Console as an Account owner. To sign in, refer to Access Azion Console.
- Every user of the account registered in Azion. The IdP and Azion hold the same users, and a user that does not exist in Azion cannot sign in. To add users, refer to Manage users.
- A text editor to hold the Okta values until you enter them in Azion Console.
Create the SAML app in Okta
Okta requires a single sign-on URL and an audience URI before it saves the app. Use https://sso.azion.com for both now, and replace them with the Azion values later.
To create the app integration in the Okta Admin Console:
- Sign in to the Okta Admin Console.
- On the homepage, under Applications, select Applications.
- Select Create App Integration.
- In the modal, select SAML 2.0 and then Next.
- Enter a name for the app. For example:
Azion SAML. - Select Next.
- In the General section, enter
https://sso.azion.comin Single sign-on URL. - Enter the same URL in Audience URI (SP Entity ID).
- In the Attribute Statements section, set Name to
email, Name format to Basic, and Value touser.email. - Select Next.
- Fill in the Feedback section as required, and select Finish. The app details open.
- Select the Sign On tab.
- Under Metadata details, select More details.
- Copy the Sign on URL to your text editor. Its format is
https://account-name.okta.com/app/app-id/sso/saml. - Copy the Issuer to your text editor. Its format is
http://www.okta.com/app-id. - In the SAML Signing Certificates section, find the active certificate, or generate a new one.
- For the certificate to use with Azion, select Actions > View IdP metadata.
- Copy the value inside the
<ds:X509Certificate>XML tag to your text editor.
Your text editor now holds the sign on URL, the issuer, and the certificate for the Azion form.
Create the identity provider in Azion Console
The Create Identity Provider form takes the Okta values. Azion then generates the values that Okta needs back.
To create the identity provider:
Access Azion Console and, in the account menu, select SSO Management.
Select Add Identity Provider. In Select the Identity Provider, select SAML.
In the General section, enter a Name. For example: Okta IdP SAML.
In the SAML Configuration section, enter the Okta Issuer in Identity provider’s Entity ID URI and the Okta Sign on URL in Sign-in URL.
In X-509 Certificate, paste the certificate, including the -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- tags.
In the Identity Providers list, select the identity provider. In Edit Identity Provider, copy Assertion Consumer Service URL and Service Provider’s Entity ID URI.
The identity provider appears in the Identity Providers list. Do not set it as active until the Okta app carries the Azion values.
Complete the SAML app in Okta
The Azion values replace the temporary https://sso.azion.com entries.
To finish the app in the Okta Admin Console:
- In the Okta Admin Console, open the app for Azion and select the General tab.
- In the SAML Settings section, select Edit.
- Select Next.
- In Single sign-on URL, paste the Assertion Consumer Service URL.
- In Audience URI (SP Entity ID), paste the Service Provider’s Entity ID URI.
- Select Next.
- Select Finish.
The Okta app points at Azion.
Assign users in Okta
Each assigned user signs in with the email configured in Okta. That email must match the email of the user in Azion.
To assign users to the app in the Okta Admin Console:
- In the Okta Admin Console, open the app for Azion and select the Assignments tab.
- In the Assign dropdown, select Assign to People.
- In the list, select Assign next to each user to add.
- Select Save and Go Back.
- Repeat the steps for every user who signs in to Azion through Okta.
The assigned users can reach the app.
Set the identity provider as active
To activate the identity provider:
Access Azion Console and, in the account menu, select SSO Management.
In the row of the identity provider, select Set as active.
Every user of the account, except the Account owner, signs in to Azion Console through Okta. While Okta is the IdP, Okta verifies multi-factor authentication (MFA) instead of Azion. When the account goes back to the Azion login, each user keeps the MFA status that was last active.