Enable your Okta users to access 1Password SaaS Manager with Single-Sign-On (SSO). Once you've completed this step you may wish to enable SCIM from Okta.
Create an Okta App Integration from scratch
- Open the Okta Administration UI and navigate to the Applications menu, then select Create App Integration.
- Select SAML 2.0, then select Next.
- Enter 1Password SaaS Manager as the App name.
-
You'll need the SAML Assertion Consumer Service (ACS) URL (Single sign-on URL) and SAML Entity ID (or Audience URI) from SaaS Manager.
To find these, in a separate tab, log in to SaaS Manager and navigate to Settings > Users > Single Sign-On (SSO) > SAML providers.
-
Fill in the following fields:
Single sign-on URL SaaS Manager SAML Assertion Consumer Service (ACS) URL Audience URI (SP Entity ID) SaaS Manager SAML Entity ID Name ID format EmailAddress Application username Email Logo https://brand.1password.com/share/zpjexDZRgpM43TjobjSa/folders/103 -
Under Attribute Statements in Okta add two statements:
Name Value given_name user.firstName family_name user.lastName - Scroll to the bottom and select Next.
- Select I'm an Okta customer adding an internal app.
- Select Finish.
Configure SaaS Manager
The final step is to set up the connection in SaaS Manager.
- In Okta, open your SaaS Manager tile and navigate to the Sign On tab.
- Under SAML 2.0, select Copy to copy the Metadata URL.
- Switch back to the SaaS Manager tab you opened earlier. You should have navigated to Settings > Users > Single Sign-On (SSO) > SAML providers.
- Select New under SAML providers.
- Enter a Name (Okta) and select Metadata from URL.
- Paste in the Metadata URL you took from Okta.
- Select Create.
Test the connection
You can now test the Okta connection.
- Log out of SaaS Manager.
- Assign yourself to the SaaS Manager application in Okta.
- Go to your My Apps page and select on the SaaS Manager tile.
You should be logged in to SaaS Manager successfully.
Troubleshooting
SaaS Manager user accounts are being created using a username rather than an email address
- Find the SaaS Manager application, open the Sign on tab and select Edit.
- From the Credentials Details section, make sure Application username format is set to Email.
Using the Okta App Catalog app
To use the App Catalog app:
Open the Okta Administration UI, and from the Applications menu and select Browse App Catalog.
- Search for Trelica and select the Okta Trelica application. Select Add next to the search result listing.
- Select Done.
Finalize configuration in Okta
- From the Sign On tab, select Edit.
- Scroll down to Advanced Sign-on Settings. You will need to fill in the ACS URL field. This is provided by SaaS Manager.
- In a separate tab, log in to SaaS Manager and go to Settings > Users > Single Sign-On (SSO).
- Copy the SAML Assertion Consumer Service (ACS) URL value and paste it into the Okta ACS URL field.
- Set the Application username format to Email.
- Select Save.
Comments
0 comments
Please sign in to leave a comment.