Configure Single Sign-On (SSO) for Okta
Single sign-on (SSO) enables ALTR administrators to sign into the ALTR platform without having to remember a separate username, password, and two-factor authentication method. For what SSO controls at the platform level, see SSO and SCIM.
SSO authenticates existing ALTR administrators; it does not create them. Without SCIM, add your administrators in ALTR before you enable SSO.
When enabling SSO, make sure you have:
- Administrator access to your identity provider.
- Super Administrator access to your ALTR account. To check your role, see Administrators.
Configure SSO with Okta
Section titled “Configure SSO with Okta”These steps create a new application in Okta that is used to sign into ALTR. Your Okta administrator should be familiar with this process.
To configure SSO with Okta:
- Create a new application in Okta.
- Sign into the Okta admin console.
- Click Create App Integration to create a new Okta application.
- Set the Sign In method to Security Assertion Markup Language (SAML) 2.0.
- Click Next.
- Under General Settings, enter an App name, such as “ALTR”. If you have multiple ALTR accounts, make the name descriptive of the account you are connecting.
- Click Next.
- Identify the metadata from ALTR needed to configure SSO.
- Sign into your ALTR account.
- Select Settings > Preferences in the navigation menu.
- Select the SSO/SCIM tab.
- Copy the metadata URL and open it in a new browser tab.
- Identify the entityID and Location fields in the XML file.
- Configure the SSO settings in Okta.
- Copy the Location field from ALTR’s metadata file (do not copy the quotation marks) and paste it into the Single sign-on URL field in Okta.
- Select the Use this for Recipient URL and Destination URL checkbox.
- Copy the entityID from ALTR’s metadata file (do not copy the quotation marks) and paste it into the Audience URI (SP Entity ID) field in Okta.
- Ensure the Application username field is set to Okta username.
- If you use ALTR’s sidecar integration, configure the SAML Settings by adding a group attribute statement:
- Locate Group Attribute Statements (optional).
- Enter groups for the Name.
- Select Basic as the Name format.
- Select Matches regex as the Filter and set it to
.*.
- Click Next.
- Verify the This is an internal app that we have created checkbox is enabled.
- Click Finish.
- Provision your ALTR administrators to your Okta application.
- In Okta, go to your ALTR application and select the Assignments tab.
- Select Assign > Assign to People.
- Locate yourself in the list of assigned users. Your Username is in the field below your name, typically shown in gray. Click Assign.
- Click Save and Go Back.
- Click Done.
- In ALTR, select Settings > Administrators in the navigation menu and find your Username.
- Ensure your ALTR Username exactly matches your Username in Okta. The match is case-sensitive. If your ALTR Username does not exactly match your Okta Username, you will not be able to sign into ALTR.
- Repeat these steps for each of your ALTR administrators.
- Configure SSO in ALTR.
- In Okta, click the Sign On tab. Copy the Metadata URL.
- In ALTR, select Settings > Preferences in the navigation menu.
- Click the SSO/SCIM tab.
- Paste the metadata URL into the Provider URL field.
- Select Okta as your IdP.
- Click Enable SSO.
- After ALTR configures SSO, keep your current window open, open an incognito window or a different browser, and sign into your ALTR account. Do not sign out of ALTR in your main window until you have confirmed you can sign into ALTR in the second window.
- Once you have signed into ALTR through SSO, you can sign out of ALTR or close your browser.