Okta
- 08 Jun 2022
- Print
- PDF
Okta
- Updated on 08 Jun 2022
- Print
- PDF
Article summary
Did you find this summary helpful?
Thank you for your feedback
The Okta integration allows you to sync SysAid with your Okta account so you can automatically log in to SysAid whenever you log in to Okta.
For this integration to work, you must be running SysAid 16.1.25 or higher.
Note
Only an admin with SysAid Administrator permissions can set up this integration.
You cannot activate this integration if another single-sign on integration has already been enabled for SysAid.
Set up your SysAid app in Okta
- Login to Okta as an administrator.
- In your Okta console, click Add Application.
- Click Create New App.
- Select the SAML 2.0 option button.
- Click Create.
- Enter SysAid in the App Name field.
- (Optional) Click Browse to select a logo, and click Upload Logo.
- Click Next.
- In the Single Sign On URL field, enter your account URL with the following extension addons/okta/jsp/consume.jsp appended to it.
- In the Audience URI field, enter urn:okta:sysaid.
- From the Name ID Format drop-down list, select EmailAddress.
- From the Application Username drop-down list, select Okta username.
- Click Show Advanced Settings.
ss - From the Response drop-down list, select Signed.
- From the Assertion Signature drop-down list, select Unsigned.
- From the Signature Algorithm drop-down list, select RSA-SHA256
- From the Digest Algorithm drop-down list, select SHA256.
- From the Assertion Encryption drop-down list, select Unencrypted.
- From the Authentication Context Class drop-down list, select X.509 Certificate.
- From the Honor Force Authentication drop-down list, select Yes.
- In the Attribute Statements section add the following attributes:
Name Name Format Value firstName Basic user.firstName lastName Basic user.lastName email Basic user.email username Basic user.login - Click Next.
- In the Feedback tab, click Finish.
- In the Sign On tab, Click View Setup Instructions.
- Copy the URL from the Identity Provider Single Sign-On URL field.
- On the main Third-Party Integrations page, in the Okta icon, click .
- Paste the URL that you copied in step above into the Okta Base URL field.
- Back in Okta, copy the contents of the Identity Provider Issuer field.
- In the original window, click the General tab.
- In the SAML Settings area, click Edit.
- Click Next.
- Click Show Advanced Settings.
- Paste the copied contents of the Identity Provider Issuer field into the SAML Issuer ID field.
- Click Next and return to the Sign On tab.
- Copy the contents of the of the X.509 Certificate field between the Begin Certificate and End Certificate lines.
- In SysAid, paste the text into the Okta Certificate field.
- In the Okta CallbackURL field, enter your account URL with the following extension addons/okta/jsp/consume.jsp appended to it.
- In Okta, from the main menu, select Security>API.
- Click Create Token.
- Enter a token name.
- ClickCreate Token.
- Copy the API Token from the Token Value field.
- In SysAid, paste the text into the Okta API Token field.
- (Optional) If you want SysAid to create new users with their Okta IDs, Enter "Y" in the Create New Users field.
- (Optional) If you selected to allow SysAid to create new users with their Okta IDs, you can replace the Okta domain name with any name you want in the Domain Mapping field. For example, "MyDomain= MyCompany.com, MyDomain2= MyCompany.com". If you want user names to contain the user's original domain, leave this field blank.
- Click the slider to activate the Okta integration.
- Click Save Changes.