KOP Integrations - Okta - Rafay Product Documentation

Integration with SAML

Follow the steps documented below to integrate your Org and Okta Organizations for Single Sign On (SSO).

Step 1: Create IdP

Within an org, the domain of an IdP cannot be used for another IdP. A domain existing in an org can be used in multiple orgs (for one IdP in each org)

Encrypting SAML assertions is optional because privacy is already provided at the transport layer using HTTPS. Encrypted assertions provide an additional layer of security on top ensuring that only the SP (Org) can decrypt the SAML assertion.

Step 2: View SP Details

The IdP configuration wizard will display critical information that you need to copy/paste into your Okta Org. Provide the following information to your Okta administrator.

Step 3: Create App in Okta

Step 4: General Settings

In step 1 of the application configuration wizard

Step 5: Configure SAML

In step 2 of the application configuration wizard

In the Group Attribute Statements section,

The "Group" configuration step is critical because it will ensure that Okta will send the groups the user belongs to as part of the SSO process. The controller uses the group information to transparently map users to the correct group/role.

<br>1<br> <br>Use same Group Attribute Name provided in Create IdP section(step 1).<br>

Complete the Feedback portion of the Okta app wizard.

Step 6: Specify IdP Metadata

Copy the "Identity Provider Metadata" URL from the App

Step 7: Assign Users and Groups

Once your Org and Okta are integrated using the steps documented above, customers need to create and assign "Groups" in Okta to the application. Multiple Okta users can be added/removed from this group.

An identical named group needs to be created on your Org. Ensure that this group is mapped to the appropriate Projects with the correct privileges.

It is important to emphasize that because of SSO via Okta, user lifecycle management can be completely offloaded to the IdP. In the example below, note that there are no users managed in this group because they are all managed in the attached Okta Org.