Configure Okta for SAML and SSO

Observe supports using Okta as an IdP with SAML support. Observe supports the following features:

  • Identity Provider(IdP)-initiated SSO
  • Service Provider-initiated SSO
  • Just-In-Time Provisioning
📘

Note

Use of stem names instead of Observe Customer IDs is not supported at this time.

Configure Okta for SAML

  1. Log into Okta as the admin and go to the Admin page.

  2. Navigate to Applications > Applications > Browse App Catalog.

  3. Enter Observe into the App Catalog search field and choose Observe.

  4. Select Observe from the list of apps, and click Add.

  5. Enter your Observe customer ID as the Customer ID.

  6. Enter the base domain for your region as the Base Domain. For example, if the URL for your Observe tenant is 123456789012.eu-1.observeinc.com, then the base domain is eu-1.observeinc.com.

  7. Select Do not display application icon in the Okta mobile app.

  8. Add users and groups to Okta.

  9. Click View Setup Instructions. Copy the text of the SAML certificate.

Group membership attributes

Observe supports receiving group membership claims via SAML. In the Sign On configuration area of the Observe app for Okta, click "Edit" in the top right, and then expand Attributes (optional) section, and select Group Attribute Statements (optional) and in the Name field, type groups (note this is case sensitive).

Configure Observe

Perform the following steps to configure Observe for Microsoft Entra ID SSO:

  1. In the left navigation rail, hover on your user name, then select Manage account.
  2. Click Customer settings.
  3. Click Add SAML.
  1. In your Okta app, copy the value for Sign on URL and paste it into the Entry point field.
  1. Copy or download the Signing Certificate from your Okta app, and paste the certificate into the Cert field.
📘

Note

Certificates must be in PEM/Base64 encoded format. The format starts with -----BEGIN CERTIFICATE----- and ends with -----END CERTIFICATE----- and contains a base64 encoded string between the two.

  1. Click Add SAML Provider to finish the configuration.