Configure Okta for SAML and SSO

Observe by Snowflake supports using Okta as an IdP with SAML support. Observe by Snowflake supports the following features:

  • Identity Provider(IdP)-initiated SSO
  • Service Provider-initiated SSO
  • Just-In-Time Provisioning
📘

Note

Use of stem names instead of Observe by Snowflake Customer IDs is not supported at this time.

Configure Okta for SAML

  1. Log into Okta as the admin and go to the Admin page.

  2. Navigate to Applications > Applications > Browse App Catalog.

  3. Enter observe into the App Catalog search field and choose Observe.

  4. Select Observe from the list of apps, and click Add.

  5. Enter your Observe by Snowflake customer ID as the Customer ID.

  6. Enter the base domain for your region as the Base Domain. For example, if the URL for your Observe by Snowflake tenant is 123456789012.eu-1.observeinc.com, then the base domain is eu-1.observeinc.com.

  7. Select Do not display application icon in the Okta mobile app.

  8. Add users and groups to Okta.

  9. Click View Setup Instructions. Copy the text of the SAML certificate.

Group membership attributes

Observe by Snowflake supports receiving group membership claims via SAML. In the Sign On configuration area of the Observe by Snowflake app for Okta, click "Edit" in the top right, and then expand Attributes (optional) section, and select Group Attribute Statements (optional) and in the Name field, type groups (note this is case sensitive).

Configure Observe by Snowflake

Perform the following steps to configure Observe by Snowflake for Microsoft Entra ID SSO:

  1. In the left navigation rail, hover on your user name, then select Manage account.
  2. Click Customer settings.
  3. Click Add SAML.
  1. In your Okta app, copy the value for Sign on URL and paste it into the Entry point field.
  1. Copy or download the Signing Certificate from your Okta app, and paste the certificate into the Cert field.
📘

Note

Certificates must be in PEM/Base64 encoded format. The format starts with -----BEGIN CERTIFICATE----- and ends with -----END CERTIFICATE----- and contains a base64 encoded string between the two.

  1. Click Add SAML Provider to finish the configuration.

Did this page help you?