Configure SSO with Okta

Before you begin — Read SSO Integration: How It Works first. Each user's Sfax Username must equal their email address.

In the Okta Admin console, go to Applications › Create App Integration › SAML 2.0.

Okta field Value
Single sign-on URL https://app.sfaxme.com/sso/sso.aspx (keep “Use this for Recipient URL and Destination URL” checked)
Audience URI (SP Entity ID) https://app.sfaxme.com/
Name ID format EmailAddress
Application username Email
Single Logout URL (optional) https://app.sfaxme.com/sso/slo.aspx
Note — In Okta, the Single sign-on URL is the ACS itself and is required. It is used for IdP-initiated sign-on, and users launch Sfax from the Okta dashboard.

Common Pitfalls

  • Application username or Name ID set to the Okta username instead of the email.
  • Assertion Signature set to Unsigned - the assertion must be signed (Signed is the Okta default).
  • Users/groups not assigned to the app.

‹ Back to SSO overview