Configure SSO with Okta
Before you begin — Read SSO Integration: How It Works first. Each user's Sfax Username must equal their email address.
In the Okta Admin console, go to Applications › Create App Integration › SAML 2.0.
| Okta field | Value |
|---|---|
| Single sign-on URL | https://app.sfaxme.com/sso/sso.aspx (keep “Use this for Recipient URL and Destination URL” checked) |
| Audience URI (SP Entity ID) | https://app.sfaxme.com/ |
| Name ID format | EmailAddress |
| Application username | |
| Single Logout URL (optional) | https://app.sfaxme.com/sso/slo.aspx |
Note — In Okta, the Single sign-on URL is the ACS itself and is required. It is used for IdP-initiated sign-on, and users launch Sfax from the Okta dashboard.
Common Pitfalls
- Application username or Name ID set to the Okta username instead of the email.
- Assertion Signature set to Unsigned - the assertion must be signed (Signed is the Okta default).
- Users/groups not assigned to the app.