Configure SAML with Okta
Last modified: Thursday February 16, 2023.
Configure Okta as your SAML IdP for Alta Video.
Task — Create custom Okta attributes
- Log in to the Okta Admin Console.
- From within Okta, create a custom Okta user profile attribute. (See: https://help.okta.com/en/prod/Content/Topics/users-groups-profiles/usgp-add-custom-user-attributes.htm.)
This custom attribute should be named appropriately, for example aware_user_group.
Creating this custom attribute as an enumeration of the names of the user groups within the Aware system allows for easier selection of the correct group later.
- For each user requiring access via SAML, set the value of the custom attribute to the NAME of the Aware User Group they should be placed in for your Aware deployment (from
Directory > People > <user> > Profile ).
Task — Configure Okta IdP
- Log in to the Okta Admin Console.
- In
Applications > Applications , clickCreate App Integration . - Select
SAML 2.0 . - Click
Next . - In
Create SAML Integration > General Settings > App name , type Aware Cloud. - Click
Next . - In
Configure SAML > SAML Settings > Single sign-on URL , paste theACS URL you obtained from Alta Video Cloud. - In
Audience URI (SP Entity ID) , paste theEntity ID you obtained from Alta Video Cloud. - To obtain User group information from SAML, configure the following attributes from
Attribute statements : - To configure the AvaAwareEmail name attribute:
- In the
Name field, type AvaAwareEmail. - In the corresponding
Value menu, select user.email (leavingName format set to Unspecified). - To configure the AvaAwareUsername name attribute:
This username will be used in the Aware system, it can be the user's email address or any other suitable unique identifier.
- Click
Add Another . - In the
Name field, type AvaAwareUsername. - In the corresponding
Value menu, select user.email or your preferred login name attribute. - (Optional) To configure the AvaAwareUserGroup name attribute:
- Click
Add Another . - In the
Name field, type AvaAwareUserGroup. - In the corresponding
Value menu, select user.aware_user_group. The attribute value must correspond to at least one role in Alta Video Cloud.This mapping must be to a valid Alta Video Cloud User group.
- Click
Next . - Click
Finish . - In the
Sign on methods panel, clickIdentity Provider metadata .
The metadata appears in your browser. - Right-click the browser pane, and select
Save as to create the IdP metadata file. - Return to the task in Configure Alta Video to enable SAML single sign-on.