MyWorkDrive SAML v2.0 Okta Integration Guide

Similar documents
ComponentSpace SAML v2.0 Okta Integration Guide

MyWorkDrive SAML v2.0 Azure AD Integration Guide

Enabling Single Sign-On Using Okta in Axon Data Governance 5.4

Juniper Networks SSL VPN Integration Guide

ComponentSpace SAML v2.0 Configuration Guide

RECOMMENDED DEPLOYMENT PRACTICES. The F5 and Okta Solution for High Security SSO

Integrating VMware Workspace ONE with Okta. VMware Workspace ONE

INTEGRATING OKTA: VMWARE WORKSPACE ONE OPERATIONAL TUTORIAL VMware Workspace ONE

RSA SecurID Access SAML Configuration for Datadog

Google SAML Integration with ETV

Morningstar ByAllAccounts SAML Connectivity Guide

Configuring Single Sign-on from the VMware Identity Manager Service to Marketo

About This Document 3. Overview 3. System Requirements 3. Installation & Setup 4

Okta SAML Authentication with WatchGuard Access Portal. Integration Guide

Configuring Alfresco Cloud with ADFS 3.0

Add OKTA as an Identity Provider in EAA

RSA SecurID Access SAML Configuration for Kanban Tool

Configure Unsanctioned Device Access Control

All about SAML End-to-end Tableau and OKTA integration

Advanced Configuration for SAML Authentication

SafeNet Authentication Manager

Integration Guide. SafeNet Authentication Manager. Using SAM as an Identity Provider for Okta

RSA SecurID Access SAML Configuration for StatusPage

SAML 2.0 SSO. Set up SAML 2.0 SSO. SAML 2.0 Terminology. Prerequisites

Integration Guide. PingFederate SAML Integration Guide (SP-Initiated Workflow)

Configuring Confluence

SAML-Based SSO Configuration

D9.2.2 AD FS via SAML2

Yellowfin SAML Bridge Web Application

esignlive SAML Administrator's Guide Product Release: 6.5 Date: July 05, 2018 esignlive 8200 Decarie Blvd, Suite 300 Montreal, Quebec H4P 2P5

Using Microsoft Azure Active Directory MFA as SAML IdP with Pulse Connect Secure. Deployment Guide

.NET SAML Consumer Value-Added (VAM) Deployment Guide

This documentation will go over how to install Sharepoint for configuring with Panopto.

This section includes troubleshooting topics about single sign-on (SSO) issues.

Okta Integration Guide for Web Access Management with F5 BIG-IP

Using Your Own Authentication System with ArcGIS Online. Cameron Kroeker and Gary Lee

<Partner Name> <Partner Product> RSA SECURID ACCESS Implementation Guide. Citrix NetScaler Gateway 12.0

<Partner Name> <Partner Product> RSA SECURID ACCESS Implementation Guide. PingIdentity PingFederate 8

RSA SecurID Access SAML Configuration for Samanage

CONFIGURING AD FS AS A THIRD-PARTY IDP IN VMWARE IDENTITY MANAGER: VMWARE WORKSPACE ONE OPERATIONAL TUTORIAL VMware Workspace ONE

<Partner Name> <Partner Product> RSA SECURID ACCESS Implementation Guide. Pulse Connect Secure 8.x

ComponentSpace SAML v2.0 Configuration Guide

Oracle WebLogic. Overview. Prerequisites. Baseline. Architecture. Installation. Contents

RSA SecurID Access SAML Configuration for Brainshark

ComponentSpace SAML v2.0 IdentityServer4 Integration Guide

Enabling Single Sign-On Using Microsoft Azure Active Directory in Axon Data Governance 5.2

SAML-Based SSO Solution

Welcome to Oracle Service Cloud Ask the Experts

Unity Connection Version 10.5 SAML SSO Configuration Example

Slack Cloud App SSO. Configuration Guide. Product Release Document Revisions Published Date

PingOne. How to Set Up a PingFederate Connection to the PingOne Dock. Quick Start Guides. Version 1.1 December Created by: Ping Identity Support

TECHNICAL GUIDE SSO SAML Azure AD

Configuring ServiceNow

Quick Start Guide for SAML SSO Access

Upland Qvidian Proposal Automation Single Sign-on Administrator's Guide

Google Auto User Provisioning

Manage SAML Single Sign-On

Integration Guide. SafeNet Authentication Manager. Using SAM as an Identity Provider for PingFederate

2 Oracle WebLogic Overview Prerequisites Baseline Architecture...6

VMWARE HORIZON CLOUD WITH VMWARE IDENTITY MANAGER QUICK START GUIDE WHITE PAPER MARCH 2018

Integrating the YuJa Enterprise Video Platform with Dell Cloud Access Manager (SAML)

Unified Communications Manager Version 10.5 SAML SSO Configuration Example

<Partner Name> <Partner Product> RSA SECURID ACCESS Implementation Guide. Cisco Adaptive Security Appliance 9.5(2)

Table of Contents. Single Sign On 1

OneLogin SAML Authentication with WatchGuard Access Portal. Integration Guide

Single Sign-On with Sage People and Microsoft Active Directory Federation Services 2.0

Webthority can provide single sign-on to web applications using one of the following authentication methods:

You also have the option of being able to automatically delete the document from SharePoint if the Note is deleted within CRM.

SAML Admin Guide. Version 1.0

Configuration Guide - Single-Sign On for OneDesk

Configuring and Delivering Salesforce as a managed application to XenMobile Users with NetScaler as the SAML IDP (Identity Provider)

Quick Start Guide for SAML SSO Access

Version 7.x. Quick-Start Guide

Authentication. August 17, 2018 Version 9.4. For the most recent version of this document, visit our documentation website.

Configuring Single Sign-on from the VMware Identity Manager Service to Trumba

SafeNet Authentication Manager

Quick Connection Guide

SAML SSO Okta Identity Provider 2

Google Apps Integration

Contents Introduction... 5 Configuring Single Sign-On... 7 Configuring Identity Federation Using SAML 2.0 Authentication... 29

Setting Up Resources in VMware Identity Manager (SaaS) Modified 15 SEP 2017 VMware Identity Manager

Configure ISE 2.3 Guest Portal with OKTA SAML SSO

RSA SecurID Access SAML Configuration for Microsoft Office 365

ADFS Setup (SAML Authentication)

Integration Guide. SafeNet Authentication Service. Protecting SugarCRM with SAS

Workday Deployment Guide Version 4.0

Protecting SugarCRM with SafeNet Authentication Manager

Integrating YuJa Active Learning into Google Apps via SAML

Oracle Access Manager Configuration Guide

SAML Authentication with Pulse Connect Secure and Pulse Secure Virtual Traffic Manager

Configuring Single Sign-on from the VMware Identity Manager Service to Bonusly

Udemy for Business SSO. Single Sign-On (SSO) capability for the UFB portal

CLI users are not listed on the Cisco Prime Collaboration User Management page.

Mitel MiContact Center Enterprise WEB APPLICATIONS CONFIGURATION GUIDE. Release 9.2

ISA 767, Secure Electronic Commerce Xinwen Zhang, George Mason University

WebEx Connector. Version 2.0. User Guide

Administering Jive Mobile Apps for ios and Android

IMPLEMENTING SINGLE SIGN-ON (SSO) TO KERBEROS CONSTRAINED DELEGATION AND HEADER-BASED APPS. VMware Identity Manager.

Introduction to application management

Cloud Secure Integration with ADFS. Deployment Guide

Transcription:

MyWorkDrive SAML v2.0 Okta Integration Guide i

Introduction In this integration, Okta is acting as the identity provider (IdP) and the MyWorkDrive Server is acting as the service provider (SP). It is assumed all users are logging in to Okta using their UPN Suffix (eg @yourdomain.com) and it matches their Active Directory username UPN. Identity Provider Configuration 1. Login into Okta. 2. Click the Admin button. 1

3. Click the Add Applications shortcut. 4. Click the Create New App button. 2

5. Select SAML 2.0 as the sign on method. 6. Specify an application name. 3

7. Specify the assertion consumer service URL (eg. https://yourmwdserver.yourdomain.com/saml/assertionconsumerservice.aspx) as the single sign-on URL. Specify the Audience URI (SP Entity ID) - enter MyWorkDrive as the audience URI. Relay state is not required. The name ID format is unspecified. The application user name is the Okta user name. Attribute and group attributes are not required. 4

8. Click the Show Advanced Settings link and check the Enable Single Logout option. Specify the single logout service URL (eg https://yourmwdserver.yourdomain.com/saml/sloservice.aspx) as the logout URL. Specify the SP Issuer. This is the local service provider name Enter MyWorkDrive. Specify the service provider certificate used to sign logout requests. This is a real public certificate installed on the MyWorkDrive Server. For example https://saml.yourdomain.com. A public copy without the private key should be exported and uploaded here to Okta (in a later step we will place the certificate pfx file with the private key in the MyWorkDrive Server SAML folder for use by MyWorkDrive for signing SAML). Click the Upload Certificate button. 5

9. Click the Next button. 10. Click the Finish button. 6

11. View the setup instructions or click the Identity Provider metadata link to download the SAML metadata. 12. Click the View Setup Instructions and record the details. These will be required when configuring the service provider. 7

13. Click the People link and the Assign to People button. For testing a manually created a user with the same username upn suffix okta@yourdomain.com and password can be used. 14. Select a user and click the Assign button. 8

15. Click the Save and Go Back button. 16. Click the Done button. 9

17. Confirm the user is listed. 18. Click the Back to Applications link and confirm the application is listed. 10

MyWorkDrive Server Configuration 1. Update the saml.config located in C:\Wanpath\WanPath.Data\Settings to uncomment out the <PartnerIdentityProvider> entry for Okta located in 2. Place your public SSL Certificate PFX export file into C:\Wanpath\WanPath.Data\Settings\Certificates and reference it in the service provider section with the password you used during the export. 3. In the Okta Identify provider section: Set the Name to the identity provider issuer. This value is also the metadata entityid. 4. In the Okta Identify provider section: Set the SingleSignOnServiceUrl to the identity provider single sign-on URL. 5. In the Okta Identify provider section: Set the SingleLogoutServiceUrl to the identity provider single logout URL. 6. Download the partner certificate file or copy it from the identity provider metadata to C:\Wanpath\WanPath.Data\Settings\Certificates and update the Okta PartnerCertificateFile section with the complete path and name of the file. The partner identity provider configuration section should be similar to the following saml.conf <!-- Okta --> <PartnerIdentityProvider Name=" http://www.okta.com/ exxxxxdasdbo3soogq355" Description="Okta" 11

SignAuthnRequest="true" SignLogoutRequest="true" SignLogoutResponse="true" WantLogoutRequestSigned="true" WantLogoutResponseSigned="true" SingleSignOnServiceUrl="hhttps://yourcompany.okta.com/app/yourcompany_mwd_ 1/exxxxxdasDbO3SoOGQ355/sso/saml" SingleLogoutServiceUrl="https://yourcompany.okta.com/app/yourcompany_mwd_1 /exxxxxdasdbo3soogq355/slo/saml" PartnerCertificateFile="C:\wanpath\WanPath.Data\Settings\Certificates\okta.cer"/> The Service provider section configuration should be similar to the following saml.conf <ServiceProvider Name="MyWorkDrive" Description="MWD Service Provider" AssertionConsumerServiceUrl="~/SAML/AssertionConsumerService.aspx" LocalCertificateFile="C:\Wanpath\WanPath.Data\Settings\Certificates\yourdomain.pfx" LocalCertificatePassword="password"/> Test Okta initiated SSO 1. Log into Okta. 12

2. Click the MyWorkDrive application. 3. You are now automatically logged into the MyWorkDrive Web File Manager application. 13

MyWorkDrive Initiated SSO 1. Browse to the url of your MWD Site /Account/Login-SAML.aspx (for example https://mwdserver.yourdomain.com/account/login-saml.aspx) and click the link to SSO to the identity provider. 14

2. Login to Okta. 3. You are now automatically logged into Okta. 15

Single Logout 1. Click the logout button. You are now logged out of the identity provider and service provider. 16