Configure Okta as the external identity provider

Prev Next
  1. Go to Applications and click on the configured application.

    To create a new application, go to Applications>Add Application>Create New App.

  2. Update the following parameters. Platform as Web and Sign on method as SAML 2.0.

  3. Configure the new app.

    • Create a Group named, Trellix-Products-prod.

    • Create a user and associate that to #a.

    • In General Settings, enter the App name as Trellix-demo-pre-prod. Click Next.

  4. Configure SAML settings.

    • Enter Single sign-on URL as https://update.me.

    • Select the checkboxes for Use this Recipient URL and Destination URL.

    • Enter Audience URL (SP Entity ID) as https://update.me.

    • Click Download Okta Certificate.

    • Click Next.

  5. In Feedback, select I'm an Okta customer adding an internal app. Click Finish.

  6. Associate user #4.b to #4.c.i application or Associate #4.a group to #4.c.i application.

  7. Details for the app will be displayed. If it is not displayed, navigate back to Applications and select the new application.

  8. Select the Sign On > View Setup Instructions.

    Note the Identity Provider Single Sign-On URL value and the Identity Provider Issuer value.

  9. Click Download certificate to download the certificate.

Mapping external IdP to IAM roles

Go to the parent topic to update the Identity Provider page. See Enabling single sign-on. Go to the section Mapping external IdP to IAM roles.

Updating Okta

Follow the steps below to update Okta after mapping it to IAM roles.

  1. Navigate to Applications and select the Okta application created.

  2. Select the General > SAML Settings > Edit > Next > Configure SAML tab.

  3. Update the Single sign on URL: Enter Assertion Consumer Service URL from the Identity Provider page.

  4. Update the Audience URL (SP Entity ID): Enter Audience from the Identity Provider page.

  5. Click Next > Finish.

  6. Assign users and/or groups to the application as required.

    IAM_Okta1.png

  7. Update user attributes and group attributes. For group attribute name enter IdP Group Claim from the Identity Provider page.

    IAM_Okta2.png