Learn how to configure Single Sign-On using SAML protocol in Okta to authenticate users to your Staffbase platform.
In this article, you will learn how to set up
SSO is optional for user management. You can choose an option based on your business requirements. Learn more about other options.
For creating an app integration in Okta, you need to receive the following:
You need to create an App Integration in Okta to set up SSO.
Staffbase recommends creating a dedicated application to maintain users for your Staffbase platform. If you want to configure SCIM for user provisioning, you are able to use a single app integration for both SSO and SCIM for your user management.
The Application username (Name ID) value and the identifier in your Staffbase platform must match for each user using SSO.
If you want to use a different value from the one already in place for your users in your Staffbase platform, you will need to update the user identifiers in your Staffbase platform first. In such a case, ensure that all future user management also includes these new identifiers.
** For Staffbase this is NOT optional. This is where you set the mapping for the profile fields from Okta to Staffbase.
Name: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
Value: user.email
Name: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
Value: user.firstName
Name: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
Value: user.lastName
Provide the following information to Staffbase:
You can copy the Metadata URL in step 8 of the Creating an App Integration section.
After creating the app integration, you can decide on which Okta users need access to the Staffbase platform using SSO.
Staffbase recommends adding a few users initially to test that everything works as expected.
The Assignments tab opens.
After you have provided Staffbase Support with the Metadata URL, you will be informed when SSO was added to your Staffbase instance and is ready for testing.
After testing the SSO authentication works as expected, you can add all users and/or groups in Okta to the app integration.
You have configured and enable SSO for your Staffbase platform.