Last updated

Create SAML application with Okta

This guide outlines the steps to create and configure a SAML application in Okta, including setup, user assignments, and metadata submission.


Step 1: Create SAML application

  1. Log in to your Okta Application Dashboard and click Applications in the sidebar.

okta

  1. Click Create App Integration.

okta

  1. Click Create New App and choose SAML 2.0 as the Sign-in method. Then, click Next.

okta

  1. Enter the name of your application, then click Next.

okta

  1. Copy and paste the values into the relevant fields in the SAML Settings section.

okta

okta

Step 2: Fill attribute statements (optional)

  1. Go Attribute Statements (optional) configuration in SAML Settings, fill in the following Attribute Statements and click Next:

okta

okta

  1. To complete the app creation process, proceed to the next page and skip or fill out the survey. Click on Finish.

okta

Step 3: Assign users

Define which groups should be allowed to log in via SAML SSO in Okta using the app you've created.

  1. Switch to the Assignments tab, click Assign, and choose Assign to Groups.

okta

  1. Locate the specific group(s) you wish to assign to the app and click Assign next to each of them. Once finished, click Done.

okta

Step 4: Submit metadata

To complete the implementation of SAML SSO, you need to provide the application with your identity provider's metadata.

Automatic configuration

  1. Click on the Sign On tab of the SAML app you just created.
  2. Copy the Metadata URL and paste it below.

okta

okta

Manual configuration

  1. Click on the Sign On tab of the SAML app you just created.
  2. Click on View SAML setup instructions.
  3. Copy the value of the Identity Provider Single Sign-On URL and X.509 Certificate fields, and then paste them into the appropriate fields in the form below.

okta

okta

Step 5: Proceed with domain claiming and role assignment

  1. Click on Proceed with domain claiming and role assignment to confirm the completion the configuration of the IDP form.
  2. Follow the instructions in the Self-service SAML configuration guide to complete this step and manage authorization.