Create a new application in Okta

To authenticate with Okta, you need to create an internal application in Okta and configure SAML.

How to

  1. In Okta, navigate to the Applications tab and click Applications.
  2. Click Add application > Create new app.
  3. In the dialog, select SAML 2.0 as the sign on method.
  4. Click Create.
  5. In the General Settings, enter an application name and add an optional logo.
  6. In the App visibility section, make sure the options are deselected so the application is visible to end users within their Okta portals.
  7. Click Next.
  8. On the SAML Settings page, enter this URL into the Single sign on URL and Audience URI fields: https://<hostname>/saml/sp/response.
    where <hostname> is that hostname that you plan to use for the identity provider in ETP. This hostname is used for the URL of the login portal.
  9. In the Name ID format menu, select EmailAddress.
  10. Click Show Advanced Settings. Apply these settings:
    1. In the Response menu, select Signed.
    2. In the Assertion Signature menu, make sure Signed is selected.
    3. In the Assertion Encryption menu, select Signed.
    4. In the Authentication context class menu, select PasswordProtectedTransport.
  11. Do not enter settings into the ATTRIBUTE STATEMENTS (OPTIONAL) area.
  12. In the GROUP ATTRIBUTE STATEMENTS (OPTIONAL) area, enter this information:
    1. In the Group Name field, enter Group.
    2. Do not specify a group filter. Leave the filter field blank.
  13. Click Next.
  14. Confirm that the app you’re creating is internal.
  15. Click Finish. After the Okta application is created, click the Identity Provider metadata link to download the metadata.xml file.

Next steps

  1. Assign imported users or groups to the application your created:
    1. In the Assignment tab of the application you added, click Assign.
    2. Select Assign to People or Assign to Groups.
    3. Enter the people or groups that you want to authenticate with the Okta IdP.
    4. Click Assign.
    5. Verify the attributes, and click Save and Go Back.
    6. Click Done.
  2. Add Okta as an identity provider