-
Log into your Okta console.
-
Navigate to Applications in the main top navigation.
-
On the left of the page, select Add Application.
-
On the left of the page, select Create New App.
-
The settings should be as follows:
-
Platform: Web
-
Sign on method: SAML 2.0
-
Click Create.
Note
This screen can look slightly different depending on your Okta account.
-
-
Under General Settings
-
App name: Expel Workbench.
-
Click Next.
-
-
You are now on the Configure SAML step in Okta. You need to copy information from Expel Workbench to complete the integration. Open a new tab or window and log into Expel Workbench (https://workbench.expel.io)
-
Navigate to Settings > My Organizations and select the organization. Then select the Integrations tab and click the Configure SSO link under Single Sign-on.
-
Next, copy and paste the following from Expel Workbench, into Okta:
-
ACS URL or Single Sign-on URL → Single sign on URL
-
Audience URI or Audience → Audience URI (SP Entity ID)
-
Leave Yes, allow users to log in locally OR via SSO selected for local logins. This selection makes initial SSO setup easier. You can change this later.
-
-
In Okta under (A) SAML Settings, Attribute Statements (Optional):
-
Type the word email under Name, and select user.email from the Value list.
Tip
These are case sensitive.
-
Click Next.
-
-
For the Okta feedback form, select I’m an Okta customer adding an internal app and fill in the following optional information as you see fit. Or This is an internal app that we have created. Then click Finish.
-
In Okta, under Sign On, Settings, click View Setup Instructions.
-
In Expel Workbench, click Next 2 times, until you see Step 3 of 3.
-
Copy and paste the following from Okta into Expel Workbench.
-
Identity Provider Single-Sign-On URL → Single Sign-On URL or SAML 2.0 Endpoint
-
Identity Provider Issuer → Issuer or Issuer ID
-
X.509 Certificate → Certificate
-
-
Click Save in Expel Workbench.
Note
Before signing in with SSO, make sure that:
-
In Okta, the Workbench application is assigned to all intended users.
-
The user email addresses you have in Okta match the email configured for the user in Workbench. The emails are case sensitive.
-
New members of your organization that need access to Workbench have user accounts created in Workbench and have the Workbench application assigned to them in your Identity Provider.
-
After you're finished testing and setting up, in Expel Workbench, you can disable local logins by selecting Edit from the list on the right, and selecting No, users can ONLY log in via SSO. Then click Next > Next > Save to save.
Comments
0 comments
Please sign in to leave a comment.