- Log in to your OKTA account.
-
Navigate to Applications > Applications > Add Application.
-
Click Create New App.
The Create a New Application Integration window appears.
- Select the following options for the corresponding fields:
- Platform: Web
- Sign on method: SAML 2.0
- Click Create.
- Select the following options for the corresponding fields:
-
In the App name field, enter any name. For this example, we used DDI test. Click Next.
- On your DDI console, go to Administration > Integrated Products/Services > SAML Authentication > Service Provider and copy the Entity ID and Single Sign On URL.
-
Go back to your Okta account. In the Create SAML Integration window, enter the following information:
- Single sign on URL: enter Single sign on URL from step 5
- Audience URI (SP Entity ID): enter Entity ID from from step 5
- Name ID format: select EmailAddress
- In the Group Attribute Statements window, enter the following:
- Name: DDI_GROUP
- Filter: Matches regex, ^(.*)*$
Click Next to complete the creation.
-
Navigate to Application > Your Application > Assignments.
-
To create a group, click Assign > Assign to Groups.
For this example, Everyone is selected. Click Assign then click Done.
- Check the People tab and it will automatically add your account.
- Navigate to Application > Your Application > Sign On tab.
- Click the Identity Provider metadata link to download. Save the xml file.
-
Navigate to DDI > Administration > Integrated Products/Services > SAML Authentication > Identity provider then click Add.
The Add Identity Provider window appears.
-
Enter the Service Name and click Select to upload the Okta Identity Provider metadata. Click Save.
-
Navigate to Administration > Accounts > SAML tab, then click Add.
Claim Value should be the exact word you use as group name on your OKTA (refer to step 9). -
Test your OKTA login, the application that you created should appear right after you log in to your OKTA account.
-
After clicking the application, it should redirect you to your DDI console without issuing any username or password. Verify that you are using your Okta account on the DDI console.
