Views:

Prerequisites

Before you begin configuring Okta, make sure that:

  • You have a valid subscription with Okta that handles the sign-in process and eventually provides the authentication credentials to the Cloud App Security management console.
  • You are logged on to the management console as a Cloud App Security global administrator. For details, see Administrator and Role.

Setting up SSO using Okta

  1. Log in to your Okta organization as a user with administrative privileges.
  2. Click Admin in the upper-right.

    Admin

    Click the image to enlarge.

  3. Navigate to Applications > Applications, then click Create App Integration.

    Create App Integration

    Click the image to enlarge.

  4. Select SAML 2.0 as the Sign in method, and then click Next.

    Sign in Method

    Click the image to enlarge.

  5. On the General Settings screen, enter "Cloud App Security" in the App name field, and click Next.

    App Name

    Click the image to enlarge.

  6. On the Configure SAML screen, specify the following:
    1. Type the Cloud App Security logon URL in Single sign on URL based on your serving site.
      For example, if the URL of your Cloud App Security management console in the address bar is "https://admin.tmcas.trendmicro.com" after logon, type https://admin.tmcas.trendmicro.com/ssoLogin in Single sign on URL.
    2. Select Use this for Recipient URL and Destination URL.
    3. Specify the Audience URI in Audience URI (SP Entity ID), which is the Cloud App Security logon URL of your serving site.
      For example, if the URL of your Cloud App Security management console in the address bar is "https://admin.tmcas.trendmicro.com" after logon, the Audience URI is https://admin.tmcas.trendmicro.com.
    4. Select EmailAddress in Name ID format.
    5. Select Okta username in Application username.
    6. Click Next.

    SAML Integration

    Click the image to enlarge.

  7. On the Feedback screen, click I'm an Okta customer adding an internal app. Select This is an internal app that we have created, and then click Finish.

    SAML Integration

    Click the image to enlarge.

  8. Click the View Setup Instructions button.

    View Setup Instructions

    Click the image to enlarge.

  9. Record the URL in Identity Provider Single Sign-On URL and the certificate content in X.509 Certificate.

    SAML Certificate

    Click the image to enlarge.

  10. Assign the application to people.
     
    Make sure to add these users as Administrators in the Cloud App Security management console.
     
    1. Select Directory > People.

      People

      Click the image to enlarge.

    2. Click the user that you want to assign the application to, and then click Assign Applications.

      Assign App

      Click the image to enlarge.

    3. Locate the Cloud App Security you added, and click Assign.

      Assign App

      Click the image to enlarge.

    4. Verify the user name and click Save and Go Back.

      Save and Go Back

      Click the image to enlarge.

    5. Confirm that the application is assigned to this user.

      Confirm App Assignment

      Click the image to enlarge.

    6. Repeat the above steps to assign the application to more users as necessary.