---
title: "Configuring SAML 2.0 Application for OKTA"
canonical: "https://docs.infoblox.com/space/BloxOneCloud/35366534/Configuring%20SAML%202.0%20Application%20for%20OKTA"
format: markdown
---
<span style="color: #000000">Before you configure the SAML federation, ensure that you have already completed the following:</span>

- [*<span style="color: #000000">Selected a domain and a protocol</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35398160)
- [*<span style="color: #000000">Generated the audience keys</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35367311)

<span style="color: #000000">To create a SAML application on your OKTA 3rd party IdP instance, complete the following:</span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ Ensure that you have access to an OKTA account for configuring SSO federation.

1. <span style="color: #000000">Log in to the OKTA instance for your 3rd party IdP and click the </span>**<span style="color: #000000">admin</span>**<span style="color: #000000"> button on the top right to get to the administration menu.</span>
  1. <span style="color: #000000">If there is a </span>**<span style="color: #000000">Developer Console</span>**<span style="color: #000000"> drop-down on the top left, click it and choose </span>**<span style="color: #000000">Classic UI</span>**<span style="color: #000000">.</span>
2. <span style="color: #000000">On the </span>*<span style="color: #000000">General Settings </span>*<span style="color: #000000">page, add the SAML application, as follows:</span>
  1. <span style="color: #000000">Select the </span>**<span style="color: #000000">Application</span>**<span style="color: #000000"> menu -> </span>**<span style="color: #000000">Applications.</span>**
  2. <span style="color: #000000">Click </span>**<span style="color: #000000">Create App Integration</span>**<span style="color: #000000">.</span>
  3. <span style="color: #000000">In the </span>*<span style="color: #000000">Create a New Application Integration</span>*<span style="color: #000000"> dialog box, enter the following, and then click </span>**<span style="color: #000000">Next</span>**<span style="color: #000000">:</span>
    - <span style="color: #000000">Choose </span>**<span style="color: #000000">SAML 2.0</span>**<span style="color: #000000">.</span>
3. <span style="color: #000000">On the </span>*<span style="color: #000000">General Settings</span>*<span style="color: #000000"> page, add your </span>**<span style="color: #000000">SAML Application Name</span>**<span style="color: #000000"> (i.e. Infoblox) and click </span>**<span style="color: #000000">Next</span>**<span style="color: #000000">.</span>
4. <span style="color: #000000">On the</span>*<span style="color: #000000"> SAML application</span>*<span style="color: #000000"> page, add the </span>**<span style="color: #000000">HUB ACS URL</span>**<span style="color: #000000"> and </span>**<span style="color: #000000">Audience URI</span>**<span style="color: #000000"> (values copied when you generate the </span>[*<span style="color: #000000">Audience Keys</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35367311)<span style="color: #000000">) to the </span>**<span style="color: #000000">Single Sign on URL</span>**<span style="color: #000000"> and </span>**<span style="color: #000000">Audience URI (SP Entity ID)</span>**<span style="color: #000000"> fields in your SAML application respectively.</span>
5. <span style="color: #000000">Select the </span>**<span style="color: #000000">Use this for Recipient URL and Destination URL</span>**<span style="color: #000000"> check box under the </span>**<span style="color: #000000">Single Sign on URL</span>**<span style="color: #000000"> section.</span>
6. <span style="color: #000000">Complete the following:</span>
  - **<span style="color: #000000">Name ID format</span>**<span style="color: #000000">: Choose </span>**<span style="color: #000000">Email Address</span>**<span style="color: #000000"> from the drop-down menu.</span>
  - **<span style="color: #000000">Application username</span>**<span style="color: #000000">: Choose </span>**<span style="color: #000000">Email</span>**<span style="color: #000000"> from the drop-down menu.</span>  
<span style="color: #000000">The subjectNameID in the SAML assertion must be the user’s email address, and the email address must have a domain name that matches the domain for which the federation is being configured</span>**<span style="color: #000000">.</span>**
7. <span style="color: #000000">Scroll to the bottom of the page and complete the following in the </span>**<span style="color: #000000">GROUP ATTRIBUTE STATEMENTS (OPTIONAL)</span>**<span style="color: #000000"> section to add a group attribute:</span>
  - **<span style="color: #000000">Name</span>**<span style="color: #000000">: Enter </span>**<span style="color: #000000">groups</span>**<span style="color: #000000"> in the field. Do not include quotes or other characters.</span>
  - **<span style="color: #000000">Name format (optional)</span>**<span style="color: #000000">: Leave this as </span>**<span style="color: #000000">Unspecified</span>**<span style="color: #000000">.</span>
  - **<span style="color: #000000">Filter</span>**<span style="color: #000000">: Choose </span>**<span style="color: #000000">Matches regex</span>**<span style="color: #000000"> from the drop-down list and enter </span>**<span style="color: #000000">.*</span>**
8. <span style="color: #000000">Click </span>**<span style="color: #000000">Next</span>**<span style="color: #000000">.</span>
9. <span style="color: #000000">On the </span>*<span style="color: #000000">Edit SAML Integration</span>*<span style="color: #000000"> page, complete the </span>**<span style="color: #000000">Help Okta Support understand how you configured this application</span>**<span style="color: #000000"> section, as follows: </span>
  - **<span style="color: #000000">Are you a customer or partner?</span>**<span style="color: #000000">: Select </span>**<span style="color: #000000">I'm an Okta customer adding an internal app</span>**<span style="color: #000000">.</span>
  - **<span style="color: #000000">App type</span>**<span style="color: #000000">: Select the </span>**<span style="color: #000000">This is an internal app we have created</span>**<span style="color: #000000"> check box.</span>
10. <span style="color: #000000">Click </span>**<span style="color: #000000">Finish</span>**<span style="color: #000000"> to save your SAML configuration. After you finish the SAML configuration, click </span>**<span style="color: #000000">View Setup Instructions</span>**<span style="color: #000000"> to complete the setup.</span>
11. <span style="color: #000000">After you click </span>**<span style="color: #000000">View Setup Instructions</span>**<span style="color: #000000">, from the new browser tab, ensure that you copy the required values for adding your Identity Provider in the SSO portal’s </span>**<span style="color: #000000">Configure SAML</span>**<span style="color: #000000"> section. You can copy these to a notepad application or one at a time while in the SSO portal itself, based on your preference. For ease of use, copy the values from the </span>*<span style="color: #000000">View Setup Instructions</span>*<span style="color: #000000"> page, so you can enter them in the SSO Portal’s</span>**<span style="color: #000000"> Configure SAML</span>**<span style="color: #000000"> section, in the following order:</span>
  - <span style="color: #000000">Identity Provider Single Sign-On URL</span>
  - <span style="color: #000000">Identity Provider Issuer</span>
  - <span style="color: #000000">X.509 Certificate key (minimum digital signature of SHA-256 is required)</span>
    <span style="color: #000000">You must enter the information in this order when configuring SAML in the SSO Portal.</span>
    <span style="color: #000000">The following is an example of the information for </span>**<span style="color: #000000">View Setup Instructions</span>**<span style="color: #000000">:</span>  
  
> Macro (inline-media-image)
12. <span style="color: #000000">Once the SAML application configuration is complete, check the following to verify the admin and test users are assigned to the SAML application in your IdP OKTA portal:</span>
  1. <span style="color: #000000">Click </span>**<span style="color: #000000">Directory</span>**<span style="color: #000000"> -> </span>**<span style="color: #000000">People</span>**<span style="color: #000000">.</span>
  2. <span style="color: #000000">Select the desired user and click </span>**<span style="color: #000000">Assign Application</span>**<span style="color: #000000">.</span>
  3. <span style="color: #000000">Select </span>**<span style="color: #000000">Applications</span>**<span style="color: #000000"> and add the SAML application.</span>  
<span style="color: #000000">Ensure that all desired users in the domain are assigned to the SAML application. Neglecting to do this will result in authentication failures for all unassigned users.</span>
  4. <span style="color: #000000">Click </span>**<span style="color: #000000">Directory</span>**<span style="color: #000000"> -> </span>**<span style="color: #000000">Groups</span>**
  5. <span style="color: #000000">Select the link for the desired group name</span>
  6. <span style="color: #000000">Select </span>**<span style="color: #000000">Manage People</span>**<span style="color: #000000">, then select the desired user and select the + button next to their name in the UI (this will add them to the group).</span>
  7. <span style="color: #000000">Select </span>**<span style="color: #000000">Manage Apps</span>**<span style="color: #000000">. In the popup dialog box, select </span>**<span style="color: #000000">Assign</span>**<span style="color: #000000"> for the SAML application, and then click </span>**<span style="color: #000000">Save</span>**<span style="color: #000000">.</span>
  8. <span style="color: #000000">Once the desired users are added to the desired group, click </span>**<span style="color: #000000">Save</span>**<span style="color: #000000">. Repeat as necessary for desired groups & users.</span>  
<span style="color: #000000">At this point, desired users and groups have been assigned to the Infoblox SAML application and you are now free to leave your OKTA instance and complete IdP configuration inside the SSO portal. The following steps describe how to configure a SAML application in the SSO Portal.</span>
13. <span style="color: #000000">In the Infoblox SSO Portal, go to </span>**<span style="color: #000000">Authentication</span>**<span style="color: #000000"> -></span>**<span style="color: #000000"> </span>****<span style="color: #000000">3rd Party IdP</span>**<span style="color: #000000">, and then click </span>**<span style="color: #000000">Configure SAML</span>**<span style="color: #000000">.</span>
14. <span style="color: #000000">Enter the following values that you copied from the SAML configuration:</span>
  1. **<span style="color: #000000">IDP Single Sign-On URL</span>**<span style="color: #000000">:  Identity Provider Single Sign-On URL.</span>
  2. **<span style="color: #000000">IDP Issuer URI</span>**<span style="color: #000000">: Identity Provider Issuer.</span>
  3. **<span style="color: #000000">Signature Certificate</span>**<span style="color: #000000">: X.509 Certificate key without BEGIN CERTIFICATE and END CERTIFICATE lines. The SSO Portal supports Base64 certificates with the following file extensions: </span>*<span style="color: #000000">.crt</span>*<span style="color: #000000">, </span>*<span style="color: #000000">.pem</span>*<span style="color: #000000">, and </span>*<span style="color: #000000">.ca-bundle</span>*<span style="color: #000000">. M</span><span style="color: #000000">inimum digital signature of SHA-256 is required.</span>  
  
> Macro (inline-media-image)
    <span style="color: #000000">If you receive an error message about the certificate, go to the beginning of the last line of the certificate and hit backspace to remove extra spaces in the previous line. You might need to repeat the same process for any lines that might include extra spaces.</span>
15. <span style="color: #000000">Click </span>**<span style="color: #000000">Save & Close</span>**<span style="color: #000000">.</span>
16. <span style="color: #000000">After you have configured the SAML application, you can complete the following configuration:</span>
  1. [<span style="color: #000000">*Mapping User Groups*</span>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35463665)
  2. [<span style="color: #000000">*Testing 3rd Party IdP Authentication*</span>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35367251)
  3. [<span style="color: #000000">*Activating 3rd Party IdP Authentication*</span>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35463635)
  <span style="color: #000000">You can also perform the following after you set up 3rd party IdP authentication:</span>
  - [<span style="color: #000000">*Deactivating 3rd Party IdP Authentication*</span>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35464005)
  - [<span style="color: #000000">*Resetting 3rd Party IdP*</span>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35367439)
  - [<span style="color: #000000">*Adding a Chiclet for IdP-initiated SSO (OKTA)*</span>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35431099)