Okta IdP SAML SSO setup process
Prerequisite
- Admin access to your Okta Identity Provider Environment
Create a MindTouch SAML Application in Okta
CXone Expert has a partnered application in Okta named MindTouch SAML. Your first step will be to create this application in Okta.
- In the Okta Admin console, go to Applications > Browse App Catalog.
- Search for MindTouch SAML and click Add.
- Enter CXone Expert as the Additional label for the application.
- Click Done.
Collect the Application's metadata
Once you create the application, collect the appropriate metadata and share it with the CXone Expert technical resource.
- In your created CXone Expert application, navigate to the Sign On tab.
- On the right side, scroll down and click on View SAML setup instructions.
- Under Configuration Steps, go to Step 2.
- Copy the Entity ID, Single sign-on service, and Public x.509 certificate.
- Send those pieces of information to the CXone Expert technical resource.
Upload metadata to the Okta application
After sending the metadata to the CXone Expert technical resource, they will provide you with a metadata link. You will download the metadata file using that link and input the necessary information into the Okta Application.
- Use the metadata download link provided by the CXone Expert technical resource to download the metadata file to your machine.
- In the Okta application, go to the Sign On tab.
- Click Edit at the top.
- Scroll down to Advanced Sign-on Settings.
- Fill out the ACS URL and Audience Restriction (SP Entity ID) using the metadata file.
- Open the View SAML setup instructions link for more detailed instructions.
- Click Save.
Assign Users / Groups to the Okta Application
To test the connection, assign Users to the application. You can add individual Users for testing purposes, or if you already know which groups you wish to assign to the CXone Expert Application, you can assign those too.
Please follow Okta's documentation on assigning users or groups for further instruction.
Test the connection
Once you have assigned users to the application in Okta, test logging in either through an IdP-initiated login or an SP-initiated login by going directly to the CXone Expert Site. Report any issues to the CXone Expert technical resource.