Skip to main content

Okta — SAML setup with iGrafx Identity

Configure Okta as the SAMLSAML An XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider. Process360 Live supports SAML 2.0 for SSO. identity provider for the iGrafx Identity Solution.

Prerequisites

  • Okta administrator access.
  • Your Tenant ID from the iGrafx Support team (used in the URLs below as YourTenant).

Steps

  1. In Okta as an administrator, select Applications → Applications, then Create App Integration.

  2. Select SAMLSAML An XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider. Process360 Live supports SAML 2.0 for SSO. 2.0 and click Next.

  3. Enter an app name (for example iGrafx), optionally an app image, and click Next.

  4. Configure SAMLSAML An XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider. Process360 Live supports SAML 2.0 for SSO. with these settings (use the URL for your region):

    SettingValue
    Single sign-on URLEMEA/Europe: https://id.igrafxcloud.eu/realms/igrafx/broker/YourTenant-idp-1/endpoint
    Rest of the world / NA: https://id.igrafxcloud.com/realms/igrafx/broker/YourTenant-idp-1/endpoint
    Audience URI (SP Entity ID)EMEA/Europe: https://id.igrafxcloud.eu/realms/igrafx
    Rest of the world / NA: https://id.igrafxcloud.com/realms/igrafx
    Default RelayStateLeave blank
    Name ID formatEmailAddress
    Application usernameEmail

    The Okta single sign-on URL for the EMEA/Europe region. The Okta single sign-on URL for the rest-of-world/NA region.

  5. Set the attribute statements, then click Next:

    Attribute nameName formatValue
    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givennameUnspecifieduser.firstName
    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surnameUnspecifieduser.lastName
  6. Complete the feedback page, click Next, then Finish.

  7. On the application's Assignments tab, click Assign to add the users and groups that should have access to iGrafx.

  8. On the Sign On tab, copy the Metadata URL.

  9. Provide the metadata URL to your iGrafx team at echo.igrafx.com.

  10. The iGrafx team then configures the iGrafx IdentityiGrafx Identity The iGrafx identity and access management service that brokers authentication between customer identity providers and Process360 Live components. Solution and tells you when it's ready to test.