Configure SAML SSO

⭐ Configure SAML SSO (with Salesforce Example)


1. What Is SAML?

SAML (Security Assertion Markup Language) is an authentication protocol that:

  • Uses encrypted XML assertions

  • Provides federated Single Sign-On (SSO) between:

    • An Identity Provider (IdP) → Okta

    • A Service Provider (SP) → the application (e.g., Salesforce)

SAML defines:

  • How the authentication request is made

  • How the response (assertion) is passed back

  • How trust is established between IdP and SP


2. How Does SAML Work?

SAML relies on a SAML assertion = an XML document that contains:

  • User identity information

  • Authentication details

  • Optional authorization data

Basic flow:

  1. User tries to access an app.

  2. Okta (IdP) authenticates the user.

  3. Okta generates a SAML assertion.

  4. Okta returns the assertion to the browser.

  5. The browser posts the assertion to the app’s Assertion Consumer Service (ACS) URL (the app’s SAML login URL).

  6. The app validates the assertion and signs the user in.


3. SAML Flows: IdP-Initiated vs SP-Initiated

A. IdP-Initiated Flow

  1. User signs in to Okta first.

  2. Okta authenticates the user and loads their End-User Dashboard.

  3. User clicks on the app (e.g., Salesforce) tile in the dashboard.

  4. Okta creates a SAML assertion and sends it to the app’s ACS URL.

  5. User is signed into the app without re-entering credentials.


B. SP-Initiated Flow

  1. User goes directly to the application (e.g., Salesforce URL).

  2. App redirects the user to Okta for authentication (SAML request).

  3. Okta authenticates the user.

  4. Okta generates a SAML assertion and sends it back to the app (via browser + ACS URL).

  5. App validates assertion and signs in the user.

Some apps support both flows; others may support only one.


4. Key SAML Concepts

  • IdP (Identity Provider):
    Authenticates the user and issues SAML assertions → in this case, Okta.

  • SP (Service Provider):
    The application that consumes the SAML assertion (e.g., Salesforce).

  • ACS URL (Assertion Consumer Service URL):
    The app’s SAML endpoint where the browser posts the SAML assertion.

  • Metadata & Certificate:

    • Metadata contains URLs, entity IDs, and certificates.

    • The SAML signing certificate from Okta lets the app verify the assertion’s signature.


5. Integrating a SAML App Using the Okta Integration Network (OIN)

When integrating a SAML app (like Salesforce) from the OIN, you must:

  1. Establish trust between Okta and the app:

    • Exchange metadata

    • Provide the app with Okta’s SAML certificate

  2. Set the ACS URL (Login URL):

    • Tell Okta where to send the SAML assertion.


6. Example: Configure SAML SSO for Salesforce (IdP-Initiated)

✅ Step 1 – Add the App Integration

  • In the OIN (Browse App Catalog), find Salesforce.

  • Confirm it supports SAML SSO.

  • Click Add Integration.


✅ Step 2 – Configure General Settings

  • In General Settings, set:

    • Application label (name)

    • Instance type

    • Custom domain (if used)

  • Click Next.


✅ Step 3 – Set Sign-On Method to SAML

  • Go to Sign-On Options.

  • Choose SAML 2.0 as the sign-on method.

  • Click Done.


✅ Step 4 – Download IdP Metadata from Okta

  • On the Sign On tab of the app in Okta:

    • Scroll to SAML Signing Certificates.

    • For the active certificate, click Actions → View IdP metadata.

  • In the metadata tab, right-click → Save as → save as metadata.xml.


✅ Step 5 – Create SAML Connection in Salesforce

  • In Salesforce Setup:

    • Go to Single Sign-On Settings.

    • Enable SAML.

    • Click New from Metadata File.

    • Upload the metadata.xml file downloaded from Okta.

    • Click Create.

    • Optionally rename Name and API Name, then Save.


✅ Step 6 – Set the ACS URL (Login URL)

  • In Salesforce SAML connection:

    • Copy the Login URL from the Endpoints section.

  • In Okta:

    • Go to the app’s Sign On tab.

    • Edit Sign-On settings.

    • In Advanced Sign-on Settings, paste that Login URL into the Login URL field.

    • Save.

This step ensures that Okta knows exactly where to send the SAML assertion.


✅ Step 7 – Set Credentials for the App

  • In Okta, Sign On tab → edit sign-on settings.

  • In Credentials Details, set:

    • The username format that matches how Salesforce expects usernames (e.g., email address, Salesforce username).

  • Save.


✅ Step 8 – Assign the App to Users

  • Assign the app to:

    • Individual users, and/or

    • Groups

  • Users will now see the Salesforce tile on their Okta dashboard.


7. Enable SP-Initiated Flow in Salesforce

To support SP-initiated SSO:

  • In Salesforce Setup:

    • Go to Company Settings → My Domain.

    • Edit Authentication Configuration.

    • Enable the Okta SAML connection.

This allows users to go to Salesforce directly and be redirected to Okta for SSO.


8. Key Takeaways (Exam-Ready)

  • SAML uses XML-based assertions for federated SSO between Okta (IdP) and apps (SPs).

  • Two main flows:

    • IdP-initiated: Start at Okta, then go to app.

    • SP-initiated: Start at app, then go to Okta.

  • Core tasks to integrate a SAML app:

    • Establish trust (metadata + certificate)

    • Configure ACS URL / Login URL

    • Configure sign-on method = SAML 2.0

    • Map usernames/attributes correctly

    • Assign the app to users/groups

  • OIN simplifies SAML integration by providing prebuilt templates.