Configure SAML SSO
⭐ Configure SAML SSO (with Salesforce Example)
1. What Is SAML?
SAML (Security Assertion Markup Language) is an authentication protocol that:
Uses encrypted XML assertions
Provides federated Single Sign-On (SSO) between:
An Identity Provider (IdP) → Okta
A Service Provider (SP) → the application (e.g., Salesforce)
SAML defines:
How the authentication request is made
How the response (assertion) is passed back
How trust is established between IdP and SP
2. How Does SAML Work?
SAML relies on a SAML assertion = an XML document that contains:
User identity information
Authentication details
Optional authorization data
Basic flow:
User tries to access an app.
Okta (IdP) authenticates the user.
Okta generates a SAML assertion.
Okta returns the assertion to the browser.
The browser posts the assertion to the app’s Assertion Consumer Service (ACS) URL (the app’s SAML login URL).
The app validates the assertion and signs the user in.
3. SAML Flows: IdP-Initiated vs SP-Initiated
A. IdP-Initiated Flow
User signs in to Okta first.
Okta authenticates the user and loads their End-User Dashboard.
User clicks on the app (e.g., Salesforce) tile in the dashboard.
Okta creates a SAML assertion and sends it to the app’s ACS URL.
User is signed into the app without re-entering credentials.
B. SP-Initiated Flow
User goes directly to the application (e.g., Salesforce URL).
App redirects the user to Okta for authentication (SAML request).
Okta authenticates the user.
Okta generates a SAML assertion and sends it back to the app (via browser + ACS URL).
App validates assertion and signs in the user.
Some apps support both flows; others may support only one.
4. Key SAML Concepts
IdP (Identity Provider):
Authenticates the user and issues SAML assertions → in this case, Okta.SP (Service Provider):
The application that consumes the SAML assertion (e.g., Salesforce).ACS URL (Assertion Consumer Service URL):
The app’s SAML endpoint where the browser posts the SAML assertion.Metadata & Certificate:
Metadata contains URLs, entity IDs, and certificates.
The SAML signing certificate from Okta lets the app verify the assertion’s signature.
5. Integrating a SAML App Using the Okta Integration Network (OIN)
When integrating a SAML app (like Salesforce) from the OIN, you must:
Establish trust between Okta and the app:
Exchange metadata
Provide the app with Okta’s SAML certificate
Set the ACS URL (Login URL):
Tell Okta where to send the SAML assertion.
6. Example: Configure SAML SSO for Salesforce (IdP-Initiated)
✅ Step 1 – Add the App Integration
In the OIN (Browse App Catalog), find Salesforce.
Confirm it supports SAML SSO.
Click Add Integration.
✅ Step 2 – Configure General Settings
In General Settings, set:
Application label (name)
Instance type
Custom domain (if used)
Click Next.
✅ Step 3 – Set Sign-On Method to SAML
Go to Sign-On Options.
Choose SAML 2.0 as the sign-on method.
Click Done.
✅ Step 4 – Download IdP Metadata from Okta
On the Sign On tab of the app in Okta:
Scroll to SAML Signing Certificates.
For the active certificate, click Actions → View IdP metadata.
In the metadata tab, right-click → Save as → save as
metadata.xml.
✅ Step 5 – Create SAML Connection in Salesforce
In Salesforce Setup:
Go to Single Sign-On Settings.
Enable SAML.
Click New from Metadata File.
Upload the
metadata.xmlfile downloaded from Okta.Click Create.
Optionally rename Name and API Name, then Save.
✅ Step 6 – Set the ACS URL (Login URL)
In Salesforce SAML connection:
Copy the Login URL from the Endpoints section.
In Okta:
Go to the app’s Sign On tab.
Edit Sign-On settings.
In Advanced Sign-on Settings, paste that Login URL into the Login URL field.
Save.
This step ensures that Okta knows exactly where to send the SAML assertion.
✅ Step 7 – Set Credentials for the App
In Okta, Sign On tab → edit sign-on settings.
In Credentials Details, set:
The username format that matches how Salesforce expects usernames (e.g., email address, Salesforce username).
Save.
✅ Step 8 – Assign the App to Users
Assign the app to:
Individual users, and/or
Groups
Users will now see the Salesforce tile on their Okta dashboard.
7. Enable SP-Initiated Flow in Salesforce
To support SP-initiated SSO:
In Salesforce Setup:
Go to Company Settings → My Domain.
Edit Authentication Configuration.
Enable the Okta SAML connection.
This allows users to go to Salesforce directly and be redirected to Okta for SSO.
8. Key Takeaways (Exam-Ready)
SAML uses XML-based assertions for federated SSO between Okta (IdP) and apps (SPs).
Two main flows:
IdP-initiated: Start at Okta, then go to app.
SP-initiated: Start at app, then go to Okta.
Core tasks to integrate a SAML app:
Establish trust (metadata + certificate)
Configure ACS URL / Login URL
Configure sign-on method = SAML 2.0
Map usernames/attributes correctly
Assign the app to users/groups
OIN simplifies SAML integration by providing prebuilt templates.