How to Configure SAML 2.0 for Offishall

<aside> šŸšØ This setup might fail without parameter values that are customized for your organization. Please use the Okta Administrator Dashboard to add an application and view the values that are specific for your organization.

</aside>

<aside> āš ļø Read this before you enable SAML Enabling SAML will affect all users who use this application, which means that users will not be able to sign-in through their regular log-in page. They will only be able to access the app through the Okta service.

Backup URL Offishall does not provide backup log-in URL where users can sign-in using their normal username and password. You can email Offishall support ([email protected]) to turn off SAML, if necessary.

</aside>

Supported Features

The Okta/Offishall SAML integration currently supports only Service Provider-initiated Single Sign-On (SP-initiated SSO).

For more information, visit theĀ Okta Glossary.

Configuration Steps

  1. Login to your Offishall account as an administrator. Click on Admin then select users

    Untitled-3.png

    Select Okta

    Untitled-4.png

Untitled-5.png

  1. Make sure provisioning is enabled:

Untitled

  1. Choose a custom domain to point your users to for signin-in to offishall (ex: [your-offishall-subdomain].offishall.io), then click Save:

Untitled

  1. Scroll to the Single Sign-onĀ SAML section, then enter the following (see screen shot at end of step for reference):

    Untitled

  2. Done!


<aside> šŸ’” Make sure that you entered the correct value in theĀ SubdomainĀ field under theĀ GeneralĀ tab in Okta. Using the wrong value will prevent you from authenticating via SAML to Offishall

</aside>

SP-initiated SSO

  1. Go toĀ https://[your-offishall-subdomain].offishall.com/signin.
  2. ClickĀ Sign in