Okta

How to Configure SAML 2.0 for Arxspan


Read this before you enable SAML

These SAML instructions contain Force Authentication configuration steps that are optional. If you are not going to use Force Authentication, skip the steps that are marked as [Optional Force Authentication] and highlighted in blue font.

Contents


Supported Features

The Okta/Arxspan SAML integration currently supports the following features:

For more information on the listed features, visit the Okta Glossary.


Configuration Steps

  1. Contact the Arxspan Support team (support@arxspan.com) and request that they enable SAML 2.0 for your account.

  2. Save, then attach the following Metadata file to your request:

    Sign into the Okta Admin dashboard to generate this value.

  3. The Arxspan Support team will process your request and will provide you with your Company Name value. After receiving a confirmation email, you can start assigning people to the application.

  4. [Optional Force Authentication]: In Okta select the Sign On tab for the Arxspan SAML app, then click Edit:

    • Uncheck Disable Force Authentication.

    • Click Save:

    arxspan_new1..png

  5. Done!

Notes

The following SAML attributes are supported:


SP-initiated SSO

  1. Go to https://eln.arxspan.com/saml/okta.

  2. Click Sign In:

    arxspan_new2.png


Simulating an IDP-initiated Flow

  1. Since the application only supports an SP-initiated flow, you can simulate an IdP-initiated flow with the Bookmark sign-on method. In Okta add another Arxspan app and follow the steps below:

    • SIGN ON METHODS: Select Bookmark-only.
    • Company Name: Enter the Company Name value provided to you by Arxspan in step 3.
    • Click Done:

    arxspan_new3.png

  2. Now you can hide the original app on the end user dashboard. Go to the General tab in Okta and check Do not display application icon to users:

    arxspan_new4.png