Okta

How to Configure SAML 2.0 for Drift


Read this before you enable SAML

Enabling SAML will affect all users who use this application, which means that users will not be able to sign-in through their regular log-in page. They will only be able to access the app through the Okta service.

Backup URL

Drift does not provide backup log-in URL where users can sign-in using their normal username and password. You can call your account owner to turn off SAML, if necessary.

Contents


Supported Features

The Okta/Drift SAML integration currently supports the following features:

For more information on the listed features, visit the Okta Glossary.


Configuration Steps

  1. Login to your Drift account as an administrator.

  2. Navigate to Settings > App Settings > Authentication and select Configure SAML Authentication. Then follow the steps below:

    • Identity Provider Entity ID: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.

    • SAML 2.0 HTTPS Redirect Endpoint: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.

    • Identity Provider Public Key: Save the following certificate as okta.pem, then upload it to Drift.

      Sign into the Okta Admin Dashboard to generate this variable.
    • Require signed assertions in SAML response: Enable this option.

    • SAML Request Signing: Keep this option disabled.

    drift1.png

  3. Still in Drift, go to Domains and add your domain:

    drift2.png

  4. In Okta, select the Sign On tab for the Drift SAML app, then click Edit.

    • Default Relay State: Enter https://app.drift.com.

    • Click Save:

    drift_newa.png

  5. Done!


Notes

The following SAML attributes are supported:


SP-initiated SSO

  1. Go to https://start.drift.com/ URL.

  2. Enter your email, then click Next:

  3. drift3.png