Read this before you enable SAML
Enabling SAML will affect all users who use this application, which means that users will not be able to sign-in through their regular log-in page. They will only be able to access the app through the Okta service.
Backup URL
EmployeeReferrals.com does not provide backup log-in URL where users can sign-in using their normal username and password. You can contact EmployeeReferrals.com support to turn off SAML, if necessary.
The Okta/EmployeeReferrals.com SAML integration currently supports the following features:
Log into EmployeeReferrals.com as an administrator.
Switch to the Admin View mode:
Navigate to Settings > Single Sign-On and enter the following information (see screenshot at end of step for reference):
SAML Metadata URL: Copy and paste the following:
Sign into the Okta Admin dashboard to generate this value.
SSO URL: Copy and paste the following:
Sign into the Okta Admin dashboard to generate this value.
Select Update Company Info.
Done!
The following SAML attributes are supported:
Name | Value |
---|---|
firstName | user.firstName |
lastName | user.lastName |
emailAddress | This is configured in the app UI; see emailAddress attribute value instructions below. |
employeeNumber | user.userName |
department | user.department |
title | user.title |
city | user.city |
state | user.state |
startDate | appuser.startDate; see startDate attribute value instructions below. |
In Okta, select the Sign On tab for the EmployeeReferrals.com app, then click Edit.
Scroll down to the ADVANCED SIGN-ON SETTINGS section.
Select a required value for the emailAddress attribute from the dropdown list:
Click Save.
In order to add the startDate attribute, perform the following steps:
In Okta, navigate to Directory > Profile Editor.
Search for the EmployeeReferrals.com app, then click Profile.
Click Add Attribute, then enter the following:
Display Name: enter the Start date value.
Variable Name: enter the startDate value.
Click Add Attribute.
Note: Scope (optional): If you check user personal, the startDate attribute will be available once you assign the user to the EmployeeReferrals.com app and will not be available once you assign the group to the app.
Click Map Attributes:
Select the Okta to EmployeeReferrals.com tab, then do the following:
Start typing the required attribute from the Okta base user profile (or use the dropdown list) and select the attributes you want to map.
In our example, we selected the hireDate custom user attribute, then the green arrows (Apply mapping on user create and update).
Click Save Mappings.
Click Apply updates now:
Now Okta will pass startDate attribute with the value of the hireDate custom field from the Okta base user profile.
Go to https://[YourSubDomain].employeereferrals.com, then click on LOG IN: