Okta

How to Configure SAML 2.0 for Forter

Contents


Supported Features

The Okta/Forter SAML integration currently supports the following features:

For more information on the listed features, visit the Okta Glossary.


Configuration Steps

  1. Sign in to your Forter account.

  2. Navigate to Account > Settings > Single sign-on and follow the steps below:

    • Metadata IDP link: Copy and paste the following:

      Sign into the Okta Admin dashboard to generate this value.

    • Note your Single Sign On URL and Audience Restriction values.

    • Enter your company Allowed mail domains, then click + (plus) to add.

    • OPTIONAL GROUPS: If you want to pass Okta groups as part of the SAML response:

      1. Check Enable security groups mapping box.

      2. Map your Okta groups to Forter's user roles: Enter the corresponding Okta group for each Forter's user role.

        Note: In our example we have used ForterUser, ForterFinancial, ForterTech, and ForterSupport Okta group values.

    • Click Save Configuration:

    forter_newa.png

  3. In Okta, select the Sign On tab for the Forter app, then click Edit.

    • OPTIONAL GROUPS: Select your preferred group filter from the userGroups dropdown list (the Starts with rule with the value Forter in order to send a groups which start with the Forter value we used in our example) for the attribute.

    • forter_newb.png

    • Scroll down to the ADVANCED SIGN-ON SETTINGS section.

    • Enter the Single Sign On URL and Audience Restriction values you made a copy of in step 2 into the corresponding fields.

    • Click Save:

    forter_newc.png

  4. Done!

Notes


Here is an example describing how to add and use the userType attribute:

  1. In Okta, navigate to Directory > Profile Editor.

  2. Search for the Forter app, then click on Profile:

    forter_newd.png

  3. Click Add Attribute, then enter the following:

    • Display Name: Enter User Type attribute name.

    • Variable Name: userType.

      Important: You must use the following variable name for the userType attribute: userType.

    • Click Save.

    Note: Scope (optional): If you check User personal, it means that the current attribute will be available once you assign the user to the Forter application and will not be available once you assign the group to the app.

    forter_newe.png

  4. Click Map Attributes:

    forter_newf.png

  5. Select the Okta to Forter tab.

  6. Start typing the required attribute from the Okta Base User profile (or use the drop down list) and select the attributes you want to map.

  7. In our example, we have selected the userType attribute, then use the green arrows (Apply mapping on user create and update).

  8. Click Save Mappings:

    forter_newg.png

  9. Click Apply updates now:

    forter_newh.png

  10. Okta will now pass the userType attribute with the value of the userType field from the Okta Base User Profile.

NOTE:

The userType attribute supports the following values:

SP-initiated SSO

  1. Open the following URL: https://portal.forter.com/login/sso.

  2. Enter your company domain value.

  3. Click SIGN IN USING YOUR IDENTITY PROVIDER:

  4. forter8.png