Okta

How to Configure SAML 2.0 for Illumio

Contents


Supported Features

The Okta/Illumio SAML integration currently supports the following features:

For more information on the listed features, visit the Okta Glossary.


Configuration Steps

  1. Login to your Illumio ASP.

  2. From the navigation menu, go to: Settings > Single Sign-On Configuration:

    illumio_new1.png

  3. Select SAML, then click Configure:

    illumio_new2.png

  4. Click Edit, then follow the steps below:

    • SSO method: Select SAML.

    • SAML Identity Provider Certificate: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.
    • Remote Login URL: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.

    • Logout Landing URL: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.

    • Authentication Method: Select Password Protected Transport.

    • Force Re-authentication (OPTIONAL): Check this option to enable Force Authentication.

    • Issuer: Make a copy of this value.

    • Assertion Consumer URL: Make a copy of this value.

    • Click Save:

    illumio_new3.png

  5. In Okta, select the Sign On tab for the Illumio app, then click Edit.

    • Enter the Assertion Consumer URL and Issuer values you made a copy of in step 4 into the corresponding fields.

    • Click Save:

    illumio_new4.png

  6. Optional: Group Attribute Steps: To send groups as a part of SAML assertion, in Okta select the Sign On tab for the Illumio ASP app, then click Edit.

    • Select the appropriate filter from the drop-down menu, then type the preferred value into the field.

    • Click Save.

    • Note: To send all groups a user is assigned to, select Regex and type .* (dot and star sign).

    illumio_new5.png

  7. Done!

Notes

The following SAML attributes are supported.

SP-initiated SSO

  1. Go to [your-Issuer] URL.

  2. Enter your username or email, then click Log In.

  3. illumio_new6.png


Force Authentication

  1. In Okta, select the Sign On tab for the Illumio ASP SAML app, then click Edit.

    • Uncheck Disable Force Authentication.

    • Click Save:

    illumio_new_a.png

  2. Check Force Re-authentication in step 4 of the Configuration Steps above