Okta

How to Configure SAML 2.0 for MindTouch

Contents


Supported Features

The Okta/MindTouch SAML integration currently supports the following features:

For more information on the listed features, visit the Okta Glossary.


Configuration Steps

  1. Contact your MindTouch Account Manager and request they enable SAML 2.0 for your account. For more information see SAML SSO - MindTouch setup.

  2. Include the following information with your request:

    • Entity ID: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.

    • Single sign-on service: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.

    • Public X.509 certificate: Download, save, then attach the following:

      Sign into the Okta Admin Dashboard to generate this variable.

  3. The MindTouch Professional Services team will process your request and will provide you with the service provider metadata URL.

    For example: https://example.com/@app/auth/[integrationid]/metadata.xml).

  4. In the service provider metadata, make a copy of the entityID (this is your Audience Restriction (SP Entity ID)) and AssertionConsumerService (this is your ACS URL) values marked in red, below:

    “mindtouch_new_1.png"

  5. In Okta, select the Sign On tab for the MindTouch app, then click Edit.

    • Enter the Audience Restriction (SP Entity ID)) and ACS URL you made a copy of in step 4 into the corresponding fields.

    • Click Save:

    mindtouch_new_2.png

  6. Group Attribute Steps (optional): To send Groups as part of SAML Assertion, in Okta, select the Sign On tab for the MindTouch app, then click Edit.

    • Select the appropriate Group filter from the dropdown menu, then enter a preferred value.

    • Click Save.

      Note: To send all groups a user is assigned to, select Regex and type .* (dot and asterix).

    • “mindtouch_new_3.png"

  7. Done!


Notes

The following SAML attributes are supported:


SP-initiated SSO

For SP-initiated flows go to the MindTouch app base URL.