Okta

How to Configure SAML 2.0 for Netskope


Read this before you enable SAML

Enabling SAML will affect all users who use this application, which means that users will not be able to sign-in through their regular log-in page. They will only be able to access the app through the Okta service.

Backup URL

To bypass the SSO use the https://[your-subdomain].goskope.com/locallogin URL.

Contents


Supported Features

The Okta/Netskope SAML integration currently supports the following features:

For more information on the listed features, visit the Okta Glossary.


Configuration Steps

  1. Login to your Netskope account as an administrator.

  2. Click Settings in the bottom left corner:

    netskope_1

  3. Navigate to Administration > SSO:

    netskope_2

  4. In the Netskope Settings section make a copy of the Service Provider Entity Id value:

    netskope_3

  5. In the SSO/SLO Settings section click EDIT SETTINGS, then follow the steps below:

    • Select Enable SSO and Sign SSO Authentication Request options.

    • IDP URL: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.

    • IDP ENTITY ID: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.

    • IDP CERTIFICATE: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.
    • Click SUBMIT:

    netskope_4

  6. In Okta, select the Sign On tab for the Netskope SAML app, then click Edit:

    • Enter your Service Provider Entity Id value you made a copy of in step 4 into the corresponding field.

    • Click Save:

    netskope_5

  7. Optional: Group Attribute Steps: To send groups as a part of SAML assertion, in Okta select the Sign On tab for the Netskope app, then click Edit.

    • Select the appropriate filter from the drop-down menu, then type the preferred value into the field.

    • Click Save.

      Note: To send all groups a user is assigned to, select Regex and type .* (dot and star sign).

    netskope_6

  8. Done!

Notes


SP-initiated SSO

Go to: https://[your-subdomain].goskope.com URL.