Okta

How to Configure SAML 2.0 for OfficeSpace Software


Read this before you enable SAML

Enabling SAML will affect all users who use this application, which means that users will not be able to sign-in through their regular log-in page. They will only be able to access the app through the Okta service.

Backup URL

Contact the OfficeSpace Support team to turn off the SSO requirement and to provide a backdoor URL.

Contents


Supported Features

The Okta/OfficeSpace Software SAML integration currently supports the following features:

  • IdP-initiated SSO
  • SP-initiated SSO
  • JIT (Just In Time) Provisioning

For more information on the listed features, visit the Okta Glossary.


Configuration Steps

  1. Login to OfficeSpace Software as an administrator.

  2. Select the Settings tab, then select Connectors from the dropdown menu:

    officespace_new1.png

  3. Enter the following values into the corresponding fields (see screen shot at end of step for reference):

    • Check Enabled.

    • Check Is primary provider.
    • Logout provider url: Copy and paste the following into this field: Sign into the Okta Admin Dashboard to generate this variable.
    • Client idp target url: Copy and paste the following into this field: Sign into the Okta Admin dashboard to generate this value.
    • Client idp certificate fingerprint: Copy and paste the following into this field: Sign into the Okta Admin dashboard to generate this value.
    • Click Save
    officespace_new2.png
  4. In the Okta Dashboard for the OfficeSpace Software application, select Okta username for the Default username format, as shown below. 

    Username Format

  5. Done!

Notes

  • Make sure that you entered the correct value in the Subdomain field under the General tab in Okta. Using the wrong value will prevent you from authenticating via SAML to OfficeSpace Software.

  • The following SAML attributes are supported:

      Name Value
      first_name user.firstName
      last_name user.lastName
      email user.email
      fullname user.firstName+" "+user.lastName

SP-initiated SSO

Go to: https://[your-subdomain].officespacesoftware.com/users/auth/saml.