Okta

How to Configure SAML 2.0 for PurchaseControl

Contents


Supported Features

The Okta/PurchaseControl SAML integration currently supports the following features:


Configuration Steps

  1. Contact PurchaseControl Support at support@purchasecontrol.com and request that they enable SAML 2.0 for your account.

  2. Include the following with your email request:

    • IDP Metadata: Copy and page the following:

      Sign in to Okta Admin app to have this variable generated for you.
    • x.509 Certificate: Copy and paste the following in PEM Text Format:

      Sign into the Okta Admin Dashboard to generate this variable.
    • IDP Issuer/Entity ID: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.

    • Login URL/SignOn URL: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.

  3. The PurchaseControl Support team will process your request. After receiving a confirmation email, you can start assigning people to the application.


New Base Profile Attribute

Before PurchaseControl can be used, a new base profile attribute needs to be added to your org. To do this, follow the instructions below:

  1. Login to Okta as an administrator, then click Admin:

    planergy1.png

  2. Navigate to Directory > Profile Editor:

    planergy2.png

  3. In the Profile Editor, edit the base profile attributes of your org’s users by clicking the Profile button for Okta users:

    planergy3.png

  4. Click Add Attributes to add a new base attribute:

    planergy4.png

  5. Add a new attribute based on the values in the image below, then click Add Attribute:

    planergy5.png

  6. By default, the Planergy attribute will be Read Only and only the admin can modify this value for users. If you want it to be updatable by users, edit the newly created attribute and set the user permission to Read-Write:

    planergy6.png

  7. To have PurchaseControl SAML app working, the Planergy attribute should always have a value. Depending on what user permission is assigned, an admin can either add it by modifying a user’s profile or a user can add the value himself. A user can add the value to this attribute by clicking Settings.

  8. Done!



Notes

The following SAML attributes are supported: