Okta

How to Configure SAML 2.0 for Workfront

Contents


Supported Features

The Okta/Workfront SAML integration currently supports the following features:


Configuration Steps

Note: There are multiple environments in Workfront. Please follow the instructions for the endpoint you wish to configure:

You can create a configuration for each endpoint by adding a new Workfront application to your organization.

Each environment has a different endpoint.

After configuring your desired environment please enter the desired environment endpoint in the ACS URL.

workfront1.png


Before you Begin

Generate the following variables, you will need them during configuration of any endpoint:


Configure SAML 2.0 for your Workfront Production Environment

  1. Sign into the production environment for your company.

  2. Select Setup in the top menu:

    workfront2.png

  3. Select System > Single Sign-On (SSO) from the Setup menu:

    workfront3.png

  4. Select Edit Settings:

    workfront4.png

  5. Select Single Sign-On > Edit Configuration:

    workfront5.png

  6. In the Single Sign-On screen that opens, select SAML 2.0 as the Type:

    workfront6.png

  7. Click Select Metadata XML then navigate to the metadata.xml file you saved earlier. The required fields will be populated from this file:

    workfront7.png

  8. For Certificate, click Choose File and navigate to the x.509 certificate you saved earlier. The required fields will be populated from this file:

    workfront8.png

  9. Check Auto-Provision Users:

    workfront_new1.png

  10. Click Map User Attributes:

    workfront9.png

  11. Map your attributes as shown below, then click Save:

    workfront_new2.png

  12. Click Test Connection:

    workfront_new3.png

  13. Click Save:

    workfront12.png

  14. Follow the steps in https://support.workfront.com/hc/en-us/articles/216671608-Updating-Users-for-SSO to change the Workfront Federated ID for all Workfront users to each user's email address.

  15. Done!


Configure SAML 2.0 for your Workfront Preview Environment

  1. Sign into the preview environment for your company.

  2. Select Setup in the top menu:

    workfront13.png

  3. Select System > Single Sign-On (SSO) from the Setup menu:

    workfront14.png

  4. In the Single Sign-On screen that opens, select SAML 2.0 as the Type:

    workfront15.png

  5. Under Populate fields from Identity Provider Metadata, click Choose File then navigate to the metadata.xml file you saved earlier. The required fields will be populated from this file:

    workfront16.png

  6. Check Auto-Provision Users:

    workfront_new1.png

  7. Map your attributes as shown below, then click Save:

    workfront17.png

  8. For Certificate, click Choose File and navigate to the x.509 certificate you saved earlier. The required fields will be populated from this file:

    workfront18.png

  9. Make sure the Admin Exemption and the Enable radio buttons are checked so admins can login without using SAML and to enable Single Sign-On:

    workfront19.png

  10. Click Test Connection:

    workfront20.png

  11. Click Save:

    workfront21.png

  12. Done!


Configure SAML 2.0 for your Workfront Sandbox

  1. Sign into the sandbox environment for your company.

    Note: For the sandbox environment, the sb01 endpoint number might differ. For example, it might be sb02, sb09 etc.

  2. Select Setup in the top menu:

    workfront22.png

  3. Select System > Single Sign-On (SSO) from the Setup menu:

    workfront23.png

  4. Select Edit Settings:

    workfront24.png

  5. Select Single Sign-On > Edit Configuration:

    workfront25.png

  6. In the Single Sign-On screen that opens, select SAML 2.0 as the Type:

    workfront26.png

  7. Under Populate fields from Identity Provider Metadata, click Select Metadata XML then navigate to the metadata.xml file you saved earlier. The required fields will be populated from this file:

    workfront27.png

  8. For Certificate, click Choose File and navigate to the x.509 certificate you saved earlier. The required fields will be populated from this file:

    workfront28.png

  9. Check Auto-Provision Users:

    workfront29.png

  10. Click Map User Attributes, then click Save:

    workfront30.png

  11. Map your attributes as shown below, then click Save:

    workfront31.png

  12. Make sure the Admin Exemption and the Enable radio buttons are checked so admins can login without using SAML and to enable Single Sign-On:

    workfront32.png

  13. Click Test Connection:

    workfront33.png

  14. Click Save:

    workfront34.png

  15. Done!


Notes

The following SAML attributes are supported: