Okta

How to Configure SAML 2.0 for Coupa


Read this before you enable SAML

Enabling SAML will affect all users who use this application, which means that users will not be able to sign-in through their regular log-in page. They will only be able to access the app through the Okta service.

Backup URL

Coupa provides the following backup log-in URL where administrators can sign-in using their normal username and password: https://acme.coupahost.com/sessions/support_login, where https://acme.coupahost.com is your Coupa base URL.


Contents


Supported Features

The Okta/Coupa SAML integration currently supports the following features:

  • IdP-initiated SSO
  • SP-initiated SSO

For more information on the listed features, visit the Okta Glossary.


Configuration Steps

  1. Sign in to Coupa as a user with Coupa Administrative rights.

  2. Click on the Setup tab in the top menu:

    coupa_newa.png

  3. Several groups of links are displayed, including a group titled Company Setup. In the Company Setup group, click on the Security Controls link:

    coupa_new_1.png

  4. Scroll down to the Sign in using SAML section and check the Sign in using SAML checkbox, if it is not checked. When checked, new UI elements appear on the page:

    coupa_new_2.png

  5. Copy the following Metadata, and save as metadata.xml.

    Sign in to Okta Admin app to have this variable generated for you.
  6. Click Browse next to Upload Idp metadata to locate and upload the metadata.xml file you just created.

  7. In Okta, select the Sign On tab for the Coupa app, then click Edit.

    copua_new_3.png

  8.  In Coupa, select Users in the lower menu on the top of the screen:

    coupa_newd.png

  9. Select the Edit icon under Actions for the user for whom you want to enable SAML:

    coupa_new_4.png

  10. Copy the email address in the Login field to the Single Sign-On ID field, as shown below. The fields must be the same.

    coupa_newf.png

  11. Scroll down and select Save in the lower right of the window:

    coupa_newg.png

  12. Set the Single Sign-On ID for additional users, if desired.
  13. Done!


Notes

SP-initiated SSO

Open your base Coupa URL.

For example: https://acme.coupahost.com/.