Okta

How to Configure SAML 2.0 for Northpass

Contents


Supported Features

The Okta/Northpass SAML integration currently supports the following features:

For more information on the listed features, visit the Okta Glossary.


Configuration Steps

  1. Login to your Northpass instance as an administrator.

  2. Navigate to Account > Settings:

    Northpass Account Settings

  3. Make a copy of your School URL, then select Authentication:

    Northpass Authentication Settings

  4. Click Edit:

    Northpass Authentication Edit

  5. The question Are you sure you want to modify the authentication setup for your school? will appear, click Continue, then enter the following (see screen shot at end of step for reference):

    • Authentication Type: Select Shared Accounts from the drop down menu.

    • What type of shared account would you like to use?: Select the Okta and Just SSO options.

    • What is your identity provider single sign-on url?: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.

    • What is your identity provider issuer?: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.

    • What is your X.509 certificate?: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.
    • Click Save.

    SchoolKeep SSO Settings

  6. In Okta, select the Sign On tab for the Northpass app, then click Edit.

    • Enter your School URL that you made a copy of in step 3 into the corresponding field.

    • Click Save.

    Northpass Okta Sign On config

  7. Optional: To send groups as part of the SAML assertion, still in Okta, select the Sign On tab for the Northpass app, then click Edit.

    • Select the appropriate filter from the Groups drop down menu, then enter a value (see screen shot).

    • Click Save.

    SchoolKeep SSO Settings in Okta 2

  8. Done!


Notes

The following SAML attributes are supported:

SP-initiated SSO

Go to: https://[your-School-URL].