Okta

How to Configure SAML 2.0 for Bright Funds

Contents


Supported Features

The Okta/Bright Funds SAML integration currently supports the following features:

For more information on the listed features, visit the Okta Glossary.


Configuration Steps

  1. Log in to your Bright Funds instance as an administrator.

  2. Navigate to Settings > Log In settings:

    Settings > Log in settings

  3. In the Email section, click Manage:

    In the Email section, click Manage

  4. Check Allow people to log in via email and password:

    Important: Do not uncheck this box until the SAML configuration has been tested successfully.

    Check Allow people to log in via email and password

  5. Click Save.

  6. In the Single Sign-on section, click Manage:

    In the Single sign-on section, click Manage

  7. In the Single Sign-on section, check Enable Single Sign-On:

    In the Single sign-on section, check Enable Single Sign On

  8. In the Configuration settings section, enter the following:

    • Sign-On URL: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.

    • Check Auto Provision Users in order to enable Just In Time Provisioning.

    • Name ID Format: Select Email:

    Enter configuration settings

  9. Save the Base URL from the Bright Funds Entity Id value.

    For example: If your Bright Funds Entity Id value is https://acme.brightfunds.org/auth/saml/consume

    Your Base URL value is https://acme.brightfunds.org:

    Save your Base URL from your Entity ID

  10. In the Certificates section, enter the following:

    • Certificate Name: Enter Okta.

    • Certificate: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.
    • Check Active.

    • Click Add new certificate.

    • Click Save:

    Enter Certificate settings

  11. In Okta, select the Sign On tab for the Bright Funds app.

  12. Scroll down to the ADVANCED SIGN-ON SETTINGS section.

  13. Enter the Base URL value from step 9 into the corresponding field.

  14. Click Save:

    Enter Base URL into Okta - Sign On tab

  15. Done!


Notes

The following SAML attributes are supported:


SP-initiated SSO

  1. Open your Bright Funds login URL.

  2. Under the Log in with single sign-on option, click Continue:

    Under Log in with Single Sign-on, click Continue