Okta

How to Configure SAML 2.0 for SAP Concur Solutions (Legacy SSO)


This OIN app integration is built using the Concur legacy SSO functionality. If you wish to use the new Early Access SSO functionality in Concur, contact your Concur representative or Concur Support (https://www.concur.com/en-us/support) for more information. You can find the app integration for the new Concur SSO in the OIN named Concur Solutions (Early Access).

Contents


Supported Features

The Okta/SAP Concur Solutions (Legacy SSO) SAML integration currently supports the following features:

For more information on the listed features, visit the Okta Glossary.


Configuration Steps

  1. Concur requires a letter of authorization before implementing SAML 2.0 for your account:

    Download the following document, sign it, and scan the signed copy into a pdf file.

    Concur Letter of Authorization - SSO Only

  2. Download the following x.509 Certificate.

    Sign into the Okta Admin app to generate this variable.
  3. Click the link below to generate a SAML Activation Request email to Concur.

    Okta SSO Activation Request

    Note: If the above link does not generate an email message on your system, open this Email Text and copy and paste the information into a new email message.

  4. Complete the required information in the email; specifically, the company name, the name of the contact, the email address of the contact, and the phone number of the contact (optional). Additionally, please include your company name somewhere in the title of the email. Then, attach the Signed Letter of Authorization you scanned in step 1 and the x.509 Certificate you downloaded in step 2 to the email, and send it.
  5. Once Concur receives your SAML activation request email, they will process your request and their Implementation Team will reach out to the contact listed in the email with next steps. The process should only take 7 to 10 days. If you need Secondary SSO or Partner SSO, notify Concur when they contact you. For any questions about the Letter of Authorization, status updates on where your SAML activation process stands, or other questions, please contact concur_saml_activation@okta.com.
  6. In Okta, select the Sign On tab for the SAP Concur Solutions (Legacy SSO) SAML app, then click Edit:

    • SSO Type: Select your Concur SSO type: Regular, Partner SSO, or Secondary SSO.

    • Click Save.

  7. Done!


Notes

Make sure that you entered the correct value in the Login URL field under the General tab in Okta. Using the wrong value will prevent you from authenticating via SAML to SAP Concur Solutions (Legacy SSO).