Okta

How to Configure SAML 2.0 for Maas360

Contents


Supported Features

The Okta/MaaS360 SAML integration currently supports the following features:

For more information on the listed features, visit the Okta Glossary.


Configuration Steps

  1. Login to your MaaS360 account as an administrator.

  2. Navigate to SETUP > Settings:

    mass_new1

  3. In the next window, expand Administrator Settings, then click Advanced:

    mass_new2

  4. Under Login Settings, check the Configure Federated Single Sign-on checkbox, then click Use SAML for Single Sign-on:

    mass_new3

  5. Enter the following SAML settings:

    • Identity Provider Name: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.

    • Sign-in Page URL: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.

    • Verification Certificate: Upload the following:

      Sign in to the Okta Admin app to have this variable generated for you.

    • Custom login URL for your administrators: Make a copy of this value. This will be used to perform an SP-initiated SAML login to MaaS360.

    • Click Save.

  6. Since the application only supports an SP-initiated flow, we need to simulate an IDP-initiated flow with the Bookmark app (for more information, see Simulating an IdP-initiated Flow with the Bookmark App). Still in Okta, go to the General tab, then click Edit:

    • Check Do not display application icon to users and Do not display application icon in the Okta Mobile App options.

    • Click Save:

    mass_new4

  7. Add a Bookmark app:

    • Application label: Enter a preferred name.

    • URL: Enter the Custom login URL you copied in step 5.

    • Click Done:

    mass_new5

  8. Assign people to the Bookmark application.

  9. Done!


Notes

SP-initiated SSO

Go to the Custom login URL you copied in step 5.