Okta

How to Configure SAML 2.0 for UltiPro

Contents


Supported Features

The Okta/UltiPro SAML integration currently supports the following features:

For more information on the listed features, visit the Okta Glossary.


Configuration Steps

  1. Contact the UltiPro Support team and request that they enable SAML 2.0 for your organization. Ask them to provide you with the SAML URL and SP Issuer values as well as your SLO certificate.

    Note: The SP Issuer value and SLO certificate are needed if you are enabling Single Logout.

  2. The UltiPro Support team will provide you with the SAML URL, SP Issuer, and SLO certificate.

  3. In Okta, select the Sign On tab for the UltiPro app, then click Edit.

    • Scroll down to the ADVANCED SIGN-ON SETTINGS section.

    • Enter the SAML URL and SP Issuer values provided to you by UltiPro (step 2) into the corresponding fields.

    • Click Save:

    ultipro_new_a.png

  4. (Optional: SLO): If you want to enable Single Logout, in Okta, select the Sign On tab for your UltiPro app, then:

    • Check the Enable Single Logout box.

    • Click Browse to locate the SLO certificate provided to you by UltiPro (step 2), then Upload as shown below.

    • Click Save:

    ultipro_new_b.png

  5. Send back the following Metadata URL to the UltiPro Support team:

    Sign into the Okta Admin dashboard to generate this value.

  6. The UltiPro Support team will process your request. After receiving a confirmation email, you can start assigning people to the application.

  7. Done!


Notes

The following SAML attributes are supported:

SP-initiated SSO

Open the following URL: [yourSamlUrl]/?cpi=[entityID].

Where: