Okta

How to Configure SAML 2.0 for Veeva Vault

Before you begin

Please Contact Veeva Customer Support to enable SSO in your vault. Once they have done so, you can begin configuring SSO. You will need Vault Admin access in order to configure SSO in Veeva Vault. Please refer to Configuring Single Sign-On on Veeva Vault for further details. 

Contents


Supported Features

The Okta/Veeva Vault SAML integration currently supports the following features:

For more information on the listed features, visit the Okta Glossary.


Configuration Steps

  1. Login to Veeva Vault as an administrator.

  2. Navigate to Admin > Settings > SAML Profiles, then click Create:

    vault_1.png

  3. Enter the following:

    • Details

      • Label: Enter Okta.

      • Name: Enter okta.

      • Status: Select Active.

    • SAML Single Sign-on Configuration

      • SAML User ID Type: Select a required value. We used Vault User Name in our example.

      • SP Entity ID: Copy and paste the following:

        Sign in to the Okta Admin app to generate this variable.

      • Identity Provider Certificate: Download, save, then click Choose to locate and upload the following certificate to Veeva Vault:

        Sign in to the Okta Admin app to generate this variable.

      • Identity Provider Login URL and SP-Initiated Request URL: Copy and paste the following into both fields:

        Sign in to the Okta Admin app to generate this variable.

      • SP-Initiated Request Binding: Select HTTP POST.

      • Signature and Digest Algorithm: Select SHA-256.

    • Identity Provider Button

    • Click Save:

    enter SAML config values

    enter SAML config values

  4. Still, on the SAML Profiles page make a copy of your Vault SSO Login URL:

    Make a copy of your Vault SSO Login URL

  5. In Okta, select the Sign On tab for the Veeva Vault app, then click Edit:

    • Scroll down to the ADVANCED SIGN-ON SETTINGS section.

    • Enter the value you saved in step 4 into the Your Vault SSO URL field.

    • Click Save.

    veevavault_newb.png

  6. To complete SSO configuration, you must apply a security policy that enables user accounts to use SSO. For more information see here

  7. Done!


Notes

SP-initiated SSO

  1. Open your base URL. For example https://acme.veevavault.com.

  2. Click Click to log in with okta:

  3. vault_2.png