Okta

How to Configure SAML 2.0 for Infor CloudSuite

Contents


Supported Features

The Okta/Infor CloudSuite SAML integration currently supports the following features:

For more information on the listed features, visit the Okta Glossary.


Configuration Steps

  1. Sign in to Infor CloudSuite tenant as an administrator.

  2. In the upper-right corner click the user icon, then select User Management.

  3. On the left side click the application menu icon, then go to Security Administration > Federated Security.

  4. Expand Federated Security then click the + (plus) icon.

  5. Enter the following:

    • Select SAML 2.0 Enabled.

    • Select Authenticate with InforSTS.

    • Display Name: Enter Okta.

    • Import SAML Metadata: Save the following metadata as metadata.xml, then locate it by clicking FROM FILE

      Sign into the Okta Admin dashboard to generate this value.

    • Click IMPORT.

  6. [Optional SLO]: Check Enable Identity Provider Single Logoff.

  7. [Optional SLO]: Select HTTP Post and enter the following Logout URL:

    Sign into the Okta Admin Dashboard to generate this variable.

  8. Assertion Identity Key: Select Identity is a NameIdentifier element of the Subject statement.

  9. IFS user lookup field: Select Username.

  10. Service Provider Information: Click VIEW.

  11. Click the Save icon at the top of the page.

  12. To enable JIT still on the page scroll down and check JIT user Provisioning Enabled.

    NOTE: If you are going to enable SCIM skip this step and move to step 13.

  13. Go to Security Administration > Authentication URL Options.

  14. In Okta, select the Sign On tab for the Infor CloudSuite SAML app, then click Edit:

    • Base URL (old): Leave this empty.

    • Enter your Assertion Consumer Service and Entity ID values (step 10) into the corresponding fields.

    • Click Save.

  15. [Optional SLO]: In Okta, select the Sign On tab for the Infor CloudSuite SAML app, then click Edit:

    • Select Enable Single Logout.

    • Signature Certificate: Upload the certificate you saved in step 10.

    • Single Logoff Service (optional): Enter Single Logoff Service value (step 10).

    • Click Save.

  16. Done!



Notes

The following SAML attributes are supported:


SP-initiated SSO

Go to your default Authentication URL.

To obtain the default URL, go to User Management > Security Administration > Authentication URL Options.