SAML and OKTA SSO Configuration

The integration has two steps, one on the Service Provider side and one on the Datarails side.

Step 1  - Datarails

Enforce Login Authorization Method

Admins can define the login authorization method for their organization.

  1. From the Home page, navigate to the left-side panel and click on Admin
  2. From there, click on Organizations

screenshot-app.datarails.com-2022.06.20-11_57_14.png

  1. In the new page that opens, find your organization (there may be only one) and click on the three dots ellipsis.
  2. Then from the dropdown choose, Enforce Auth Method For Admins

screenshot-app.datarails.com-2022.06.20-12_02_16.png

  1. Select “SAML” method and click the “Save” button
  2. Click Save.
  3. Click on the three dots on the right of the organization, and select Edit SAML Configurations:
  4. Enter the information from the SAML site in the following screen:
    Name: Name this SSO
    IDP Issue (entityID): Will be popluted automatically. The unique identifier for the Identity Provider (IdP) in a SAML configuration
    IDP Medadata URL: The link provided by the Identity Provider that contains all the configuration information the Service Provider needs to set up SAML SSO. For OKTA instructions on creating this link go to Step 2
  5. Click Save

User Login flow 

    1. In the login screen select the SAML button
    2. Fill the domain and click “Sign In”

 

Generate SCIM Auth Token

To enable SCIM-based provisioning, you must generate an authentication token associated with your user account. Follow these steps:

  1. Navigate to Datarails Admin > Members & Groups.

  2. Locate your user account (SCIM operations will be executed under this user).

  3. Click the three-dot menu next to your user entry and select SCIM Token.

  4. Copy the generated SCIM token and SCIM base URL. These will be required when configuring SCIM in your identity provider (e.g., Okta).


 

 

Step 2  - Service Provider Setup, for example: OKTA

 

2.1 Login in the okta site and click on the “Admin” button

2.2 On the new page select “Add APP” option

2.3 Select a “Create new APP” option

2.4 Choose “SAML 2.0” type

2.5 Type APP name

2.6. Fill all required fields

Single sign-on URL:  https://app.datarails.com/saml2/acs/

Audience URI (SP entity ID): https://app.datarails.com/saml2/metadata/

NameID format: EmailAddress

Application UserName: Email

Attribute statements:  email -> user.email

2.7 Click "Finish"

2.8 Copy metadata URL

2.9 Go to the “Assignments” tab

2.10 Select Assign to people

2.11  Select all necessary people and click Done





© Datarails Ltd. All rights reserved.

Updated

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request

Comments

0 comments

Please sign in to leave a comment.