> ## Documentation Index
> Fetch the complete documentation index at: https://docs.airmdr.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Okta SSO Set-up and Configuration

> AirMDR supports Okta single sign-on to authenticate users for access to the AirMDR application.

### Overview

Okta Single Sign-On (SSO) can authenticate access to various applications by integrating it with your application. Here’s a step-by-step guide to setting up Okta SSO authentication.

AirMDR supports the Okta single sign-on (SSO) method for authenticating users and granting them access to the user interface.

### Pre-requisites

<Tip>
  Prior to set-up, Super Admin must have the Okta Developer Account with Admin access.
</Tip>

1. Login into the **Okta Admin Console**.
2. Enter your admin username and password, then click **Sign In**.
3. Navigate to **Applications** → **Applications** and click **Create App Integration**. A pop-up modal will show up.

   <img src="https://mintcdn.com/airmdr/zY82Puh7osfDaxiZ/images/SSO-14.png?fit=max&auto=format&n=zY82Puh7osfDaxiZ&q=85&s=1dcb971d3d2bacf8a4d07fddb92f7397" alt="SSO 14 Pn" width="2604" height="1176" data-path="images/SSO-14.png" />
4. In the pop-up modal, select the radio button next to SAML 2.0, and click **Next**.

   <img src="https://mintcdn.com/airmdr/zY82Puh7osfDaxiZ/images/SSO-15.png?fit=max&auto=format&n=zY82Puh7osfDaxiZ&q=85&s=eec673df2a823a6d03fa07524ce62646" alt="SSO 15 Pn" width="1852" height="1022" data-path="images/SSO-15.png" />
5. **Create SAML Integration**
   * In the General Settings tab, provide the following details

     * **App Name**: Enter `AirMDR`
     * **App logo:** (optional) - Upload the AirMDR logo for easier identification.
     * Click **Next.**

     <img src="https://mintcdn.com/airmdr/zY82Puh7osfDaxiZ/images/SSO-16.png?fit=max&auto=format&n=zY82Puh7osfDaxiZ&q=85&s=9bf07755d038f789c5df38bdfca37207" alt="SSO 16 Pn" width="1470" height="1138" data-path="images/SSO-16.png" />
   * In the Configure SAML Settings tab, provide the following details
     * **Single sign-on URL**: [https://app.airmdr.com/airmdrapi/sso/acs](https://app.airmdr.com/airmdrapi/sso/acs)

       <Note>
         Make sure the check-box is selected for "**Use this for Recipient URL and Destination URL**"
       </Note>
     * **Audience URI (SP Entity ID)**: [https://app.airmdr.com/airmdrapi](https://app.airmdr.com/airmdrapi)
     * **Default Relay State**: [https://app.airmdr.com](https://app.airmdr.com/airmdrapi)

       <img src="https://mintcdn.com/airmdr/zY82Puh7osfDaxiZ/images/SSO-20.png?fit=max&auto=format&n=zY82Puh7osfDaxiZ&q=85&s=7489f3faa95a17a1591f87548e200de1" alt="SSO 20 Pn" width="1468" height="1460" data-path="images/SSO-20.png" />
     * Add a SAML attribute with name `email` and value `user.email`

       <img src="https://mintcdn.com/airmdr/zY82Puh7osfDaxiZ/images/SSO-17.png?fit=max&auto=format&n=zY82Puh7osfDaxiZ&q=85&s=d74479bf70606228e65ce48c19a8d754" alt="SSO 17 Pn" width="1386" height="454" data-path="images/SSO-17.png" />
     * In the B section, preview the SAML assertion generated with the information provided (optional)
     * Click **Next.**

       <img src="https://mintcdn.com/airmdr/zY82Puh7osfDaxiZ/images/SSO-21.png?fit=max&auto=format&n=zY82Puh7osfDaxiZ&q=85&s=2eeffdf5fd84d0e9f5ee11cec6adc97d" alt="SSO 21 Pn" width="1470" height="668" data-path="images/SSO-21.png" />
   * In the Feedback tab, provide the necessary details for Okta Support to understand how you configured this application (Optional).
   * Click **Finish**.

     <img src="https://mintcdn.com/airmdr/zY82Puh7osfDaxiZ/images/SSO-22.png?fit=max&auto=format&n=zY82Puh7osfDaxiZ&q=85&s=91f2a06f19158043650c29080b779f4b" alt="SSO 22 Pn" width="1776" height="1582" data-path="images/SSO-22.png" />
6. On Finishing, you will be redirected to application, select the **Sign on** tab.

   <Tip>
     To view the configuration parameters at any time, navigate to **Applications** → **Applications**, click on the **ACTIVE** status tab, and then select the application you want to view the details for and select the **Sign On** tab.
   </Tip>

   <img src="https://mintcdn.com/airmdr/zY82Puh7osfDaxiZ/images/SSO-36.png?fit=max&auto=format&n=zY82Puh7osfDaxiZ&q=85&s=b7dba0449ee5e7206b205e3743f7a29a" alt="SSO 36 Pn" width="2030" height="1114" data-path="images/SSO-36.png" />
7. Click on the **More details** drop-down.

   <img src="https://mintcdn.com/airmdr/zY82Puh7osfDaxiZ/images/SSO-23.png?fit=max&auto=format&n=zY82Puh7osfDaxiZ&q=85&s=e6d73d1fdb60ac61b5572541d0cf94de" alt="SSO 23 Pn" width="2150" height="1332" data-path="images/SSO-23.png" />
8. Securely Copy, Download the required Configuration Parameters
   * <Icon icon="angles-right" /> Sign on URL
   * <Icon icon="angles-right" /> Issuer ID
   * <Icon icon="angles-right" /> Download the Signing Certificate

     <img src="https://mintcdn.com/airmdr/zY82Puh7osfDaxiZ/images/SSO-24.png?fit=max&auto=format&n=zY82Puh7osfDaxiZ&q=85&s=c4f2e72025a6b6dfaa6ddefe95104523" alt="SSO 24 Pn" width="1098" height="766" data-path="images/SSO-24.png" />
9. Go to the **Assignments** tab of the application (For example: AirMDR) you just created.
10. Click **Assign** → **Assign to People** or **Assign to Groups.**

    <img src="https://mintcdn.com/airmdr/zY82Puh7osfDaxiZ/images/SSO-35.png?fit=max&auto=format&n=zY82Puh7osfDaxiZ&q=85&s=3bdfd0284559028bf13c137f01112b9e" alt="SSO 35 Pn" width="1794" height="704" data-path="images/SSO-35.png" />
11. Select the appropriate users/groups, then click **Assign** and **Done.**

### Set up and configure Okta SSO in AirMDR UI

1. Login into the [AirMDR](https://app.airmdr.com/) application.
2. On the bottom left, click on the **User** and select **Go to Admin dashboard**.

   <img src="https://mintcdn.com/airmdr/zY82Puh7osfDaxiZ/images/SSO-25.png?fit=max&auto=format&n=zY82Puh7osfDaxiZ&q=85&s=0fb4b458fda75f361b4c8d512cb0ff15" alt="SSO 25 Pn" width="706" height="488" data-path="images/SSO-25.png" />
3. Click on the midline ellipsis option (<Icon icon="ellipsis-vertical" color="#020203" />three dots) option below the ACTIONS column, and click **Edit**.

   <img src="https://mintcdn.com/airmdr/zY82Puh7osfDaxiZ/images/SSO-34.png?fit=max&auto=format&n=zY82Puh7osfDaxiZ&q=85&s=3e4380bfe8346b75e40d6c20773272e7" alt="SSO 34 Pn" width="2792" height="214" data-path="images/SSO-34.png" />
4. Select the **SSO SETTINGS** tab.
5. In the **Setup SSO** dropdown list, select **Yes, New Config**.

   <Tip>
     If the parent organization has an existing SSO configuration and the child organization intends to reuse it, select the **Inherit from Parent** option from the **Setup SSO** drop-down menu.
   </Tip>

   <img src="https://mintcdn.com/airmdr/zY82Puh7osfDaxiZ/images/SSO-28.png?fit=max&auto=format&n=zY82Puh7osfDaxiZ&q=85&s=ac898f6cc3a220428b406abb7f9cbd20" alt="SSO 28 Pn" width="1014" height="666" data-path="images/SSO-28.png" />
6. Fill in the SAML Protocol Configuration Parameters details generated from Okta.

   <Check>
     In the **Identity Provider (IdP) to use** dropdown list select **Custom.**
   </Check>

   <Check>
     Use **Upload** option to include the **Identity Provider Certificate** **(Signing Certificate)** downloaded from Okta.
   </Check>

   <Note>
     The downloaded Okta certificate has a default file extension of `.cert`.\
     Users must ensure the file extension is changed to `.crt` before uploading.

     <u>For example</u>: `Okta.crt`
   </Note>

   <Check>
     In the **Provide your SSO endpoint**, enter the **Identity Provider Login URL (Sign On URL)** copied from Okta.
   </Check>

   <img src="https://mintcdn.com/airmdr/zY82Puh7osfDaxiZ/images/SSO-29.png?fit=max&auto=format&n=zY82Puh7osfDaxiZ&q=85&s=b1b8da82c4d0a419a9a68b3c1732e01a" alt="SSO 29 Pn" width="1002" height="1266" data-path="images/SSO-29.png" />

   <Check>
     In the **Use Issuer ID** dropdown, select **Yes** and provide **Issuer** **ID** copied from Okta.
   </Check>
7. Click **Submit**. (SSO Okta SSO Authentication is successfully created for your account).

   <img src="https://mintcdn.com/airmdr/zY82Puh7osfDaxiZ/images/SSO-31.png?fit=max&auto=format&n=zY82Puh7osfDaxiZ&q=85&s=e8882fcd2700e028beee26dec7b9a725" alt="SSO 31 Pn" width="984" height="900" data-path="images/SSO-31.png" />

### To Evaluate Integration

1. Navigate to the AirMDR Login page, enter your **Email,** and click **Proceed to Login**.

   <Info>
     As your SSO Okta SSO Authentication is successfully created for your account.
   </Info>

   <img src="https://mintcdn.com/airmdr/zY82Puh7osfDaxiZ/images/SSO-32.png?fit=max&auto=format&n=zY82Puh7osfDaxiZ&q=85&s=6a667bbd8179e916b1405f81d3072025" alt="SSO 32 Pn" width="670" height="438" data-path="images/SSO-32.png" />
2. The page will be redirected to the Okta URL provided as the **SSO Endpoint** in the **SSO SETTINGS**.
3. Enter the credentials created in the **Okta** → **User Management**

<Frame>
  <Icon icon="rocket-launch" />  Hurray! You are Logged in Successfully
</Frame>
