> ## Documentation Index
> Fetch the complete documentation index at: https://docs.plerion.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Okta single sign-on

> Set up Okta single sign-on (SSO) with Plerion using SAML and role-based access control (RBAC).

With the **Okta single sign-on (SSO)** integration, you can enable secure authentication to Plerion through Okta. This setup uses SAML and role-based access control (RBAC) to map Okta users and groups to Plerion roles.

<Tip>
  We recommend using two different browser sessions (or two separate browsers) while configuring Okta and Plerion. This prevents conflicts caused by sharing the same login session.
</Tip>

## Steps to configure Okta SSO

<Steps>
  <Step title="Log in to Okta">
    Sign in to your Okta account with the required roles and permissions.
  </Step>

  <Step title="Create a new Okta application">
    * Go to `Applications` and click `Create App Integration`.
    * Select `SAML 2.0` and click `Next`.
    * Enter an app name and click `Next`.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/fJI95sGNdPDJ0pYK/images/onboarding/sso/okta-sso/okta-sso-app-name.png?fit=max&auto=format&n=fJI95sGNdPDJ0pYK&q=85&s=ffc860dce8e19a19f76ba88eda5a65e4" alt="Okta create SAML application screen" width="2312" height="1184" data-path="images/onboarding/sso/okta-sso/okta-sso-app-name.png" />
    </Frame>
  </Step>

  <Step title="Configure SAML settings">
    * In Plerion, go to `Admin` > `Security` > `Single sign-on` and copy the **SSO URL**.
    * In Okta, paste this URL into the **Single sign-on URL** and **Audience URI (SP Entity ID)** fields.
    * Set `Name ID format` to `EmailAddress`.
    * For `Attribute statements`, provide the required values and continue.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/fJI95sGNdPDJ0pYK/images/onboarding/sso/okta-sso/okta-sso-name-id-format.png?fit=max&auto=format&n=fJI95sGNdPDJ0pYK&q=85&s=fcb60da648212dec6a7757a23e7f4ea3" alt="Okta SAML settings showing Single Sign-On URL and Audience URI fields" width="2300" height="1518" data-path="images/onboarding/sso/okta-sso/okta-sso-name-id-format.png" />
    </Frame>
  </Step>

  <Step title="Finish Okta application setup">
    Review your settings, select your preferences, and click `Finish`.
  </Step>

  <Step title="Add users to the Okta application">
    * In Okta, go to `Directory` > `People` and click `Add person`.
    * Enter the user details and click `Save`.
    * Open your application, go to the `Assignments` tab, click `Assign` > `Assign to people`, and assign the new user.
    * Click `Done` to confirm.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/fJI95sGNdPDJ0pYK/images/onboarding/sso/okta-sso/okta-sso-add-person.png?fit=max&auto=format&n=fJI95sGNdPDJ0pYK&q=85&s=502fee1d4f60df00c13fafce86c7cca8" alt="Okta assignments page with user role selection" width="2284" height="688" data-path="images/onboarding/sso/okta-sso/okta-sso-add-person.png" />
    </Frame>
  </Step>

  <Step title="Copy identity provider details">
    * In your application, go to the `Sign-on` tab and click `View SAML setup instructions`.
    * Copy the **Single sign-on URL**, **Identity provider issuer**, and **X.509 certificate**.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/fJI95sGNdPDJ0pYK/images/onboarding/sso/okta-sso/okta-sso-copy-details.png?fit=max&auto=format&n=fJI95sGNdPDJ0pYK&q=85&s=07719a9767e0c4d64faa4ea6a4171621" alt="Okta SAML setup instructions with SSO URL and certificate" width="2136" height="1496" data-path="images/onboarding/sso/okta-sso/okta-sso-copy-details.png" />
    </Frame>
  </Step>

  <Step title="Configure trust in Plerion">
    * In Plerion, go to `Admin` > `Security` > `Single sign-on`.
    * Paste the following values into the matching fields:
      * **Single sign-on URL**
      * **Identity provider issuer**
      * **X.509 certificate**
    * Save the configuration.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/fJI95sGNdPDJ0pYK/images/onboarding/sso/okta-sso/okta-sso-configure-sso.png?fit=max&auto=format&n=fJI95sGNdPDJ0pYK&q=85&s=ea77facae256723251510760d1b1cbd2" alt="Plerion SSO trust configuration screen" width="2610" height="1490" data-path="images/onboarding/sso/okta-sso/okta-sso-configure-sso.png" />
    </Frame>
  </Step>

  <Step title="Test your Okta SSO connection">
    * Click `Test` in Plerion. A new window will open where you can sign in with the user you added in Okta.
    * Verify that you can log in to Plerion using Okta SSO.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/fJI95sGNdPDJ0pYK/images/onboarding/sso/okta-sso/okta-sso-test-connection.png?fit=max&auto=format&n=fJI95sGNdPDJ0pYK&q=85&s=5d968e0e2a5556063f6c74c70f3a37f4" alt="Plerion authentication test for Okta SSO" width="1838" height="1412" data-path="images/onboarding/sso/okta-sso/okta-sso-test-connection.png" />
    </Frame>
  </Step>
</Steps>

## Attribute mapping and roles

<Steps>
  <Step title="Create and assign Okta groups">
    * In Okta, go to `Directory` > `Groups` and click `Add group`.
    * Enter a name (for example, **testOrgAdmin**) and click `Save`.
    * Open your application, go to the `Assignments` tab, click `Assign` > `Assign to groups`, and assign your new group.
    * Add the previously created user to this group.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/fJI95sGNdPDJ0pYK/images/onboarding/sso/okta-sso/okta-sso-group-configuration.png?fit=max&auto=format&n=fJI95sGNdPDJ0pYK&q=85&s=e8927502c94fb6d44846f64614f1cfcf" alt="Okta groups configuration screen" width="1374" height="518" data-path="images/onboarding/sso/okta-sso/okta-sso-group-configuration.png" />
    </Frame>
  </Step>

  <Step title="Configure group attribute statements in Okta">
    * In your application, go to the `General` tab.
    * Under `SAML settings`, click `Edit` and go to `Configure SAML`.
    * Add a **Group attribute statement**.

    <Info>
      Example: Set the attribute name to **group** and use your group name (**testOrgAdmin**) as the filter.
    </Info>

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/fJI95sGNdPDJ0pYK/images/onboarding/sso/okta-sso/okta-sso-group-attribute-mapping.png?fit=max&auto=format&n=fJI95sGNdPDJ0pYK&q=85&s=43ca5873be852070c3bdca7ca2771c18" alt="Okta group attribute mapping configuration" width="1458" height="512" data-path="images/onboarding/sso/okta-sso/okta-sso-group-attribute-mapping.png" />
    </Frame>
  </Step>

  <Step title="Map attributes in Plerion">
    * In Plerion, go to `Admin` > `Security` > `Single sign-on` > `Attribute mapping`.
      * For **Email**, select **Use SAML Name ID**.
      * For **Display name**, leave unchecked to let users choose their own, or map the Okta user’s first and last name.
      * For **Roles**, add a mapping with the SAML attribute name **group**.
      * Map **testOrgAdmin** to the **Organization Admin** role.
    * Save the configuration.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/fJI95sGNdPDJ0pYK/images/onboarding/sso/okta-sso/okta-sso-plerion-attribute-mapping.png?fit=max&auto=format&n=fJI95sGNdPDJ0pYK&q=85&s=de7a93b7ff540cd6d8c2ae5ca488bc1d" alt="Plerion attribute mapping with role assignment" width="2516" height="1130" data-path="images/onboarding/sso/okta-sso/okta-sso-plerion-attribute-mapping.png" />
    </Frame>
  </Step>

  <Step title="Test the attribute mapping">
    * Click `Test` in Plerion.
    * Verify that the attribute mapping works as expected.

    <Frame>
      <img src="https://mintcdn.com/pleriondocs/fJI95sGNdPDJ0pYK/images/onboarding/sso/okta-sso/okta-sso-success.png?fit=max&auto=format&n=fJI95sGNdPDJ0pYK&q=85&s=3d59c439b48be79b7216859de8770f38" alt="Plerion attribute mapping test confirmation" width="1820" height="1406" data-path="images/onboarding/sso/okta-sso/okta-sso-success.png" />
    </Frame>
  </Step>
</Steps>

## Accessing Plerion through Okta

You can access Plerion using the **App Embed link** from your Okta application (`General` tab > `App embed link`).\
Log in with your Okta user credentials, and you will be signed in with the mapped Plerion role.

<Frame>
  <img src="https://mintcdn.com/pleriondocs/fJI95sGNdPDJ0pYK/images/onboarding/sso/okta-sso/okta-sso-embed-link.png?fit=max&auto=format&n=fJI95sGNdPDJ0pYK&q=85&s=6c90f0c55d05b1806dde71f7ecf40447" alt="Okta app embed link with URL for accessing Plerion" width="1430" height="934" data-path="images/onboarding/sso/okta-sso/okta-sso-embed-link.png" />
</Frame>
