> ## Documentation Index
> Fetch the complete documentation index at: https://airmdr-docs-google-workspace-skills-catalog.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Okta SSO Set-up and Configuration

> AirMDR supports Okta single sign-on to authenticate users for access to the AirMDR application.

### Overview

Okta Single Sign-On (SSO) can authenticate access to various applications by integrating it with your application. Here’s a step-by-step guide to setting up Okta SSO authentication.

AirMDR supports the Okta single sign-on (SSO) method for authenticating users and granting them access to the user interface.

### Pre-requisites

<Tip>
  Prior to set-up, Super Admin must have the Okta Developer Account with Admin access.
</Tip>

1. Login into the **Okta Admin Console**.
2. Enter your admin username and password, then click **Sign In**.
3. Navigate to **Applications** → **Applications** and click **Create App Integration**. A pop-up modal will show up.

   <img src="https://mintcdn.com/airmdr-docs-google-workspace-skills-catalog/s4Oj_J7GpXBNdoAE/images/SSO-14.png?fit=max&auto=format&n=s4Oj_J7GpXBNdoAE&q=85&s=64aa56e1d4a883d7800c0bbb14e8fb39" alt="SSO 14 Pn" width="2604" height="1176" data-path="images/SSO-14.png" />
4. In the pop-up modal, select the radio button next to SAML 2.0, and click **Next**.

   <img src="https://mintcdn.com/airmdr-docs-google-workspace-skills-catalog/s4Oj_J7GpXBNdoAE/images/SSO-15.png?fit=max&auto=format&n=s4Oj_J7GpXBNdoAE&q=85&s=97e7a455a028d720e0ad3fa275304221" alt="SSO 15 Pn" width="1852" height="1022" data-path="images/SSO-15.png" />
5. **Create SAML Integration**
   * In the General Settings tab, provide the following details

     * **App Name**: Enter `AirMDR`
     * **App logo:** (optional) - Upload the AirMDR logo for easier identification.
     * Click **Next.**

     <img src="https://mintcdn.com/airmdr-docs-google-workspace-skills-catalog/s4Oj_J7GpXBNdoAE/images/SSO-16.png?fit=max&auto=format&n=s4Oj_J7GpXBNdoAE&q=85&s=31ea0fa2c2642823127efba3f090fffa" alt="SSO 16 Pn" width="1470" height="1138" data-path="images/SSO-16.png" />
   * In the Configure SAML Settings tab, provide the following details
     * **Single sign-on URL**: [https://app.airmdr.com/airmdrapi/sso/acs](https://app.airmdr.com/airmdrapi/sso/acs)

       <Note>
         Make sure the check-box is selected for "**Use this for Recipient URL and Destination URL**"
       </Note>
     * **Audience URI (SP Entity ID)**: [https://app.airmdr.com/airmdrapi](https://app.airmdr.com/airmdrapi)
     * **Default Relay State**: [https://app.airmdr.com](https://app.airmdr.com/airmdrapi)

       <img src="https://mintcdn.com/airmdr-docs-google-workspace-skills-catalog/s4Oj_J7GpXBNdoAE/images/SSO-20.png?fit=max&auto=format&n=s4Oj_J7GpXBNdoAE&q=85&s=e9fdab2dc3fc27303508588a0d78f8b7" alt="SSO 20 Pn" width="1468" height="1460" data-path="images/SSO-20.png" />
     * Add a SAML attribute with name `email` and value `user.email`

       <img src="https://mintcdn.com/airmdr-docs-google-workspace-skills-catalog/s4Oj_J7GpXBNdoAE/images/SSO-17.png?fit=max&auto=format&n=s4Oj_J7GpXBNdoAE&q=85&s=6293b9a8fe70db3dbd103b998e1798c4" alt="SSO 17 Pn" width="1386" height="454" data-path="images/SSO-17.png" />
     * In the B section, preview the SAML assertion generated with the information provided (optional)
     * Click **Next.**

       <img src="https://mintcdn.com/airmdr-docs-google-workspace-skills-catalog/s4Oj_J7GpXBNdoAE/images/SSO-21.png?fit=max&auto=format&n=s4Oj_J7GpXBNdoAE&q=85&s=0b87c099335ae20c41b169f1dd35137e" alt="SSO 21 Pn" width="1470" height="668" data-path="images/SSO-21.png" />
   * In the Feedback tab, provide the necessary details for Okta Support to understand how you configured this application (Optional).
   * Click **Finish**.

     <img src="https://mintcdn.com/airmdr-docs-google-workspace-skills-catalog/s4Oj_J7GpXBNdoAE/images/SSO-22.png?fit=max&auto=format&n=s4Oj_J7GpXBNdoAE&q=85&s=9b4faa82939a28753331ff407ffed680" alt="SSO 22 Pn" width="1776" height="1582" data-path="images/SSO-22.png" />
6. On Finishing, you will be redirected to application, select the **Sign on** tab.

   <Tip>
     To view the configuration parameters at any time, navigate to **Applications** → **Applications**, click on the **ACTIVE** status tab, and then select the application you want to view the details for and select the **Sign On** tab.
   </Tip>

   <img src="https://mintcdn.com/airmdr-docs-google-workspace-skills-catalog/s4Oj_J7GpXBNdoAE/images/SSO-36.png?fit=max&auto=format&n=s4Oj_J7GpXBNdoAE&q=85&s=531eea19cfce0fbe6ced1d393dd82b74" alt="SSO 36 Pn" width="2030" height="1114" data-path="images/SSO-36.png" />
7. Click on the **More details** drop-down.

   <img src="https://mintcdn.com/airmdr-docs-google-workspace-skills-catalog/s4Oj_J7GpXBNdoAE/images/SSO-23.png?fit=max&auto=format&n=s4Oj_J7GpXBNdoAE&q=85&s=0d04c8cdb37198aadcb3de20c89449a2" alt="SSO 23 Pn" width="2150" height="1332" data-path="images/SSO-23.png" />
8. Securely Copy, Download the required Configuration Parameters
   * <Icon icon="angles-right" /> Sign on URL
   * <Icon icon="angles-right" /> Issuer ID
   * <Icon icon="angles-right" /> Download the Signing Certificate

     <img src="https://mintcdn.com/airmdr-docs-google-workspace-skills-catalog/s4Oj_J7GpXBNdoAE/images/SSO-24.png?fit=max&auto=format&n=s4Oj_J7GpXBNdoAE&q=85&s=8a1489fadcc56dcd5c61c15b34657572" alt="SSO 24 Pn" width="1098" height="766" data-path="images/SSO-24.png" />
9. Go to the **Assignments** tab of the application (For example: AirMDR) you just created.
10. Click **Assign** → **Assign to People** or **Assign to Groups.**

    <img src="https://mintcdn.com/airmdr-docs-google-workspace-skills-catalog/s4Oj_J7GpXBNdoAE/images/SSO-35.png?fit=max&auto=format&n=s4Oj_J7GpXBNdoAE&q=85&s=839d0a18f9f0aaf2cbe9a4e32a0c905b" alt="SSO 35 Pn" width="1794" height="704" data-path="images/SSO-35.png" />
11. Select the appropriate users/groups, then click **Assign** and **Done.**

### Set up and configure Okta SSO in AirMDR UI

1. Login into the [AirMDR](https://app.airmdr.com/) application.
2. On the bottom left, click on the **User** and select **Go to Admin dashboard**.

   <img src="https://mintcdn.com/airmdr-docs-google-workspace-skills-catalog/s4Oj_J7GpXBNdoAE/images/SSO-25.png?fit=max&auto=format&n=s4Oj_J7GpXBNdoAE&q=85&s=df68172574fcd3d015897cd34659277d" alt="SSO 25 Pn" width="706" height="488" data-path="images/SSO-25.png" />
3. Click on the midline ellipsis option (<Icon icon="ellipsis-vertical" color="#020203" />three dots) option below the ACTIONS column, and click **Edit**.

   <img src="https://mintcdn.com/airmdr-docs-google-workspace-skills-catalog/s4Oj_J7GpXBNdoAE/images/SSO-34.png?fit=max&auto=format&n=s4Oj_J7GpXBNdoAE&q=85&s=d31bc2f12056a48ee24b0a6bf310bbfa" alt="SSO 34 Pn" width="2792" height="214" data-path="images/SSO-34.png" />
4. Select the **SSO SETTINGS** tab.
5. In the **Setup SSO** dropdown list, select **Yes, New Config**.

   <Tip>
     If the parent organization has an existing SSO configuration and the child organization intends to reuse it, select the **Inherit from Parent** option from the **Setup SSO** drop-down menu.
   </Tip>

   <img src="https://mintcdn.com/airmdr-docs-google-workspace-skills-catalog/s4Oj_J7GpXBNdoAE/images/SSO-28.png?fit=max&auto=format&n=s4Oj_J7GpXBNdoAE&q=85&s=e162e85b23c1bc095b1a3a68920cf4ca" alt="SSO 28 Pn" width="1014" height="666" data-path="images/SSO-28.png" />
6. Fill in the SAML Protocol Configuration Parameters details generated from Okta.

   <Check>
     In the **Identity Provider (IdP) to use** dropdown list select **Custom.**
   </Check>

   <Check>
     Use **Upload** option to include the **Identity Provider Certificate** **(Signing Certificate)** downloaded from Okta.
   </Check>

   <Note>
     The downloaded Okta certificate has a default file extension of `.cert`.\
     Users must ensure the file extension is changed to `.crt` before uploading.

     <u>For example</u>: `Okta.crt`
   </Note>

   <Check>
     In the **Provide your SSO endpoint**, enter the **Identity Provider Login URL (Sign On URL)** copied from Okta.
   </Check>

   <img src="https://mintcdn.com/airmdr-docs-google-workspace-skills-catalog/s4Oj_J7GpXBNdoAE/images/SSO-29.png?fit=max&auto=format&n=s4Oj_J7GpXBNdoAE&q=85&s=e8cabc60cbf2548714535db8153b9b60" alt="SSO 29 Pn" width="1002" height="1266" data-path="images/SSO-29.png" />

   <Check>
     In the **Use Issuer ID** dropdown, select **Yes** and provide **Issuer** **ID** copied from Okta.
   </Check>
7. Click **Submit**. (SSO Okta SSO Authentication is successfully created for your account).

   <img src="https://mintcdn.com/airmdr-docs-google-workspace-skills-catalog/s4Oj_J7GpXBNdoAE/images/SSO-31.png?fit=max&auto=format&n=s4Oj_J7GpXBNdoAE&q=85&s=f95bc18f7e45dc136479ed830cf3cbbd" alt="SSO 31 Pn" width="984" height="900" data-path="images/SSO-31.png" />

### To Evaluate Integration

1. Navigate to the AirMDR Login page, enter your **Email,** and click **Proceed to Login**.

   <Info>
     As your SSO Okta SSO Authentication is successfully created for your account.
   </Info>

   <img src="https://mintcdn.com/airmdr-docs-google-workspace-skills-catalog/s4Oj_J7GpXBNdoAE/images/SSO-32.png?fit=max&auto=format&n=s4Oj_J7GpXBNdoAE&q=85&s=ca00e3ab9b5b028923d06a4f8fbf9d15" alt="SSO 32 Pn" width="670" height="438" data-path="images/SSO-32.png" />
2. The page will be redirected to the Okta URL provided as the **SSO Endpoint** in the **SSO SETTINGS**.
3. Enter the credentials created in the **Okta** → **User Management**

<Frame>
  <Icon icon="rocket-launch" />  Hurray! You are Logged in Successfully
</Frame>
