---
title: "Configure SSO with Okta"
canonical: "https://docs.aryaka.com/space/KNOW/1268809736/Configure%20SSO%20with%20Okta"
format: markdown
---
MyAryaka Authentication is a single sign-on (SSO) service that enables customers to access multiple applications and platforms offered by Aryaka using a single set of log in credentials. Currently these applications include MyAryaka and the Ticketing Portal. Additionally, Aryaka offers support for customers who use Okta Single Sign-on to log in to the MyAryaka portal using their Okta credentials.  MyAryaka Authentication is enabled by default and can be used in conjunction with Okta SSO or disabled as described later in this document. This guide explains how to configure SSO with Okta. It includes the following sections: Prerequisites Obtain an Aryaka Customer ID Configure SAML in Okta Configure MyAryaka app in Okta Configure the IDP Metadata in MyAryaka Map Okta Users to Aryaka Users Log in using Okta SSO Some of the procedures described in this document are performed in the Okta administrator interface. While we have made every effort possible to ensure accurate descriptions and screen captures at time of publication, updates to the Okta UI are beyond our control. Refer to the documentation provided by Okta to ensure you have the most recent information. Prerequisites MyAryaka account with read/write access Okta administrator account Obtain an Aryaka Customer ID for Okta Go to MyAryaka at  https://my.aryaka.com/ . The MyAryaka Login page appears. Log in using your MyAryaka credentials. The Home page appears. Click  Global Settings  in the left navigation pane, then click  SSO  in the Access Control tile. The Single Sign On (SSO) page appears. Click the  Edit  icon to enter edit mode. Click the  External IDP   toggle. The configuration fields appear.  Click  Okta , then note the Customer ID—the unique identifier for your company or organization, for example, cust_710—that must be entered in the Okta UI as described in the next section. If you cannot complete this procedure for any reason, contact Aryaka Support at  support@aryaka.com . You must return to this page in MyAryaka to complete the SSO configuration  after  completing the steps in the Okta administrator portal. You may not want to log out or navigate away from this page at this time. Configure SAML in Okta Complete the procedure in this section to configure SAML-based SSO within Okta. This procedure results in an application being created in Okta called  MyAryaka . This application typically has an associated application tile that appears in your Okta dashboard. The procedure in this section (specifically step 5b) describes hiding the application tile to avoid confusion with a different application tile called  MyAryaka Login  that you are instructed to create in the next section. Note that even though you are hiding the MyAryaka tile, the underlying SAML configuration settings are being referenced even when the tile is hidden. To configure SAML SSO in Okta Log in to the Okta portal as an administrator user. The Dashboard appears: Click  Add Applications   in the right Shortcuts pane. The Add Application page appears:     Type MyAryaka In the search bar, select it from the list that drops appears, and then click  Add .  Click   Create New App  . The Create a New Application Integration dialog appears:   Select  Web   from the Platform drop-down list, click the   SAML 2.0   sign-on method, and then click   Create  . The General Setting tab of the Add MyAryaka page appears:    (Optional) Modify the entry in the Application Label field. Click the two  Do not display application icon ... checkboxes in Application Visibility field. This prevents the  MyAryaka  tile generated by this procedure from appearing in the Okta Gallery. You will create a  MyAryaka Login  tile in the next section that is used for the SSO login. Click  Done . The SAML Settings page appears. Click the  Sign On  tab. Do one of the following: Click the  Identify Provider Metadata  link to obtain the metadata URL. Alternatively, click  View Setup Instructions  to obtain the metadata URL. Copy or note this URL. It is required to configure SAML in MyAryaka as described in the Configure the IDP Metadata section. Click  Edit , then click  View Setup Instructions . The XML-formatted IDP metadata appears in the Optional section: Copy the XML content into an XML file and save it, for example:  OktaIDPMetadataForAryaka.xml . Upload this XML file to MyAryaka as described in the Configure the IDP Metadata section. In the Advanced Sign-On Settings section, paste or enter the customer ID that you copied from MyAryaka (in step 6 in the previous section) into the Customer ID field. Click  Save . The SAML settings are saved in Okta. Configure MyAryaka in Okta This section describes the procedure for creating the MyAryaka application in Okta, which results in the creation of a  MyAryaka Login  application tile that appears in the Okta gallery and is used to perform SSO. Step 2 of this procedure describes how to hide the  MyAryaka  application tile created by the SAML SSO configuration. This is intended for users that created the tile using earlier versions of this document. If you clicked the two checkboxes as described in step 5b in the previous section, you can skip step 2 in this section. To create the MyAryaka application entry in Okta Log in to the Okta Dashboard as an administrator user. (Optional) Hide the existing MyAryaka application tile that was created by the SAML SSO configuration: Search for MyAryaka in the Applications section, then select the MyAryaka application from the results: The MyAryaka App Setting page appears with the General tab displayed by default: In the Application Visibility field, click the following checkboxes, then click  Save : Do not display application icon to users Do not display application icon in the Okta Mobile App Click  Applications  in the top navigation pane, then click  Add Application . The Add Applications page appears: Click  Create New App . The Create a New Application Integration page appears: Click the  Platform  drop-down list, then select  Web  from the list of options. Click the  Secure Web Authentication (SWA)  option button Click  Create . The Create SWA Integration page appears. It includes two main sections: General App Settings How Will You Users Sign In? Configure the General App Settings as follows: Enter MyAryaka Login in the App Name field. Enter   https://my.aryaka.com/OktaLoginForm   in the App’s Login Page URL field. (Optional) Upload a logo using the instructions on the App Logo field. In the App Type field, click the  This is an internal application … checkbox. Scroll to the How Will You Users Sign In? section and configure it as follows: Select  Administrator sets username, password … from the Who Sets the Credentials? drop-down list. Select  Okta username  from the Application Username drop-down list. Select  Create and update  from the Update Application Username On drop-down list. Click  Finish . The MyAryaka Login application is now configured in Okta, but no users are configured to use it yet. Click the  Assignments  tab on the Applications page for the newly created MyAryaka Login application.   On the Assignments tab page that appears, click one or both of the following: •  Assign  >  Assign to People    • Assign  >  Assign to Groups Then select the Okta group or user in your organization that needs access to the MyAryaka application. After assigning access to users or groups, these users can see the MyAryaka Login application tile on the New Apps tab of the Okta gallery: Configure the IdP Metadata in MyAryaka This procedure describes entering the identify provider (IdP) metadata in MyAryaka. This metadata can be in the form of a URL or contained in an XML file depending on which option you selected in step 7 in the Configure SAML in Okta section. To configure the IdP metadata If the MyAryaka SSO page is not already open, navigate to it and enter edit mode as follows: Go to MyAryaka at  https://my.aryaka.com/ . The MyAryaka Login page appears. Log in using your MyAryaka credentials. The Home page appears. Click  Global Settings  in the left navigation pane, then click  SSO  in the Access Control tile. The Single Sign-On (SSO) page appears. Click the  Edit  icon to enter edit mode. Click the  External IDP  toggle, then click  Okta . The configuration fields appear and the Customer ID you used to configure Okta (in the previous section) appears in the Customer ID field  unless  you obtained the ID from Aryaka Support. (Optional) Click  No  to disable MyAryaka Authentication in the MyAryaka Authentication pane. MyAryaka Authentication is enabled by default and can be used in conjunction with Okta SSO. It currently provides SSO from within MyAryaka to the Ticketing Portal. Do one of the following in the Okta IDP Metadata pane: Click  Upload File , navigate to the XML file you created in step 7 in the Configure SAML in Okta section. When the IDP metadata XML file uploads successfully, SSO set-up is complete. If the IDP upload fails, contact Aryaka Support at  support@aryaka.com . Click  Use URL , then enter the URL that you obtained in step 7 in the Configure SAML in Okta section.  Click  Submit . Your order is submitted to Aryaka support for processing. You may need to configure users as described in the next section if their Okta user accounts differ from their Aryaka accounts. Map Okta Users to Aryaka Users This user mapping procedure is  not  required if a user's Okta account email address (used to log in to Okta) is the same as his or her MyAryaka username (the email address used to log in to MyAryaka). If the email addresses differ, the user's account must be configured in MyAryaka to match the corresponding Okta account. Users' accounts can be added or modified in the MyAryaka User Management section as follows.  To modify user accounts in MyAryaka Log in to MyAryaka. The Home page appears. Click  Global Settings  in the left navigation pane, then click  Users  in the Access Control tile. The Users page appears. It lists all users configured in MyAryaka and their email address used to access MyAryaka. Click the row of the user you want to modify. The user's details page appears:. Click the  Edit  icon. The page appears in edit mode and includes additional fields. Set the SSO ID same as Email field to  No , and then enter your Okta login ID (the user name you use to log in to Okta) in the SSO ID field that appears. Click  Submit . A change request is sent to Aryaka support. Repeat this procedure for all users configured in MyAryaka whose Okta login email address differs from their MyAryaka login email address. Log in using Okta SSO The SSO log in process differs slightly depending on whether the user’s organization has configured both authentication systems (that is, Aryaka’s and Okta’s), or only Okta’s: If the user’s organization has configured both authentication systems, the following workflow occurs the first time users click the MyAryaka Login tile in their Okta gallery: User is prompted for his or her MyAryaka username, then clicks Continue. The next window offers the option to Sign in with Okta. Note that if this user has previously logged in at  https://my.aryaka.com/ , he or she is not prompted for the MyAryaka username. User selects the Sign in with Okta option to complete the single sign-on and display the MyAryaka home page. On subsequent visits, users do not need to provide the MyAryaka username, when they select the Sign in with Okta option they go directly to MyAryaka home page. If the user’s organization has configured only Okta authentication, the following workflow occurs the first time users click the MyAryaka Login tile in their Okta gallery: User is prompted to enter his or her MyAryaka username, then clicks Continue. The MyAryaka home page appears. Note that if this user has previously logged in at  https://my.aryaka.com/  , he or she is not prompted for the MyAryaka username. On subsequent visits, when the user clicks on MyAryaka application tile in Okta, the MyAryaka homepage appears. If users clear their browser cookies, they must reenter their MyAryaka username the first time after clicking the MyAryaka tile in the Okta Dashboard. In this topic Related topics Configure SSO Log in to MyAryaka using SSO