---
title: "Configure Okta SAML for AIM"
canonical: "https://docs.aryaka.com/space/KNOW/144638068/Configure%20Okta%20SAML%20for%20AIM"
format: markdown
---
This document explains how to configure your Okta SAML identity provider (IdP) to synchronize users and user groups between Okta and MyAryaka.  To edit or delete an existing configuration, see the  Manage Okta SAML  topic. Some of the procedures described in this document are performed in the Okta administrator interface. While we have made every effort possible to ensure accurate descriptions and screen captures at time of publication, updates to the Okta UI are beyond our control. Refer to the documentation provided by Okta to ensure you have the most recent information. Prerequisites MyAryaka account with read and write access Okta administrator account Configure identity authentication using Okta SAML in MyAryaka Complete the procedure described in this section to add an Okta instance to your Aryaka Identity Management configuration and obtain SAML settings required for subsequent configuration. To configure identity authentication using Okta SAML in MyAryaka Go to MyAryaka at  https://my.aryaka.com/ . The MyAryaka Login page appears. Log in using your MyAryaka credentials. The Home page appears. Click  Global Settings  in the left navigation pane. The Global Settings page appears and displays a series of tiles. Click  Manage  in the Identity Management tile. The Aryaka Identity Management page appears. Click  Add  on the Enterprise’s Okta tile in the Available Identity Providers section. The Configure Enterprise’s Okta page appears and displays the following panes: SAML Identity and Provider Pre-configuration steps for SAML Okta SAML Details In the SAML Identity and Provider section, enter a name for this Okta instance in the Enterprise’s Okta Name field. Note that you can create multiple Okta instances. The fields in the Pre-configuration Steps for SAML section are automatically populated. These fields are required for the Okta SAML configuration described in step 5c in the next section. We recommend leaving this page open, as there are more configuration tasks that you must perform here after working in the Okta user interface, as described in the next section.  Configure Aryaka as an Okta application Complete the procedure described in this section to configure SAML-based SSO and to create an application in Okta called  Aryaka Identity Management. To configure SAML SSO in Okta Log in to the Okta Admin Console as an administrator user.  Click  Applications  >  Applications  in the left navigation pane. The Applications page appears with the application catalog displayed by default: Click  Create App Integration . The Create a new app integration dialog appears: Click  SAML 2.0  then click  Next . The Create SAML Integration page appears with the General Settings tab displayed by default: Configure the SAML integration:  Enter  Aryaka Identity Management  in the App Name field.  Click  Next . The Configure SAML tab appears. In the Single sign-on URL field, enter the URL from the Single Sign-On URL field on the MyAryaka Configure Enterprise’s Okta page, for example: https://aim.aryaka.com/realms/c1/broker/saml/endpoint.  In the Audience URI (SP Entity ID) field, enter the ID from the SP Entity ID field on the MyAryaka Configure Enterprise’s Okta page, for example: https://aim.aryaka.com/realms/c1. (Optional) Complete the remaining fields as required. You can consult the Okta documentation for details about these fields and their available options. Click  Next . The Feedback tab appears. Click  Finish . Your SAML integration settings are saved, and the newly-create application appears on the Applications page. Obtain the SAML 2.0 metadata URL from Okta Complete the procedure described in this section to obtain the metadata URL or metadata XML file that is required to configure SAML in MyAryaka.  To obtain the SAML 2.0 metadata URL from Okta If it is not already open, navigate to the Applications page in the Okta Admin Console (click  Applications  >  Applications  >  Browse App Catalog ). The application you created in the previous section appears in the application catalog. Click the application name (for example,  Aryaka Identity Management ). The selected application’s details page appears (ensure the Sign On tab is selected): Click  Copy  below the Metadata URL. The URL is copied to your computer’s clipboard. You can paste this URL into MyAryaka as described in the next section. (Optional) Save the SAML 2.0 metadata as an XML file: Paste the copied metadata URL into your browser’s address field then press Enter. The metadata appears as an XML page. Click  File  >  Save As  in your browser, then name the file with an XML extension, for example: AryakaIdentityManagement.xml. You can upload this file into MyAryaka as described in the next section. Configure SAML in MyAryaka Complete the procedure described in this section to configure SAML in MyAryaka. You must provide the SAML 2.0 metadata URL or file obtained in the previous procedure.  To configure SAML in MyAryaka If it is not already open, navigate to the Configure Enterprise’s Okta page: Log in to MyAryaka. The Home page appears. Click  Global Settings  in the left navigation pane. The Global Settings page appears and displays a series of tiles. Click  Manage  in the Identity Management tile. The Aryaka Identity Management page appears. Click  Add  on the Enterprise’s Okta tile in the Available Identity Providers section. The Configure Enterprise’s Okta page appears. In the Okta SAML Details section, select one of the following Okta IdP Metadata options: Click  Upload File , click  Browse , and then navigate to the metadata XML file that you created in step 4 of the previous procedure. Click  Use URL  then paste the metadata URL copied from Okta in step 3 of the previous procedure. Enter the user domain that must be redirected to this instance of Okta in the IdP Redirect Domain field.  Click  Submit . MyAryaka obtains the Identity Provider Entity ID and Single Sign-On Service URL from the selected URL or file and displays them in the Okta SAML Details pane of the < IdPname > page. Create an access token in Okta Complete the procedure described in this section to create an access token in Okta that is used by the Aryaka Identity Management system to authenticate with Okta and obtain user and user group data. To create an access token in Okta Log in to the Okta Admin Console as a user with read-only permissions.  Click  Security  >  API  in the left navigation pane. The API page appears with the Authorization Servers tab displayed by default. Click the  Tokens  tab, then click  Create Token . The Create Token dialog appears. Enter a name for the token, then click  Create Token . The token is generated and appears in the Token Value field. Click the  Copy  icon. The token is copied to your computer's clipboard. You must paste the token into MyAryaka as described in the next section. Configure user and group API details in MyAryaka Complete the procedure described in this section to configure user and group API details in MyAryaka. You must provide the access token that you created in the previous procedure. To configure user and group API details in MyAryaka If it is not already open, navigate to the < IdPname > page for this Okta instance: Log in to MyAryaka. The Home page appears. Click  Global Settings  in the left navigation pane. The Global Settings page appears and displays a series of tiles. Click  Manage  in the Identity Management tile. The Aryaka Identity Management page appears. Click  Manage  on the Enterprise’s Okta tile in the Configured Identity Providers section. The < IdPname > page appears. Click  Edit  in the User and Group API Details pane. The User and Group API Details page appears in edit mode. Paste the API token that was created in the previous procedure into the API Token field. Enter the number of seconds between synchronization operations in the Sync Period field or accept the default 86400 seconds (24 hours). MyAryaka and Okta are synchronized whenever the time defined in this field passes. Select one of the following Source Type options: Click  Organization Domain , then enter the domain name in the Okta Domain field. For example, for Aryaka, the entry would be aryaka.okta.com.  Click  API URLs , then enter the appropriate URL in the Group API and the User API fields. For example, for Aryaka, the entries would be https://aryaka.okta.com/api/v1/groups and https://aryaka.okta.com/api/v1/users. (Conditional) Aryaka Identity Management currently supports up to 100 user groups for an organization. If your organization’s total group count is greater than 100, in the Groups section, enter group names in the  Filter Groups With Exact Match  field or enter partial group names in the  Filter Groups Start With  field to specify up to 100 groups that you want to configure for user identification. Click  View Filtered Groups  to view included user groups based on your filter criteria. Note:  If needed, you can still configure all IdP users in step 7. In the Users section, select one of the following toggles to specify which users to pull from the IdP: All Organization Users—Regardless of group configuration (specified in step 6), all users are pulled from the IdP and can be used for policy configuration. This option is selected by default. Users from Select Groups—Only users from the configured groups (specified in step 6) are pulled from the IdP. Click  Submit . A message confirms the configuration updates and your entries appear in the read-only User and Group API Details pane on the < IdPname > page Map users to the Aryaka Identity Management application in Okta Complete the procedure described in this section to assign users stored in Okta to the new application you created for Aryaka Identity Management. To map users to Aryaka Identity Management in Okta Log in to the Okta Admin Console as an administrator user. Click  Applications  >  Applications  in the left navigation pane. The Applications page appears. Click  Assign Users to App . The Assign Applications page appears with the Assign Apps to People tab displayed by default. In the Applications table, click the application name that you created in step 5a of the Configure SAML in Okta procedure (we suggested that you name it Aryaka Identity Management). In the People table, click one or more users that you want to assign the selected application. Note that you can click the  Person & Username  check box (first row of the People table) to select all entries in the People table. Click  Next  above or below the People table. The Confirm Assignments tab page appears. It displays the selected application (Aryaka Identity Management in this example) and all of the users assigned to it. Click  Confirm Assignments  above or below the the table. The assignments are saved and the Applications page appears. The assignments made are synchronized between Okta and MyAryaka when the next sync operation occurs (by default, it runs automatically every 24 hours). The Aryaka Identity Management >  IdPname  page includes a Last Successful Sync tile, which displays the timestamp of the last synchronization and the option to manually run the sync operation. Verify the integration in MyAryaka  Complete the procedure described in this section to verify your Okta integration in MyAryaka. After completing the configuration, you can view the total number of users and user groups in MyAryaka. To verify the Okta integration If it is not already open, navigate to the < IdPname > page for this Okta instance: Log in to MyAryaka. The Home page appears. Click  Global Settings  in the left navigation pane. The Global Settings page appears and displays a series of tiles. Click  Manage  in the Identity Management tile. The Aryaka Identity Management page appears. Click  Manage  on the Enterprise’s Okta tile in the Configured Identity Providers section. The < IdPname > page appears and displays the following: Sync Status tile—Displays the date and time of the last successful synchronization between Aryaka Identity Management and Okta. Pre-configuration Steps for SAML—Displays read-only fields that were used to configure SAML in Okta. Okta SAML Details pane—Allows you to modify and test the current Okta configuration. User and Group API Details pane—Allows you to modify the API used to query your users and user groups.  (Optional) Click  Resync  in the Sync Status summary tile to manually run the sync operation between Okta and MyAryaka. The Last Successful Sync, Users, and User Group tiles are updated. (Optional) Click  Test IdP Configuration  in the Okta SAML Details pane to determine if Aryaka Identity Management can query Okta. A pop-up message indicates whether the test succeeds or fails. (Optional) Click  Test Authorization  in the User and Group API Details pane to verify authorization. A pop-up message indicates whether the test succeeds or fails.  In this topic