---
title: "Configure partner SSO"
canonical: "https://docs.aryaka.com/space/PTNR/784072990/Configure%20partner%20SSO"
format: markdown
---
MyAryaka includes the  MyAryaka Authentication  service, which provides single sign-on (SSO) authentication. This allows users to use one set of login credentials (name and password) to access multiple applications and platforms. Additionally, MyAryaka integrates with the following identity providers (IdP) that also provide SSO functionality: Azure Active Directory (Azure AD) Okta The three services can be used individually (standalone mode), or you can pair MyAryaka Authentication with either Okta or Azure AD. When either of the supported IdPs are configured individually, you log into the IdP, and the provided credentials allow you access to MyAryaka and whatever other applications are configured for the IdP. If you also choose to configure MyAryaka Authentication with an IdP, the provided credentials allow you access to MyAryaka and whatever other applications are configured for the IdP, and whatever applications are configured for SSO with MyAryaka. This topic describes configuring SSO integration with Azure AD and Okta. MyAryaka Authentication is enabled by default, and can be disabled during the configuration of Azure AD or Okta. Configure SSO with Azure AD  In general, the procedure to integrate Azure AD with MyAryaka is as follows: Obtain an Identifier, Reply URL, and Sign on URL for Azure AD in MyAryaka Configure SAML in Azure AD Configure the MyAryaka application in Azure AD Configure single sign-on in MyAryaka Upload metadata to Azure AD Map Azure users to Aryaka users Procedures must be performed using the Azure AD user interface and the MyAryaka user interface. To complete the procedures described, you must have a Microsoft Azure AD administrator account, and a MyAryaka account with read/write access. We have made every effort to provide accurate details about the Azure AD user interface, but updates to it are beyond our control. Refer to the documentation provided by Microsoft to ensure you have the most recent information for configuring Azure AD. To obtain an Identifier, Reply URL, and Sign on URL for Azure AD Log in to MyAryaka. The Home page appears. Click  Config  >  Access Control  >  Partner SSO . The Single Sign-On (SSO) page appears in read-only mode. Click the  Edit  icon. The page displays in edit mode. Click the  External IDP  toggle. The configuration fields appear. Click the  Azure AD  icon. The following fields appear (the values in these fields are required to configure SAML in Azure AD in the next section): Identifier (Entity ID) Reply URL Sign on URL   To configure SAML in Azure AD Log in to Azure AD as an administrator user at  https://manage.windowsazure.com . The Home page appears. Click  Azure Active Directory  in the left navigation pane. Click  Enterprise applications  on the Manage menu that appears. The Enterprise Applications – All Applications page appears. Click  New application . The New Application page appears. In the Add an Application pane (center), click  Non-gallery application , enter MyAryaka in the Name field (right pane), and then click  Add  (bottom right). After the addition of the MyAryaka application is processed, the SSO – Getting Started page appears. In the Manage menu, click  Single sign-on . The Select a Single Sign-on Method options appear. Click  SAML . The SSO – SAML-based Sign-on page appears. Click the  Edit  icon on the Basic SAML Configuration tile and paste the values copied from the Identifier, Reply URL, and Sign on URL fields in MyAryaka. These values were obtained from MyAryaka during the procedure in the previous section. Save  the changes to the Basic SAML Configuration tile. Click  Download  next to Federation Metadata XML in the SAML Signing Certificate section. The file is downloaded to your local computer or specified location. Share the downloaded Federation Metadata XML file with Aryaka using one of the following options: Upload it to MyAryaka as described in the next section. Contact Aryaka customer support at  support@aryaka.com  or  https://info.aryaka.com/contact-us.html . To configure the MyAryaka application in Azure AD Ensure you are logged in to Azure AD as an administrator user. Hide the existing MyAryaka application tile that you created for the SAML SSO: Go to the Azure AD Home page, click  Azure Active Directory  in the left navigation pane, and then select Enterprise Applications from the pop-up menu. The Enterprise Applications page appears. Click  All Applications  in the left navigation pane. The Enterprise Applications | All Applications page appears. Enter MyAryaka (or whatever name you entered in Name field in step 5 in the procedure in the previous section) in the Search field. The search results display the MyAryaka page. Click  Properties  in the left navigation pane, click  No  next to the Visible to Users option, and then click  Save . The SAML SSO configuration is updated to hide the MyAryaka application tile but retain the other properties. Return to the Enterprise Applications page. You can use the left navigation pane or the path at the top of the page. Click  New Application . The Add an Application page appears. Click  Non-gallery application . The Add Your Own Application page appears. Enter MyAryaka Login in the Name field, then click  Add . After the application is created, the MyAryaka Login | Overview page appears. Click  Assign users and groups . The MyAryaka Login | Users and Groups page appears. Click  Add User  and add the groups or individual users in your organization that need access to MyAryaka. Click  Overview  in the left navigation pane, then select  Set up Single Sign On . The MyAryaka Login | Single Sign-On (SSO) page appears. Select the  Linked  option. The MyAryaka Login | Linked Sign-on page appears. Enter  https://my.aryaka.com/IdpLoginForm  in the Sign on URL field, then click  Save . Click  Properties  in the left navigation pane, upload the Aryaka logo (optimum size for the logo is 215 x 215 pixels), and then click  Save . The MyAryaka Login application configuration is complete. Users that were assigned access can see the MyAryaka Login application tile in the Azure AD portal.  To configure single sign-on in MyAryaka Log in to MyAryaka. The Home page appears. Click  Config  >  Access Control  >  Partner SSO . The Single Sign-On (SSO) page appears in read-only mode. Click the  Edit  icon. The page displays in edit mode. Click the  External IDP  toggle. The configuration fields appear. Note that the MyAryaka Authentication is enabled by default. Click the  Azure AD  icon. The ADFS IDP Federation Metadata field appears. (Optional) Click  No  in the Enable MyAryaka Authentication field to disable the MyAryaka Authentication service that provides SSO from the MyAryaka portal to the Ticketing Portal. Click  Browse , then navigate to the Azure IDP Federation Metadata XML file (Federation Metadata) that you downloaded from the Azure AD administration portal. Click  Submit . The uploaded file is automatically processed, and the Aryaka (SP) Entity ID field appears. Click the   Download  icon next to the SP Metadata field to download the SP Metadata file, then upload it to the Azure AD portal as described in the next section.  To upload metadata to Azure AD  Log in to Azure AD as an administrator user at  https://manage.windowsazure.com . The Home page appears. Open the SAML-based Sign-on page if it is not already open. Click  Upload metadata file  to upload the file downloaded from MyAryaka (as described in the previous section) or received from Aryaka Support. The Upload Metadata File fields appear. Click the  Folder  icon next to the Select a File field, navigate to the metadata file, and then click  Add . If the metadata file uploads successfully, SSO configuration is complete. You may need to configure users as described in the next section if their Azure AD user accounts differ from their Aryaka accounts, otherwise, all of your users now can use Azure AD SSO to access MyAryaka.  If this step fails, contact Aryaka Support at  support@aryaka.com  or  https://info.aryaka.com/contact-us.html .  To map Azure AD users to MyAryaka users  This user mapping procedure is not required if a user's Azure AD account email address (used to log in to Azure AD) is the same as his or her MyAryaka username (the email address used to log in to MyAryaka). If the email addresses differ, the user’s account must be configured in MyAryaka to match the corresponding Azure AD account. Users’ accounts can be added or modified in the MyAryaka User Management section as follows. Log in to MyAryaka. The Home page appears. Click  Access Control  >  Partner Users . The Users page appears with all users listed in the table. Click the row in the table that contains the user that you want to map to Azure AD for SSO. The selected user's details page appears in read-only mode. Click the  Edit  icon. The page displays in edit mode. Set the SSO ID Same as Email field to   No , and then enter the email address that matches the email address configured in Azure AD.  Click  Submit  to send your change request to Aryaka Support for processing.  Repeat step 3 through step 6 for each user that requires mapping. To log in using Azure AD SSO The SSO log in process differs slightly depending on whether the user’s organization has configured  both  authentication systems (that is, Aryaka’s and Azure’s), or only Azure’s: If the user’s organization has configured  both  authentication systems, the following workflow occurs the first time users click the MyAryaka Login tile in their Azure portal: User is prompted for his or her MyAryaka username, then clicks Continue. The next window offers the option to Sign in with Azure. Note that if this user has logged in using the direct MyAryaka URL previously, he or she is  not  prompted for the MyAryaka username. User selects the Sign in with Azure option to complete the single sign-on and display the MyAryaka Home page. On subsequent visits, users do not need to provide the MyAryaka username, when they select the Sign in with Azure option, they go directly to MyAryaka Home page. If the user’s organization has configured  only Azure  authentication, the following workflow occurs the first time users click the MyAryaka Login tile in their Azure portal: User is prompted to enter his or her MyAryaka username, then clicks Continue. The MyAryaka Home page appears. Note that if this user has logged in using the direct MyAryaka URL previously, he or she is  not  prompted for the MyAryaka username. On subsequent visits, when the user clicks on MyAryaka application tile in Azure, the MyAryaka Home page appears. If users clear their browser cookies, they must reenter their MyAryaka username the first time after clicking the MyAryaka tile in the Azure portal. Configure SSO with Okta  In general, the procedure to integrate Okta with MyAryaka is as follows: Obtain an Entity ID for Okta in MyAryaka  Configure SAML and generate a metadata file in Okta Configure the MyAryaka application in Okta Upload the metadata file to MyAryaka Map Okta users to Aryaka users Procedures must be performed using the Okta user interface and the MyAryaka user interface. To complete the procedures described, you must have an Okta administrator account, and a MyAryaka account with read/write access. We have made every effort to provide accurate details about the Okta Dashboard user interface, but updates to it are beyond our control. Refer to the documentation provided by Okta to ensure you have the most recent information for configuring Okta. To obtain an Entity ID for Okta  Log in to MyAryaka. The Home page appears. Click  Config  >  Access Control  >  Partner SSO . The Single Sign-On (SSO) page appears in read-only mode. Click the  Edit  icon. The page displays in edit mode. Click the  External IDP  toggle. The configuration fields appear. Click  Okta . Copy the Customer ID (for example, cust_710) to your clip board. If you are a logged in as a Partner User, copy the Partner ID (for example, part_123) to your clipboard. This is required to configure SAML in Okta as described in the next section. You must return to this page in MyAryaka to complete the SSO configuration  after  completing the steps in the Okta administrator portal. You may not want to log out or navigate away from this page at this time.    To configure SAML in     Okta  Log in to the Okta portal as an administrator user. The Dashboard appears. Click  Add Applications  in the right Shortcuts pane. The Add Applications page appears. Search for MyAryaka in the Search bar, make a selection from the drop-down menu, and click  Add . Modify the label of the application if needed and click  Done . Click the  Identify Provider Metadata  link to get the metadata URL. Alternatively, click  View Setup Instructions  to find the metadata URL. Save this URL. Use this URL or upload the XML Upload file to MyAryaka as described in the next section. Navigate back to the Sign On tab and click  Edit . In the Advanced Sign On Settings section, paste or enter the customer portion of the entity ID (for example, cust_710) that you copied from MyAryaka in step 6 of the previous section. Click  Save . To configure the MyAryaka application in Okta Log in to the Okta Dashboard as an administrator user. Hide the existing MyAryaka application tile that you created for the Okta SSO: Search for MyAryaka in the Applications section, then select the MyAryaka application from the results. The MyAryaka App Setting page appears. In the Application Visibility field (under General > App Settings), click the following checkboxes, then click  Save : Do not display application icon to users Do not display application icon in the Okta Mobile App Click  Applications  in the top navigation pane, then click  Add Application . The Add Application page appears. Click  Create New App . The Create a New Application Integration page appears. Click the  Platform  drop-down list, then select  Web  from the list of options. Click the  Secure Web Authentication (SWA)  option button, then click  Create . The Create SWA Integration page appears. It includes two main sections: General App Settings How Will Your Users Sign In? Configure the General App Settings as follows: Enter MyAryaka Login in the App Name field. Enter  https://my.aryaka.com/IdpLoginForm  in the App’s Login Page URL field. (Optional) Upload a logo using the instructions on the App Logo field. In the App Type field, click the  This is an internal application … checkbox. Configure the How Will Your Users Sign In? settings as follows: Select  Administrator sets username, password … from the Who Sets the Credentials? drop-down list. Select  Okta username  from the Application Username drop-down list. Select  Create and update  from the Update Application Username On drop-down list. Click  Finish . The MyAryaka Login application is configured in Okta, but no users are configured to use it yet. Click the  Assignments  tab on the Applications page for the newly created MyAryaka Login application. The Assignments tab page appears. Click one or both of the following: Assign > Assign to People  Assign > Assign to Groups  Select the Okta groups or users in your organization that needs access to the MyAryaka application. After assigning access to users or groups, these users can see the MyAryaka Login application tile on the New Apps tab of the Okta gallery. To upload the IDP metadata file to MyAryaka If the MyAryaka SSO page is not already open, navigate to it and enter edit mode as follows: Go to MyAryaka at  https://my.aryaka.com/ . The MyAryaka Login page appears. Log in to MyAryaka. The Home page appears. Click  Access Control  >  Partner SSO . The Single Sign-On (SSO) page appears in read-only mode. Click the  Edit  icon. The page displays in edit mode. Click the  External IDP  toggle, then click  Okta . The configuration fields appear and the Entity ID you used to configure Okta (in the previous section) appears in the Aryaka (SP) Entity ID field  unless  you obtained the ID from Aryaka Support. (Optional) If you obtained the Entity ID from Aryaka Support, copy it into the Aryaka (SP) Entity ID field. (Optional) Click  No  to disable MyAryaka Authentication in the MyAryaka Authentication pane. MyAryaka Authentication is enabled by default and can be used in conjunction with Okta SSO. It currently provides SSO from within MyAryaka to the Ticketing Portal. Click  Upload File  in the Okta IDP Metadata pane, navigate to the XML file you created in step 5 in the previous section, and then click  Submit . If the IDP metadata XML file uploads successfully, SSO set-up is complete. You may need to configure users as described in the next section if their Okta user accounts differ from their Aryaka accounts, otherwise, all of your users now can use Okta SSO to access MyAryaka. If the IDP metadata XML upload fails, contact Aryaka Support at  support@aryaka.com  or  https://info.aryaka.com/contact-us.html .  To map Okta users to MyAryaka users  This user mapping procedure is  not  required if a user's Okta account email address (used to log in to Okta) is the same as his or her MyAryaka username (the email address used to log in to MyAryaka). If the email addresses differ, the user’s account must be configured in MyAryaka to match the corresponding Okta account. Users’ accounts can be added or modified in the MyAryaka User Management section as follows. Log in to MyAryaka. The Home page appears. Click  Access Control  >  Partner Users . The Users page appears with all users listed in the table. Click the row in the table that contains the user that you want to map to Okta for SSO. The selected user's details page appears in read-only mode. Click the  Edit  icon. The page displays in edit mode. Set the SSO ID Same as Email field to  No , and then enter the email address that matches the email address configured in Okta.  Click  Submit  to send your change request to Aryaka Support for processing.  Repeat step 3 through step 6 for each user that requires mapping.   To log in using Okta SSO   The SSO log in process differs slightly depending on whether the user’s organization has configured  both  authentication systems (that is, Aryaka’s and Okta’s), or only Okta’s: If the user’s organization has configured  both  authentication systems, the following workflow occurs the first time users click the MyAryaka Login tile in their Okta gallery: User is prompted for his or her MyAryaka username, then clicks Continue. The next window offers the option to Sign in with Okta. Note that if this user has previously logged in at  https://my.aryaka.com/ , he or she is  not  prompted for the MyAryaka username. User selects the Sign in with Okta option to complete the single sign-on and display the MyAryaka Home page. On subsequent visits, users do not need to provide the MyAryaka username, when they select the Sign in with Okta option they go directly to MyAryaka Home page. If the user’s organization has configured  only Okta  authentication, the following workflow occurs the first time users click the MyAryaka Login tile in their Okta gallery: User is prompted to enter his or her MyAryaka username, then clicks Continue. The MyAryaka Home page appears. Note that if this user has previously logged in at  https://my.aryaka.com/ , he or she is  not  prompted for the MyAryaka username. On subsequent visits, when the user clicks on MyAryaka application tile in Okta, the MyAryaka Home page appears. If users clear their browser cookies, they must reenter their MyAryaka username the first time after clicking the MyAryaka tile in the Okta Dashboard. In this topic Related topics Log in to MyAryaka using SSO Access the Ticketing Portal