Optimize SAML SSO configuration flow, add docs for Azure AD SAML

This commit is contained in:
Tuan Dang
2023-07-29 14:39:06 +07:00
parent cc4b749ce8
commit e961a30937
37 changed files with 126 additions and 60 deletions
+18 -19
View File
@@ -4,32 +4,31 @@ description: "Configure Okta SAML 2.0 for Infisical SSO"
---
Prerequisites:
- Okta Developer Account with access to create custom application integrations.
1. In Infisical, head over to your organization Settings > Authentication > SAML SSO Configuration and select **Set up SAML SSO**.
Next, copy the **ACS URL** and **Entity ID** to use when configuring the Okta SAML 2.0 application.
Next, copy the **Single sign-on URL** and **Audience URI (SP Entity ID)** to use when configuring the Okta SAML 2.0 application.
![SAML Okta Infisical initial configuration](../../../images/sso-okta-0.png)
![Okta SAML initial configuration](../../../images/sso/okta/init-config.png)
2. In the Okta Admin Portal, select Applications > Applications from the
navigation. On the Applications screen, select the **Create App Integration**
button.
![SAML Okta create app integration](../../../images/sso-okta-1.png)
![SAML Okta create app integration](../../../images/sso/okta/create-app-integration.png)
3. In the Create a New Application Integration dialog, select the **SAML 2.0** radio button:
![SAML Okta create SAML 2.0 integration](../../../images/sso-okta-2.png)
![SAML Okta create SAML 2.0 integration](../../../images/sso/okta/create-saml-app.png)
4. On the General Settings screen, give the application a unique name like Infisical and select **Next**.
![SAML Okta create SAML 2.0 integration](../../../images/sso-okta-3.png)
![SAML Okta create SAML 2.0 integration](../../../images/sso/okta/general-settings.png)
5. On the Configure SAML screen, set the **Single sign-on URL** to **ACS URL** and **Audience URI (SP Entity ID)** to
**Entity ID** from step 1.
5. On the Configure SAML screen, set the **Single sign-on URL** and **Audience URI (SP Entity ID)** from step 1.
![SAML Okta configure IdP fields](../../../images/sso-okta-4.png)
![SAML Okta configure IdP fields](../../../images/sso/okta/configure-saml.png)
<Note>
If you're self-hosting Infisical, then you will want to replace
@@ -43,30 +42,30 @@ Next, copy the **ACS URL** and **Entity ID** to use when configuring the Okta SA
- `firstName -> user.firstName`
- `lastName -> user.lastName`
![SAML Okta attribute statements](../../../images/sso-okta-5.png)
![SAML Okta attribute statements](../../../images/sso/okta/attribute-statements.png)
Once configured, select the **Next** button to proceed to the Feedback screen and select **Finish**.
Once configured, select **Next** to proceed to the Feedback screen and select **Finish**.
7. Get IdP values
Once your application is created, select the **Sign On** tab for the app and select the **View Setup Instructions** button located on the right side of the screen:
![SAML Okta view setup instructions](../../../images/sso-okta-6.png)
![SAML Okta view setup instructions](../../../images/sso/okta/view-setup-instructions.png)
Copy the **Identity Provider Single Sign-On URL**, the **Identity Provider Issuer**, and the **X.509 Certificate** to use when finishing configuring the Okta SAML in Infisical.
Copy the **Identity Provider Single Sign-On URL**, the **Identity Provider Issuer**, and the **X.509 Certificate** to use when finishing configuring Okta SAML in Infisical.
![SAML Okta IdP values](../../../images/sso-okta-7.png)
![SAML Okta IdP values](../../../images/sso/okta/idp-values.png)
Back in Infisical, set **Entrypoint** to **Identity Provider Single Sign-On URL**, **Issuer** to **Identity Provider Issuer**,
and **Certificate** to **X.509 Certificate** from above. Once you've done that, press **Add** to complete the required configuration.
Back in Infisical, set **Identity Provider Single Sign-On URL**, **Identity Provider Issuer**,
and **Certificate** to **X.509 Certificate** from above. Once you've done that, press **Update** to complete the required configuration.
![SAML Okta paste values into Infisical](../../../images/sso-okta-8.png)
![SAML Okta paste values into Infisical](../../../images/sso/okta/idp-values-2.png)
8. Finally, navigate to the **Assignments** tab and select **Assign**
You can assign access to the application on a user-by-user basis using the Assign to People option, or in-bulk using the Assign to Groups option.
![SAML Okta assignment](../../../images/sso-okta-9.png)
![SAML Okta assignment](../../../images/sso/okta/assignment.png)
At this point, you have configured everything you need within the context of the Okta Admin Portal.
@@ -74,4 +73,4 @@ At this point, you have configured everything you need within the context of the
Enabling SAML SSO enforces all members in your organization to only be able to log into Infisical via Okta.
![SAML Okta assignment](../../../images/sso-okta-10.png)
![SAML Okta assignment](../../../images/sso/okta/enable-saml.png)