Users with the Manage District Settings user permission can set up single sign-on with Okta. This integration creates user accounts as users log in for the first time.
This is a three-step process:
- In Okta, add a new SSO Connection.
- In Facilities Schedules, configure SAML .
- In Facilities Schedules, set default roles for users who login via Okta .
| Important: Because of the technical knowledge required, your district's IT administrator will most likely need to perform this procedure. |
Step 1: In Okta, add a new SSO Connection.
A few things to take note of while setting up the SAML application:
- Fields are case sensitive.
- Enter a unique App Name to correspond with Facilities Schedules.
-
For SAML Settings, set up the single sign-on URL.
Note: Enter https://XXXXX.mlschedules.com/MLSAMLConnect.aspx. Replace “XXXXX” with your custom Schedules subdomain. - Be sure to select the Use this for Recipient URL and Destination URL checkboxes.
- For the Application username, select Okta username.
- In Attribute Statements, you need to match the text exactly as follows:
- FirstName
Value: user.firstName - LastName
Value: user.lastName - Email
user.email - ExternalId
user.employeeNumber
- FirstName
- In Group Attribute Statements, select the groups you will pass to Schedules. This will then automatically assign users role(s) in Schedules.
- Select I'm an Okta customer adding an internal app.
- Download the SAML signing certificate to copy into Schedules.
| Note: Okta’s interface and field names may have changed since this was written. Use these steps as a general guide, and select the closest matching options in your Okta portal. |
Step 2: In Facilities Schedules, configure SAML
-
In Facilities Schedules, select Admin > Single Sign On > SAML Configuration. The SAML Integration Admin page appears.
-
Next to Okta, click
. A pop-up appears.
- Do the following:
- Under Issuer, enter the desired Okta URL.
- Under the Login Link, if desired, paste the App Embed Link from Okta.
-
Under Certificate, enter the certificate.
Note: You download this from Okta, then enter here. - Select the Classification for Users Group.
- Click Save.
Step 3: In Schedules, set default roles for users who login via Okta
|
Notes:
|
- Select Admin > Single Sign On > SAML Group Settings. The Manage SAML Groups page appears.
- Click +Add SAML Group. A pop-up appears.
- Do any of the following:
-
Enter a Group Name.
Note: This will be the group name established in Okta. - Select the desired Roles.
-
Select the desired Sites.
Note: To select All Sites, select the checkbox.
-
- Click Save.
- Repeat steps 2-4 for each group you want to add.
Comments
0 comments
Please sign in to leave a comment.