Skip to main content

Okta - SSO & SAML Configuration

Overview

Set up and maintain Okta as your identity provider (IdP) for login to ZenGRC.


Prerequisites

  • Administrator access to ZenGRC

  • Administrator access to Okta

Step by Step Instructions


Initial Setup and Configuration

This set of instructions is intended to be completed first and includes steps on the initial configuration.

1. Sign in to Okta

Sign in to Okta as an administrator.

2. Reviewing the Dashboard

Depending on the setup of the Okta for your company, this should take you to the main dashboard for Okta.

3. Go to Applications

Expand the Applications menu and select Applications

Okta documentation on Build a Single Sign-On (SSO) integration is included if needed for additional information

4. Create the SSO Application in Okta

Select Create App Integration to begin creating the integration between ZenGRC and Okta

5. Setting up for SAML 2.0

Select the SAML 2.0 from the options listed and click Next

6. Name the Application for SSO

Enter the App Name for the integration as ZenGRC and click Next

If you wish to add a logo for the Application and not show the gear icon (highlighted with the green box). Email Support at [email protected] and the image file can be sent to you.

Do not select any of the App Visibility option to avoid application from not displaying

7. Input the Metadata from ZenGRC

Enter the service provider metadata collected from ZenGRC into Okta.

  • If you happen to have administrative access to both Okta and ZenGRC, then you can copy-and-paste the values directly from ZenGRC into Okta as shown.

  • ​If you are an Okta administrator but do not have administrative access to ZenGRC, then copy-and-paste these settings from the text file provided to you by the ZenGRC administrator.

IMPORTANT

If Okta is configured for users to utilize an actual user account and not an email address to log into the network applications, the flag for the Application Username format under SAML Settings will need to be updated to email (Okta defaults to username).

Click Save.

8. Configure Advanced Settings

Click Show Advanced Settings in Okta.

9. Logout Settings

Next to Enable Single Logout, select the checkbox beside Allow application to initiate Single Logout.

10. Adding Additional Metadata from ZenGRC

In the Single Logout URL text box, paste the value from ZenGRC Single Logout URL. The string will end with "single_logout_service."

11. Adding Final Metadata from ZenGRC

In the SP Issuer field, paste the value again from ZenGRC Entity ID. The string will end with "metadata."

12. Load ZenGRC Signature Certificate

Click Browse next to Signature Certificate and select the certificate that your ZenGRC administrator should have provided.

Click Upload Certificate.

13. Attribute Setup

Under Attribute Statements, create two custom parameters as follows:

  • Add email to the Name field with a value of user.email

  • Add nickname to the Name field with a value of user.fullName

14. Configuration Complete

Scroll down to the bottom of the screen and click Next.

15. Feedback

Select the option I’m an Okta Customer Adding an Internal App to be able to skip the remaining questions on this screen.

16. Finishing the Configuration

Scroll down to the bottom and select Finish.

17. Download Okta SAML Certificate

From the main screen where the ZenGRC application was just created, be sure you have Sign On tab selected.

Scroll down till you see SAML Signing Certificates and select the drop-down from Actions and select Download Certificate.

Be sure this certificate is given to the ZenGRC Administrator, as it will be required to complete the integration between ZenGRC and Okta.

18. Add Users to the Application for SSO

The final step in Okta is to add users to the application that will require access to ZenGRC using the SSO Login option.

Users are added under the Assignments tab from the main screen where the ZenGRC application was just created.

The following steps MUST be completed in ZenGRC by the ZenGRC Administrator to complete the integration

19. Import the Okta SAML Certificate into ZenGRC

The certificate downloaded from Okta needs to be imported into ZenGRC by the ZenGRC Administrator.

From ZenGRC, go to Settings > Authentication.

Click the Edit Settings for the SAML 2.0 Authentication.

Scroll down to the bottom and select Browse to locate the file provided by the Okta Administrator.

Click Load IdP Metadata to load the certificate selected above.

The bottom fields, which should be blank for first-time setup, will populate automatically once the above file is imported with the Okta metadata information. This completes the integration handshake between the two systems.

Scroll down to the bottom and click Next

Scroll down to the bottom again and click Next to exit the settings screen

20. Enable SAML 2.0 and Debug

Enable the SAML 2.0 option on the Authentication Settings screen

Enable the Debug Mode on the Authentication Settings screen

SAML Groups Configuration


Contact Customer Support at [email protected] or via the Intercom Messenger to have SAML Groups enabled in your instance prior to following these steps.

1. Access Groups in ZenGRC

Log into ZenGRC and go to Settings > Authentication.

Click the option to Edit/Manage Groups.

2. Create Groups in ZenGRC for User Access

Enter a name for the four individual access groups (these will need to be duplicated in Okta as well).

Note: The groups can be named as you wish, but we recommend referencing the access level in it to avoid confusion.

Check the box for Enable group-based role handling in ZenGRC.

Click Save SAML Settings.

3. Log into Okta as an Administrator

Log into Okta as the Administrator.

4. Go to the User Interface

Click Developer Console in the top-left corner of Okta and select Classic UI.

5. Reviewing the Dashboard

Depending on the setup of the Okta for your company, this should take you to the main dashboard for Okta.

6. Go to Groups

Expand the Directory menu and select Groups.

7. Adding Groups to Okta

Select Add Group.

8. Setting Up the Group

Enter the name of the group exactly as it is in ZenGRC.

Enter a description (optional).

Click Save.

Do this step for each of the groups configured in ZenGRC. There should be 4 total (Administrator, Editor, Reader, Contributor). There is no group for No Access.

9. Confirm All Groups

Once all the groups have been added to Okta, verify they appear as expected and the names match exactly to what is in ZenGRC.

If you need to edit anything, select the title you want to edit and in the following screen click the Profile option to edit the name or description.

10. Add Users to the Groups

Select the group access name to add users to.
The first tab is labeled People.
Click the Assign People option to access the screen of adding users.

11. Selecting Users for Each Group

Scroll through the list of Not Members and click the users to add to the Members column who should be with this access level.

OR

Use the search option to find users and click on the name to add them to the Members column.

Click Save when done selecting users.

12. Adding Application to Group

The second tab is labeled Applications.

Click the Assign Applications option to access the screen of adding applications.

13. Selecting Application for Each Group

Use the Search field to find the application ZenGRC.

Click the Assign option next to the application.

Click Done to save.

14. Return to Groups

Click the Back to Groups option to go back to the main Groups screen to work on the next group.

Repeat steps 10 through 14 till all Group Names have been configured with Users and Application.

15. Verify Group Names Configured

Validate from the Group main menu that all 4 group names have People assigned and 1 Application assigned.

16. Go to Application

From the menu on the left-hand side, expand the Applications option.

Select Applications.

17. Select the ZenGRC Application

Use the Search field to find the ZenGRC application.

Click the application name to select it.

18. Change in the General Tab

Select General from the tab just below the title of the Application.

19. Editing the SAML Settings

Click the Edit option to the right-hand side of the SAML Settings.

20. Adding Group Attribute

Click Next in the General Settings setup.

In the SAML Settings screen, scroll down till Group Attribute Statements (optional) can be seen.

Enter the following parameters:

  • Add groups to the Name field.

  • Add .* to the field to the right of Matches regex.

Scroll down some more and click Next.

Scroll down to the bottom of the page and click Finish.

21. Change in the Assignments Tab

At the main Application screen, select the Assignments tab.

22. Remove the Individual Users

With the Groups added to the application, the Individual users need to be converted to the groups to avoid access issues.

23. Converting the Users

Using the drop-down menu, select the Convert All Assignments option. This will convert the Individual users that have been assigned to their respective Groups.

For users already logged into ZenGRC, this will not affect them. However, anyone trying to log in during the conversion may experience an issue as they are updated to the group they are assigned to. Once the conversion is done users should be able to log in normally.

24. Warning Message

When selecting the Convert All Assignments, a warning message will pop up. Select the Convert All option to start the process.

25. Validate the User Types

Once the conversion is complete, refresh the screen.

Validate the Type of user column to be sure all show Group. Any user who still shows as an Individual was not assigned to a Group in steps 10 and 11. It is best at this time to delete the user from the application using the X to the right-hand side of their name.

Then go back to the Groups screen and add the user(s) to their appropriate Group for access. This will automatically update the application through the Group and will not require another conversion.

Updating Certificates

This set of instructions is intended to be completed when a new certificate is required or is expiring.

1. Sign in to ZenGRC

Use the Sign in with SSO, provided the certificate you are replacing has not already expired for Okta. If so, then utilize Sign in with Email or Sign in with Google.

2. Access Authentication Settings

In the left-hand navigation, click Settings > Authentication.

3. Edit Settings

Click SAML 2.0 > Edit Settings to access the ZenGRC and Okta confirmation URLs and certificates.

4. Add IdP Certificate

Scroll to the bottom of the screen.

Click the option to + Add IdP Certificate.

Make sure the certificate file is available and open at this point. The file itself will not be imported, but rather the data in the file will need to be copied and then pasted into ZenGRC.

5. Adding Certificate Data

After clicking the + Add IdP Certificate a new blank field will open to allow the pasting of the certificate data from Okta to ZenGRC.

Be sure to copy all the data if using a file. There will be a starting and ending point identified by the following:

-----BEGIN CERTIFICATE-----

-----END CERTIFICATE-----

Be sure to copy everything as it is all required for the certificate creation in ZenGRC.

Click Save when done.

6. Confirm Loaded Certificate

Once saved, there should now be two certificates displayed:

The old one was originally configured with SSO/SAML and the new one just added.

Click Next and Next (following screen) to exit out.

The next step of removing the old certificate is OPTIONAL - keeping the application clean is important, but not required.

7. Removing Old Certificate

Click the at the end of the box containing the old certificate.

A drop-down will display and selecting Delete will delete the old certificate.

After deleting the certificate, be sure to log out and log back into ZenGRC to be sure the new certificate alone is working and will allow SSO login to continue.

Did this answer your question?