New LucidLink Single Sign-On (SSO) SAML 2.0: Integration with Okta

  • Updated

Target audience: Workspace administrators

This article is part of the New LucidLink Single Sign-On (SSO) SAML 2.0 implementation series of articles.

Requirements

  • Organization email domain configured and verified in the LucidLink Application or Webportal for your Workspace. Please use this article for the domain setup.
  • Admin Access to create the app in your Identity Provider's Admin Console.

Setup instructions

1. Start the integration within the LucidLink​ Application or Webportal

From the LucidLink Application or Webportal, click on the 3-dot menu next to the Workspace name and click on SSO Integration. Then click on the Set Up SSO button.

SSO Setup start.png

Obtain the values from the following 2 fields from the SSO configuration page to put into your IdP Admin Console in the next step:

  • Service Provider Consumer URL
  • Service Provider entity ID
SSO Config Start_new.png

2. Create a LucidLink app within the Okta Admin Console

If your Okta application is already created, choose it from the Application list and move to Section 3 - Configure the LucidLink application within the Okta Admin Console.

From your Okta Admin Console, click Applications from the left navigation menu.

SAML 2_0 create app.png

Click the Create App Integration button to create a new application.

Choose SAML 2.0 from the next screen and click Next.
SAML 2_0 selection.png

Give the App a name and click Next:

app configuration.png

3. Configure the LucidLink app within the Okta Admin Console

Enter the following values in the SAML Settings section panel:

  • Single sign-on URL (Service Provider Consumer URL value from LucidLink SSO Integration) 
  • Audience URI (SP Entity ID) (Service Provider entity ID value from LucidLink SSO Integration) 
  • Select EmailAddress from the Name ID format dropdown.

configure saml.png

Scroll Down to the Attribute Statements (optional) section, add the following attribute, and then hit Next.

Name:  Name format (optional) Value
email Unspecified user.email

 

attribute.pngOn the next screen select It's required to contact the vendor to enable SAML and click Finish.

vendor app.pngOn the Application Sign On page, expand the More Details section under the Metadata details section. 

more details button.png

Obtain the values from the following 2 fields to put into the LucidLink SSO Integration tab in the next step:

  • Sign on URL
  • Issuer

Click the Download button next to the Signing Certificate line.

4. Finish the integration within the LucidLink​ SSO Integration tab

Enter the 2 fields from the Okta Admin Console into the LucidLink SSO Integration tab:

  • Single Sign-On URL
  • Identity Provider entity ID (Issuer URL from  the last step in Okta)

browse to certificate file.png

Then upload the Identity provider certificate and click Save.

You have done it!

You should now see the Okta SSO setup In the LucidLink SSO Integration tab. You will need to select your authentication settings and then download the SSO Key to distribute to any users needing to authenticate to your Workspace via SSO.

Okta SSO is complete.png

Add users and groups to your app within the Okta Admin Console

You will need to assign your Okta users and groups to the new LucidLink app within the Okta Admin Portal before the users can authenticate within the LucidLink Application or Webportal.
add users_groups to app.png

Next Step:

 

Was this article helpful?

0 out of 0 found this helpful