How to set up Okta single sign-on (SSO)
Okta can be configured as your Identity Provider for Marfeel, enabling single sign-on (SSO) access for your organization. This guide covers the requirements, supported features, and step-by-step configuration process.
Requirements
Section titled “Requirements”- Admin access to an Okta organization
- Admin access to a Marfeel organization on an Enterprise plan
Supported features
Section titled “Supported features”Okta SSO supports the following authentication flows with Marfeel:
Identity Provider (IdP)-Initiated Authentication (SSO) Flow: This authentication flow occurs when the user attempts to log into the application from the apps list in Okta.
Service Provider (SP)-Initiated Authentication (SSO) Flow: This authentication flow occurs when the user attempts to log into the application from Marfeel.
Just In Time (JIT) Provisioning: Automatic user creation when a user authenticated in Okta accesses Marfeel for the first time.
User Federation, role management, and similar administrative functions are not supported. Users and their Marfeel roles still need to be managed from the Marfeel settings page.
Configuration steps
Section titled “Configuration steps”-
Contact your account manager, or support, providing your Okta Domain (looks like xxx.okta.com). You will be provided an
aliasfor your account. -
In Okta, go to Applications, then Browse App Catalog, and search and add Marfeel. Link to Marfeel’s App on Okta’s Integration Network
-
Enter the provided
aliasin the required app settings. -
Assign the users or groups that should be able to log into Marfeel.
-
Go to the Marfeel App, then the Sign On tab, and note the Client ID and Client Secret. Contact your account manager, or support, to provide them.
Logging into Marfeel using Okta
Section titled “Logging into Marfeel using Okta”Once Okta SSO is set up, users on the Marfeel account can log in through Okta:
- Access Okta and navigate to the app’s page.
- Select Marfeel to log in.
Alternatively, you can access Marfeel directly by navigating to http://hub.marfeel.com/sign-in/oidc/{alias}.
What SSO features does Okta support with Marfeel?
Okta supports Identity Provider (IdP)-initiated and Service Provider (SP)-initiated authentication flows, as well as Just In Time (JIT) provisioning for automatic user creation. User federation and role management are not supported and must be managed from the Marfeel settings page.
How do I log into Marfeel using Okta SSO?
You can log in by accessing your Okta portal and selecting the Marfeel app, or by navigating directly to http://hub.marfeel.com/sign-in/oidc/{alias} where {alias} is the account alias provided by your account manager.
Can I make Okta SSO mandatory for all users?
Yes. Once Okta is configured as your identity provider, you can enforce SSO authentication as mandatory and disallow user/password logins from the Authentication and SSO settings page.