Okta is a standards-compliant OAuth 2.0 authorization server that provides cloud
identity solutions for your organization, and a single sign-on provider that makes
it easy to manage access to your Cloud App Security
account.
This section describes how to configure Okta as a SAML (2.0) identity provider for
Cloud App Security to use.
Before you begin configuring Okta, make sure that:
-
You have a valid subscription with Okta that handles the sign-in process and eventually provides the authentication credentials to the Cloud App Security management console.
-
You are logged on to the management console as a Cloud App Security global administrator.
Procedure
- Log in to your Okta organization as a user with administrative privileges.
- Click Admin in the upper right, and then navigate to .
- Click Add Application, and then click Create
New App.The Create a New Application Integration screen appears.
- Select Web as the Platform and SAML 2.0 as the Sign on method, and then click Create.
- On the General Settings screen, type a name for Cloud App Security in App name, for example, Trend Micro Cloud App Security, and click Next.On the General Settings screen, type a name for Cloud App Security in App name, for example, Cloud App Security, and click Next.
- On the Configure SAML screen, specify the
following:
- Type the Cloud App Security logon URL in
Single sign on URL based on your serving
site.For example, if the URL of your Cloud App Security management console in the address bar is "https://admin-eu.tmcas.trendmicro.com" after logon, type https://admin-eu.tmcas.trendmicro.com/ssoLogin in Single sign on URL.
- Select Use this for Recipient URL and Destination URL.
- Specify the Audience URI in Audience URI (SP Entity
ID), which is the Cloud App Security logon URL of your serving
site.For example, if the URL of your Cloud App Security management console in the address bar is "https://admin-eu.tmcas.trendmicro.com" after logon, the Audience URI is https://admin-eu.tmcas.trendmicro.com.
- Select EmailAddress in Name ID format.
- Select Okta username in Application username.
- Click Next.
- Type the Cloud App Security logon URL in
Single sign on URL based on your serving
site.
- On the Feedback screen, click I'm
an Okta customer adding an internal app, select This
is an internal app that we have created, and then click
Finish.The Sign On tab of your newly created Cloud App Security application appears.
- Click View Setup Instructions, and record the URL in Identity Provider Single Sign-On URL and the certificate content in X.509 Certificate.
- Assign the application to people.
- Select .
- Click the user that you want to assign the application to, and then
click Assign Applications.The Assign Applications screen appears.
- Locate Cloud App Security you added and click Assign.
- Verify the user name and click Save and Go Back.
- Confirm that the application is assigned to this user.
- Repeat the above steps to assign the application to more users as necessary.
You are now ready to configure Okta for single sign-on and add these users as administrators in the Cloud App Security management console.