This guide walks you through configuring Single Sign-On (SSO) between ObservePoint and Okta using SAML 2.0.
Prerequisites
Admin access to your Okta account
Admin access to your ObservePoint account
Step 1: Start SSO Configuration in ObservePoint
Log into ObservePoint as an Account Admin
Navigate to Settings > Single Sign-on
Click to start a new SSO configuration
Step 2: Create SAML Application in Okta
Sign into the Okta admin console
In the left navigation, expand Applications and click Applications
Click Create App Integration
Select SAML 2.0 as the integration type
Click Next
Step 3: Configure General Settings
Give your application a name (e.g., "ObservePoint")
(Optional) Upload a logo
Click Next
Step 4: Configure SAML Settings
Setup ACS CALLBACK URL: Copy values from ObservePoint
Audience URI (SP Entity ID): Copy values from ObservePoint
Advanced settings (optional): These can be configured but are not required for a minimal setup
Click Next
Step 5: Complete Application Setup
On the feedback page, select the appropriate options or simply click Finish
Step 6: Assign Users and Groups
Navigate to the Assignments tab in your new application
Click the Assign button
Choose Assign to People or Assign to Groups
Search for the users or groups who need access to ObservePoint
Click the Assign button next to each user or group
Click Done when finished
Step 7: Get the Metadata URL
Return to the Sign On tab
Scroll to the SAML 2.0 section in the Settings pane
Copy the Metadata URL
Step 8: Complete ObservePoint Configuration
Return to the ObservePoint SSO configuration screen
Paste the Okta Metadata URL into the configuration field
ObservePoint will validate the URL and retrieve all necessary configuration data
Click Next
Step 9: Configure ObservePoint SSO Settings
Choose an account subdomain for SSO login (e.g.,
yourcompany.app.observepoint.com)User provisioning: Choose whether to automatically create ObservePoint accounts for users who don't already exist
Users are matched by email address from your identity provider
If auto-provisioning for new users is disabled, users must have an existing ObservePoint account before logging in via SSO
Step 10: Test and Activate
Click Test the SSO configuration
Verify that you can successfully authenticate
If the test is successful, click Activate to enable SSO for your account
Your Okta SSO integration is now live login using your custom subdomain!
Advanced Features
Once your basic SSO setup is complete, you can configure these additional features:
Require signed SAMLRequests: Enhanced security requiring Okta to import ObservePoint's certificate from the metadata file
Single Sign-On (SSO): Allow users to launch ObservePoint directly from the Okta portal
Single Logout (SLO): When a user's Okta session ends, their ObservePoint session will also end
Note: ObservePoint will not terminate the Okta session
Troubleshooting
If you encounter issues:
Verify that the metadata URL is correct and accessible
Ensure users are properly assigned in Okta
Check that email addresses match between Okta and ObservePoint
Confirm that your subdomain is unique and available
