# Okta

Go into your **Okta admin console** (it should look like this: `https://<your_url>.okta.com/admin/dashboard`)

1. In the sidebar menu, click on **Applications > Applications**

   <figure><img src="https://intuitem.gitbook.io/ciso-assistant/~gitbook/image?url=https%3A%2F%2F217025809-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FUJGpmCYDFJNsz2CDasSm%252Fuploads%252FAYesqWLkeQDiWw640Ij9%252FScreenshot.png%3Falt%3Dmedia%26token%3D89f99fe4-a81e-4e73-81c8-c833303ce9bd&#x26;width=768&#x26;dpr=4&#x26;quality=100&#x26;sign=24f90ebc&#x26;sv=2" alt=""><figcaption></figcaption></figure>

2. Click now on **Create App Integration**

   <figure><img src="https://intuitem.gitbook.io/ciso-assistant/~gitbook/image?url=https%3A%2F%2F217025809-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FUJGpmCYDFJNsz2CDasSm%252Fuploads%252FdSdR1MRDxoeRULPhYJhj%252FScreenshot%281%29.png%3Falt%3Dmedia%26token%3Dc4634784-ed28-4b6a-85ef-4b7464090149&#x26;width=768&#x26;dpr=4&#x26;quality=100&#x26;sign=e550153e&#x26;sv=2" alt=""><figcaption></figcaption></figure>

3. Select **SAML 2.0** and click on **Next**

   <figure><img src="https://intuitem.gitbook.io/ciso-assistant/~gitbook/image?url=https%3A%2F%2F217025809-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FUJGpmCYDFJNsz2CDasSm%252Fuploads%252FweUhSro71mwRYB0tbvgy%252FScreenshot%282%29.png%3Falt%3Dmedia%26token%3Dbdc5f3c9-bfb7-4b34-8c98-2e94da9520ef&#x26;width=768&#x26;dpr=4&#x26;quality=100&#x26;sign=bc75aa5c&#x26;sv=2" alt=""><figcaption></figcaption></figure>

4. Choose an **App name** and click on **Next**

   <figure><img src="https://intuitem.gitbook.io/ciso-assistant/~gitbook/image?url=https%3A%2F%2F217025809-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FUJGpmCYDFJNsz2CDasSm%252Fuploads%252FV7cXJV3E2ptwldQ0LQHK%252FScreenshot%283%29.png%3Falt%3Dmedia%26token%3Db7346c58-f0d4-4b47-b69a-290071b0bb01&#x26;width=768&#x26;dpr=4&#x26;quality=100&#x26;sign=9d34fe03&#x26;sv=2" alt=""><figcaption></figcaption></figure>

5. Add the **Single sign-on** **URL**: `<base_url>/api/accounts/saml/0/acs/` (for example with localhost: `https://localhost:8443/api/accounts/saml/0/acs/`) (see screenshot below)

6. Add the **Audience URI (SP Entity ID),** it has to be the same than **SP Entity ID** in CISO Assistant (see screenshot below)

7. Choose **Email** as the **Application username**

   <figure><img src="https://intuitem.gitbook.io/ciso-assistant/~gitbook/image?url=https%3A%2F%2F217025809-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FUJGpmCYDFJNsz2CDasSm%252Fuploads%252F4Du76vTZapbBlhb75HM5%252FScreenshot%284%29.png%3Falt%3Dmedia%26token%3De58e02af-21ab-4f17-a750-25a4cfa6200d&#x26;width=768&#x26;dpr=4&#x26;quality=100&#x26;sign=420e0425&#x26;sv=2" alt=""><figcaption></figcaption></figure>

8. Add **Attribute Statements**

   * `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname` for user's first name
   * `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname` for user's last name

   <figure><img src="https://intuitem.gitbook.io/ciso-assistant/~gitbook/image?url=https%3A%2F%2F217025809-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FUJGpmCYDFJNsz2CDasSm%252Fuploads%252F1MoE2mNEngXH5Uxh7HiL%252FScreenshot%285%29.png%3Falt%3Dmedia%26token%3D0a69edde-338c-48e1-b2c6-85ffec659616&#x26;width=768&#x26;dpr=4&#x26;quality=100&#x26;sign=524d60e5&#x26;sv=2" alt=""><figcaption></figcaption></figure>

9. Click on **Next** and fill in the **Feedback** page as you wish then click on **Finish**

   <figure><img src="https://intuitem.gitbook.io/ciso-assistant/~gitbook/image?url=https%3A%2F%2F217025809-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FUJGpmCYDFJNsz2CDasSm%252Fuploads%252FwAxCOWH5I62vwYUuYccR%252FScreenshot%286%29.png%3Falt%3Dmedia%26token%3Df045c8a4-af09-4e74-a50e-084017825488&#x26;width=768&#x26;dpr=4&#x26;quality=100&#x26;sign=69a8e40c&#x26;sv=2" alt=""><figcaption></figcaption></figure>

   <figure><img src="https://intuitem.gitbook.io/ciso-assistant/~gitbook/image?url=https%3A%2F%2F217025809-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FUJGpmCYDFJNsz2CDasSm%252Fuploads%252FfyEIIB8gv7l4plELSWYm%252FScreenshot%287%29.png%3Falt%3Dmedia%26token%3D48c83acf-5ca6-44e7-a448-957440b99354&#x26;width=768&#x26;dpr=4&#x26;quality=100&#x26;sign=60fbbadc&#x26;sv=2" alt=""><figcaption></figcaption></figure>

10. In the **Settings** box inside **SAML 2.0:**

    * Copy the **Metadata URL** and paste it into the **Metadata URL** field in CISO Assistant
    * Copy the **Issuer** url and paste it into the **IdP Entity ID** field in CISO Assistant

    <figure><img src="https://intuitem.gitbook.io/ciso-assistant/~gitbook/image?url=https%3A%2F%2F217025809-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FUJGpmCYDFJNsz2CDasSm%252Fuploads%252FawwU2wsQIx4AvIDxbew1%252FScreenshot%288%29.png%3Falt%3Dmedia%26token%3Da04a085a-32b1-484a-8c37-384c2438c8c1&#x26;width=768&#x26;dpr=4&#x26;quality=100&#x26;sign=210606cc&#x26;sv=2" alt=""><figcaption></figcaption></figure>

11. Go to the **Assignments** tab

    <figure><img src="https://intuitem.gitbook.io/ciso-assistant/~gitbook/image?url=https%3A%2F%2F217025809-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FUJGpmCYDFJNsz2CDasSm%252Fuploads%252FhrgmtuD2JoleiXxjPHbM%252FScreenshot%289%29.png%3Falt%3Dmedia%26token%3Dc9cf59b1-6e31-490b-b30f-e6670dce8a66&#x26;width=768&#x26;dpr=4&#x26;quality=100&#x26;sign=ea3af4fb&#x26;sv=2" alt=""><figcaption></figcaption></figure>

12. Click on **Assign** and choose whether you want to assign users or specific groups

    <figure><img src="https://intuitem.gitbook.io/ciso-assistant/~gitbook/image?url=https%3A%2F%2F217025809-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FUJGpmCYDFJNsz2CDasSm%252Fuploads%252F3MIUKjgpmo09QPMv0tu8%252FScreenshot%2810%29.png%3Falt%3Dmedia%26token%3D760643ee-56e0-4a86-a07b-c2e425bfea27&#x26;width=768&#x26;dpr=4&#x26;quality=100&#x26;sign=d19e5909&#x26;sv=2" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
Add a user in your application doesn't automatically create the user on CISO Assistant
{% endhint %}

You can now[ configure Clario Assistant](https://intuitem.gitbook.io/ciso-assistant/features-focus/sso) with the **3 parameters** you've retrieved.

***
