Okta Single Sign-On
Okta·AE_Okta_SSO_ConfigurationGuide
Overview
The Okta SSO connector configures AlertEnterprise Guardian to federate authentication to Okta via SAML 2.0. AE Guardian acts as the SAML Service Provider (SP); Okta acts as the Identity Provider (IdP) with its own identity store (users + groups created in Okta or synced from upstream sources via Okta AD Agent / SCIM).
For new-hire identity sync — distinct from SSO authentication — pair this connector with the full okta connector (which uses Okta's REST API for cardholder/identity provisioning + reconciliation) or with sail-point-rest when SailPoint owns the identity lifecycle.
Setup pattern mirrors adfs-sso: AE provides metadata XML; Okta admin creates a new SAML 2.0 Application in the Okta admin console, imports the AE metadata, configures attribute statements (email → Name ID, optional tenant claim). Users must be assigned to the Okta application AND exist in AE Guardian's database before they can log in.
Architecture
Composed from this connector's actors + edges. Trust zones are color-coded; trust crossings render as thicker lines.
Authentication
1 method supported
AE Guardian acts as the SAML Service Provider; Okta acts as the Identity Provider. AE provides metadata XML; the Okta admin creates a SAML 2.0 application in Okta admin console, imports AE metadata, and assigns users / groups to the application. On authentication, Okta posts a SAML response to AE's ACS endpoint with the user's email as Name ID.
Prerequisites
Everything that must be in place for this connector to work, with the owner who's responsible.
Okta tenant with SAML 2.0 application configured for AE
customerAn operational Okta tenant. The Okta admin creates a SAML 2.0 application, imports AE-provided metadata XML, and assigns users/groups to it.
Known limitations
Documented constraints to set customer expectations before deployment.
Authentication only — no provisioning or reconciliation
informationalThis connector configures SSO. For identity data sync, pair with the okta connector.
IAM specifics
- OIDC
- yes
- SAML
- yes
- SCIM
- yes
- JIT provisioning
- configurable
- Group sync mode
- not-supported
- Source of record
- No
MFA enforced by Okta via Sign-On Policies. AE Guardian inherits MFA enforcement from Okta — no AE-side configuration required.
Email-formatted Name ID + optional tenant claim. Customers can extend the attribute statement in the Okta application configuration.
- src/connectors/okta-sso/source.pdf — Full configuration guide — 17 pages, updated 2025-08-22