> ## Documentation Index
> Fetch the complete documentation index at: https://airmdr-docs-crowdstrike-skills-catalog.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Okta SSO Set-up and Configuration

> AirMDR supports Okta single sign-on to authenticate users for access to the AirMDR application.

### Overview

Okta Single Sign-On (SSO) can authenticate access to various applications by integrating it with your application. Here’s a step-by-step guide to setting up Okta SSO authentication.

AirMDR supports the Okta single sign-on (SSO) method for authenticating users and granting them access to the user interface.

### Pre-requisites

<Tip>
  Prior to set-up, Super Admin must have the Okta Developer Account with Admin access.
</Tip>

1. Login into the **Okta Admin Console**.
2. Enter your admin username and password, then click **Sign In**.
3. Navigate to **Applications** → **Applications** and click **Create App Integration**. A pop-up modal will show up.

   <img src="https://mintcdn.com/airmdr-docs-crowdstrike-skills-catalog/Od8RYZmVUWfFxYMn/images/SSO-14.png?fit=max&auto=format&n=Od8RYZmVUWfFxYMn&q=85&s=6a56a05b526f8b9e9daaccaecafd15f6" alt="SSO 14 Pn" width="2604" height="1176" data-path="images/SSO-14.png" />
4. In the pop-up modal, select the radio button next to SAML 2.0, and click **Next**.

   <img src="https://mintcdn.com/airmdr-docs-crowdstrike-skills-catalog/Od8RYZmVUWfFxYMn/images/SSO-15.png?fit=max&auto=format&n=Od8RYZmVUWfFxYMn&q=85&s=e43dfeca39f5f44fc07fefea9b21cb74" alt="SSO 15 Pn" width="1852" height="1022" data-path="images/SSO-15.png" />
5. **Create SAML Integration**
   * In the General Settings tab, provide the following details

     * **App Name**: Enter `AirMDR`
     * **App logo:** (optional) - Upload the AirMDR logo for easier identification.
     * Click **Next.**

     <img src="https://mintcdn.com/airmdr-docs-crowdstrike-skills-catalog/Od8RYZmVUWfFxYMn/images/SSO-16.png?fit=max&auto=format&n=Od8RYZmVUWfFxYMn&q=85&s=4e0f24a3e61fb1623b52691f5255ce57" alt="SSO 16 Pn" width="1470" height="1138" data-path="images/SSO-16.png" />
   * In the Configure SAML Settings tab, provide the following details
     * **Single sign-on URL**: [https://app.airmdr.com/airmdrapi/sso/acs](https://app.airmdr.com/airmdrapi/sso/acs)

       <Note>
         Make sure the check-box is selected for "**Use this for Recipient URL and Destination URL**"
       </Note>
     * **Audience URI (SP Entity ID)**: [https://app.airmdr.com/airmdrapi](https://app.airmdr.com/airmdrapi)
     * **Default Relay State**: [https://app.airmdr.com](https://app.airmdr.com/airmdrapi)

       <img src="https://mintcdn.com/airmdr-docs-crowdstrike-skills-catalog/Od8RYZmVUWfFxYMn/images/SSO-20.png?fit=max&auto=format&n=Od8RYZmVUWfFxYMn&q=85&s=d4848e9079b858a88de4b21545e52fde" alt="SSO 20 Pn" width="1468" height="1460" data-path="images/SSO-20.png" />
     * Add a SAML attribute with name `email` and value `user.email`

       <img src="https://mintcdn.com/airmdr-docs-crowdstrike-skills-catalog/Od8RYZmVUWfFxYMn/images/SSO-17.png?fit=max&auto=format&n=Od8RYZmVUWfFxYMn&q=85&s=d37c3e765b411d993b8a0f732673cfb2" alt="SSO 17 Pn" width="1386" height="454" data-path="images/SSO-17.png" />
     * In the B section, preview the SAML assertion generated with the information provided (optional)
     * Click **Next.**

       <img src="https://mintcdn.com/airmdr-docs-crowdstrike-skills-catalog/Od8RYZmVUWfFxYMn/images/SSO-21.png?fit=max&auto=format&n=Od8RYZmVUWfFxYMn&q=85&s=87bae927f53b36c24318ac273a18e8b3" alt="SSO 21 Pn" width="1470" height="668" data-path="images/SSO-21.png" />
   * In the Feedback tab, provide the necessary details for Okta Support to understand how you configured this application (Optional).
   * Click **Finish**.

     <img src="https://mintcdn.com/airmdr-docs-crowdstrike-skills-catalog/Od8RYZmVUWfFxYMn/images/SSO-22.png?fit=max&auto=format&n=Od8RYZmVUWfFxYMn&q=85&s=a86839596d4d65ca24514cf290ce6657" alt="SSO 22 Pn" width="1776" height="1582" data-path="images/SSO-22.png" />
6. On Finishing, you will be redirected to application, select the **Sign on** tab.

   <Tip>
     To view the configuration parameters at any time, navigate to **Applications** → **Applications**, click on the **ACTIVE** status tab, and then select the application you want to view the details for and select the **Sign On** tab.
   </Tip>

   <img src="https://mintcdn.com/airmdr-docs-crowdstrike-skills-catalog/Od8RYZmVUWfFxYMn/images/SSO-36.png?fit=max&auto=format&n=Od8RYZmVUWfFxYMn&q=85&s=365b2a79339d6566d7601f88dc06a0de" alt="SSO 36 Pn" width="2030" height="1114" data-path="images/SSO-36.png" />
7. Click on the **More details** drop-down.

   <img src="https://mintcdn.com/airmdr-docs-crowdstrike-skills-catalog/Od8RYZmVUWfFxYMn/images/SSO-23.png?fit=max&auto=format&n=Od8RYZmVUWfFxYMn&q=85&s=1322dcbfa1708f6919d9f00ce1e03ac9" alt="SSO 23 Pn" width="2150" height="1332" data-path="images/SSO-23.png" />
8. Securely Copy, Download the required Configuration Parameters
   * <Icon icon="angles-right" /> Sign on URL
   * <Icon icon="angles-right" /> Issuer ID
   * <Icon icon="angles-right" /> Download the Signing Certificate

     <img src="https://mintcdn.com/airmdr-docs-crowdstrike-skills-catalog/Od8RYZmVUWfFxYMn/images/SSO-24.png?fit=max&auto=format&n=Od8RYZmVUWfFxYMn&q=85&s=945f1ef95d486bbab88f0c4576669545" alt="SSO 24 Pn" width="1098" height="766" data-path="images/SSO-24.png" />
9. Go to the **Assignments** tab of the application (For example: AirMDR) you just created.
10. Click **Assign** → **Assign to People** or **Assign to Groups.**

    <img src="https://mintcdn.com/airmdr-docs-crowdstrike-skills-catalog/Od8RYZmVUWfFxYMn/images/SSO-35.png?fit=max&auto=format&n=Od8RYZmVUWfFxYMn&q=85&s=7a4dffe1cf87980470982efe2e4eb6c0" alt="SSO 35 Pn" width="1794" height="704" data-path="images/SSO-35.png" />
11. Select the appropriate users/groups, then click **Assign** and **Done.**

### Set up and configure Okta SSO in AirMDR UI

1. Login into the [AirMDR](https://app.airmdr.com/) application.
2. On the bottom left, click on the **User** and select **Go to Admin dashboard**.

   <img src="https://mintcdn.com/airmdr-docs-crowdstrike-skills-catalog/Od8RYZmVUWfFxYMn/images/SSO-25.png?fit=max&auto=format&n=Od8RYZmVUWfFxYMn&q=85&s=cb057f83b683777fc4ca45474ebcbe3f" alt="SSO 25 Pn" width="706" height="488" data-path="images/SSO-25.png" />
3. Click on the midline ellipsis option (<Icon icon="ellipsis-vertical" color="#020203" />three dots) option below the ACTIONS column, and click **Edit**.

   <img src="https://mintcdn.com/airmdr-docs-crowdstrike-skills-catalog/Od8RYZmVUWfFxYMn/images/SSO-34.png?fit=max&auto=format&n=Od8RYZmVUWfFxYMn&q=85&s=c875180cc453db351c0f1cbafc7f44fe" alt="SSO 34 Pn" width="2792" height="214" data-path="images/SSO-34.png" />
4. Select the **SSO SETTINGS** tab.
5. In the **Setup SSO** dropdown list, select **Yes, New Config**.

   <Tip>
     If the parent organization has an existing SSO configuration and the child organization intends to reuse it, select the **Inherit from Parent** option from the **Setup SSO** drop-down menu.
   </Tip>

   <img src="https://mintcdn.com/airmdr-docs-crowdstrike-skills-catalog/Od8RYZmVUWfFxYMn/images/SSO-28.png?fit=max&auto=format&n=Od8RYZmVUWfFxYMn&q=85&s=df6821274af3757a84b22955b8730730" alt="SSO 28 Pn" width="1014" height="666" data-path="images/SSO-28.png" />
6. Fill in the SAML Protocol Configuration Parameters details generated from Okta.

   <Check>
     In the **Identity Provider (IdP) to use** dropdown list select **Custom.**
   </Check>

   <Check>
     Use **Upload** option to include the **Identity Provider Certificate** **(Signing Certificate)** downloaded from Okta.
   </Check>

   <Note>
     The downloaded Okta certificate has a default file extension of `.cert`.\
     Users must ensure the file extension is changed to `.crt` before uploading.

     <u>For example</u>: `Okta.crt`
   </Note>

   <Check>
     In the **Provide your SSO endpoint**, enter the **Identity Provider Login URL (Sign On URL)** copied from Okta.
   </Check>

   <img src="https://mintcdn.com/airmdr-docs-crowdstrike-skills-catalog/Od8RYZmVUWfFxYMn/images/SSO-29.png?fit=max&auto=format&n=Od8RYZmVUWfFxYMn&q=85&s=e84b3bebd1c9148af8e3c10470d10cf9" alt="SSO 29 Pn" width="1002" height="1266" data-path="images/SSO-29.png" />

   <Check>
     In the **Use Issuer ID** dropdown, select **Yes** and provide **Issuer** **ID** copied from Okta.
   </Check>
7. Click **Submit**. (SSO Okta SSO Authentication is successfully created for your account).

   <img src="https://mintcdn.com/airmdr-docs-crowdstrike-skills-catalog/Od8RYZmVUWfFxYMn/images/SSO-31.png?fit=max&auto=format&n=Od8RYZmVUWfFxYMn&q=85&s=a4302b09a1785e2fa38250c83e252637" alt="SSO 31 Pn" width="984" height="900" data-path="images/SSO-31.png" />

### To Evaluate Integration

1. Navigate to the AirMDR Login page, enter your **Email,** and click **Proceed to Login**.

   <Info>
     As your SSO Okta SSO Authentication is successfully created for your account.
   </Info>

   <img src="https://mintcdn.com/airmdr-docs-crowdstrike-skills-catalog/Od8RYZmVUWfFxYMn/images/SSO-32.png?fit=max&auto=format&n=Od8RYZmVUWfFxYMn&q=85&s=c839c1a4a40b510366a2a4b41342961c" alt="SSO 32 Pn" width="670" height="438" data-path="images/SSO-32.png" />
2. The page will be redirected to the Okta URL provided as the **SSO Endpoint** in the **SSO SETTINGS**.
3. Enter the credentials created in the **Okta** → **User Management**

<Frame>
  <Icon icon="rocket-launch" />  Hurray! You are Logged in Successfully
</Frame>
