BarRaiser Okta Integration SSO Setup
Prerequisites
- When using SAML as the SSO mode with provisioning, you need to have a paid BarRaiser account and you will have to log in as the account owner or account admin.
- Users must have accounts in both Okta and BarRaiser (with the same email address) to use SSO
Supported Features
The Okta/BarRaiser SAML integration currently supports the following features:
- IdP-initiated SSO
- SP-initiated SSO
- The SP-initiated SSO URL is https://app.barraiser.com/login
- Just-In-Time provisioning
For more information on the listed features, visit the Okta Glossary.
Configuration Steps for BarRaiser Okta integration
Step 1: Add BarRaiser from the Okta App Catalog
- Sign in to your Okta admin dashboard
- Navigate to Applications -> Applications -> Browse App Catalog
- Search for "BarRaiser" using the search bar and click on the "BarRaiser" app
- Click "Add Integration"
Step 2: Fetch the Okta Integration info for BarRaiser app
- In Okta, under the BarRaiser app, click the "Sign On" tab
- Under Settings -> Sign on methods -> SAML 2.0 -> Copy the "Metadata URL"
Example of Metadata URL:
https://dev-xxxxxxxx.okta.com/app/xxxxxxxxxxxxxxxxx/sso/saml/metadata
Step 3: Provide the Okta Integration info to BarRaiser
Send an email to the support@barraiser.com with the metadata URL
Step 4: Assign users / groups and test the BarRaiser Okta integration
- In Okta, under the BarRaiser app, click the "Assignments" tab
- Assign any users or groups that you would like to have access to BarRaiser
- You can test the IdP-initiated flow by navigating to your end user dashboard in Okta and clicking on the newly created BarRaiser application
- You can test the SP-initiated flow by navigating to https://app.barraiser.com/login and providing your Okta-associated email address
Notes
The following SAML attributes are used by the BarRaiser Okta integration:
Name | Value |
---|---|
first_name | user.firstName |
last_name | user.lastName |
user.email |
Note: If you wish to disable the regular sign in options and only enable SAML login for your domain users, you can request to do so by sending an email at support@barraiser.com