Steps: Configure SAML SSO Using Okta
Configure Adaptive Planning to accept SAML SSO tokens from your instance of Okta. Your Okta instance is an identity provider and Adaptive Planning is a service provider. There are 2 approaches for configuring SAML SSO in Adaptive Planning with Okta:
- Use the Okta-validated Adaptive Planning application. This is the recommended approach.
- Create an Okta application to connect to Adaptive Planning. This approach is recommended if you’re unable to configure SAML SSO using the standard Adaptive Planning application.
Since the configuration includes steps that you must complete in Okta and Adaptive Planning, keep both applications open side-by-side on two browser tabs.
Prerequisites
- An Okta account with administrative permissions.
- An Adaptive Planning account with administrative permissions
- A confirmation email from Adaptive Planning stating that you've provisioned SAML on your instance
Use the Okta Validated Adaptive Planning Application
If you configure everything correctly, Okta redirects you to Adaptive Planning. After successfully testing your setup, you can enable SAML SSO for your users in Adaptive Planning. See Enabling SAML SSO for all Users in .
- Sign in to Okta administration and clickAdmin.
- Click theApplicationstab.
- ClickBrowse App Catalogand search for Adaptive Insights. From the search results, selectAdaptive Insights SAML.
- ClickAdd Integrationand enter these details:
- Application label. The default values is Adaptive Insights. You can leave the default value as the application label.
- Adaptive Planning SSO URL. From Adaptive Planning, copy and paste the URL from .
- NameID format. Leave the default value ofUnspecified.
- Application Visibility:
- Do not display application icon to users. The option is unchecked by default. You can select this option based on your business requirements.
- Do not display application icon in the Okta Mobile App:The option is unchecked by default. You can select this option based on your business requirements.
- ClickDone.
Set Okta as an Identity Provider in Adaptive Planning
- In the application you added within Okta in the previous section, click theSign Ontab.
- ClickView SAML setup instructions.
- To complete configuring Adaptive Planning to accept SAML 2.0 requests from Okta, follow the instructions on the View SAML setup Instructions page.
Test the SAML SSO from Okta into Adaptive Planning
- In Okta, click the application you added inAdd the Adaptive Planning Application in Okta.
- Click theAssignmentstab and then select thePeopletab.
- ClickAssignand selectAssign to People.
- Assign the application to yourself and any other users who require access to it.
- Sign in to Adaptive Planning with your administrator credentials.
- Go toAdmin > Edit Userand select the user that you want to give access to the app.
- Do the same for other users who need access to the app, if any.
- In Okta, clickMy Apps.
- Find the icon with the name of the application you created and click it.
Create an Okta application to connect to Adaptive Planning.
- Sign in to Okta and clickAdmin.
- Click theApplicationstab.
- ClickCreate App Integrationand selectSAML 2.0. Then clickNext.
- InApp name, enter a name for the application. Example: Adaptive Planning.
- For theDo not display application icon to usersoption, the default state is unchecked. You can select the option based on your business requirements.
- For theDo not display application icon in Okta Mobile appoption, the default state is unchecked. You can select the option based on your business requirements.
- ClickNext.
- InSingle sign-on URL, copy and paste the SSO URL from Adaptive Planning. Navigate to.
- Keep theUse this for Recipient URL and Destination URLoption checked.
- InAudience URI (SP Entity ID)enter the same SSO URL that you copied from Adaptive Planning.
- Leave theDefault Relay Statefield blank.
- InName ID format, selectUnspecified.
- InApplication username, selectEmail.
- ClickNext.
- SelectI'm an Okta customer adding an internal app. It’s important that you select this setting to make sure that the application isn’t visible to users outside of your instance. For more details, see the Okta documentation.
- ClickFinish.
- UnderSAML Signing Certificates, clickActionsforSHA-2type and selectDownload certificate. Save the certificate in a location you’ll remember.
Set Okta as an Identity Provider in Adaptive Planning
Once you’ve created an app inside Okta, you can set up Okta as an identity provider in Adaptive Planning.
- Sign in to the Adaptive Planning instance as a user with administrator permissions.
- From the main menu selectAdministration. UnderUsers and Permissions, clickSAML SSO Settings.
- Provide these SAML SSO details:
- InIdentity provider name, enter...
- InIdentity provider Entity IDcopy and paste the Identity Provider Issuer value. To find this information, click the application that you created previously, and then click theSign Ontab in Okta. Next clickView SAML setup Instructions.You can find this information in Okta.
- InIdentity provider SSO URL, copy and paste theIdentity Provider Single Sign-On URL. To find this URL, click theSign Ontab in Okta and then clickView SAML setup Instructions.
- (Optional) InCustom logout URL, enter a URL where to redirect users if they clickLogoutin the Adaptive Planning application.
- ForSAML user id, selectUser's Adaptive Planning user name.
- ForSAML user id location, selectUser ID in NameID of Subject.
- ForSAML nameID format:, select the same name ID format that you configured in Okta. Example: Unspecified
- User id in Attribute
- ClickDownload Certificate.
- n theEnable SAMLsection, selectAllow SAML SSO and direct Adaptive Planning login.
- ClickSave.
Test the Setup
You can test the SAML SSO sign in from Okta into Adaptive Planning.
- In Okta, click the application you created.
- Click theAssignmentstab and thenPeople.
- ClickAssignand selectAssign to People.
- Assign the application to yourself and any other users who will require access to it.
- Sign in to Adaptive Planning with your administrative credentials.
- From the main menu, selectAdministration. UserUsers and Permissions, clickUsers. ClickEditnext to the user that you want to give access to the app.
- InSAML Federation ID, enter the email address for the user from your Okta account.
- ClickSubmit.
- Do the same for other users who need access to the app, if any.
- In Okta, clickMy Applications.
- Find the icon with the name of the application you created and click it. If you configure everything correctly, Okta redirects you to Adaptive Planning.
After successfully testing your setup, you can enable SAML SSO for your users. See Enable SAML SSO for all Users.
SSO Into Excel Interface for Planning and OfficeConnect
After you've successfully configured and tested SAML SSO,
Excel Interface for Planning
and OfficeConnect
users can
sign in using only their usernames. They can leave the password field blank.