Ir para o conteúdo principal
Adaptive Planning
Steps: Configure SAML SSO Using Okta

Steps: Configure SAML SSO Using Okta

Configure Adaptive Planning to accept SAML SSO tokens from your instance of Okta. Your Okta instance is an identity provider and Adaptive Planning is a service provider. There are 2 approaches for configuring SAML SSO in Adaptive Planning with Okta:
  • Use the Okta-validated Adaptive Planning application. This is the recommended approach.
  • Create an Okta application to connect to Adaptive Planning. This approach is recommended if you’re unable to configure SAML SSO using the standard Adaptive Planning application.
Since the configuration includes steps that you must complete in Okta and Adaptive Planning, keep both applications open side-by-side on two browser tabs.

Prerequisites

  • An Okta account with administrative permissions.
  • An Adaptive Planning account with administrative permissions
  • A confirmation email from Adaptive Planning stating that you've provisioned SAML on your instance

Use the Okta Validated Adaptive Planning Application

If you configure everything correctly, Okta redirects you to Adaptive Planning. After successfully testing your setup, you can enable SAML SSO for your users in Adaptive Planning. See Enabling SAML SSO for all Users in .
  1. Sign in to Okta administration and click
    Admin
    .
  2. Click the
    Applications 
    tab.
  3. Click
    Browse App Catalog
    and search for Adaptive Insights. From the search results, select
    Adaptive Insights SAML
    .
  4. Click
    Add Integration
    and enter these details:
    1. Application label
      . The default values is Adaptive Insights. You can leave the default value as the application label.
    2. Adaptive Planning SSO URL
      . From Adaptive Planning, copy and paste the URL from
      Administration
      SAML SSO Settings
      SSO URL
      .
    3. NameID format
      . Leave the default value of
      Unspecified
      .
    4. Application Visibility
      :
      • Do not display application icon to users
        . The option is unchecked by default. You can select this option based on your business requirements.
      • Do not display application icon in the Okta Mobile App:
        The option is unchecked by default. You can select this option based on your business requirements.
  5. Click
    Done
    .

Set Okta as an Identity Provider in Adaptive Planning

  1. In the application you added within Okta in the previous section, click the
    Sign On
    tab.
  2. Click
    View SAML setup instructions.
  3. To complete configuring Adaptive Planning to accept SAML 2.0 requests from Okta, follow the instructions on the View SAML setup Instructions page.

Test the SAML SSO from Okta into Adaptive Planning

  1. In Okta, click the application you added in
    Add the Adaptive Planning Application in Okta
    .
  2. Click the
    Assignments
    tab and then select the
    People
    tab.
  3. Click
    Assign
    and select
    Assign to People
    .
  4. Assign the application to yourself and any other users who require access to it.
  5. Sign in to Adaptive Planning with your administrator credentials.
  6. Go to
    Admin > Edit User
    and select the user that you want to give access to the app.
  7. Do the same for other users who need access to the app, if any.
  8. In Okta, click
    My Apps
    .
  9. Find the icon with the name of the application you created and click it.

Create an Okta application to connect to Adaptive Planning.

  1. Sign in to Okta and click
    Admin
    .
  2. Click the
    Applications 
    tab.
  3. Click
    Create App Integration
    and select
    SAML 2.0
    . Then click
    Next
    .
  4. In
    App name
    , enter a name for the application. Example: Adaptive Planning.
  5. For the
    Do not display application icon to users
    option, the default state is unchecked. You can select the option based on your business requirements.
  6. For the
    Do not display application icon in Okta Mobile app
    option, the default state is unchecked. You can select the option based on your business requirements.
  7. Click
    Next.
  8. In
    Single sign-on URL
    , copy and paste the SSO URL from Adaptive Planning. Navigate to
    Administration
    SAML SSO Settings
    SSO URL
    .
  9. Keep the 
    Use this for Recipient URL and Destination URL
    option checked.
  10. In
    Audience URI (SP Entity ID)
    enter the same SSO URL that you copied from Adaptive Planning.
  11. Leave the
    Default Relay State
    field blank.
  12. In
    Name ID format
    , select
    Unspecified
    .
  13. In
    Application username
    , select
    Email
    .
  14. Click
    Next
    .
  15. Select
    I'm an Okta customer adding an internal app
    . It’s important that you select this setting to make sure that the application isn’t visible to users outside of your instance. For more details, see the Okta documentation.
  16. Click
    Finish
    .
  17. Under
    SAML Signing Certificates
    , click
    Actions
    for
    SHA-2
    type and select
    Download certificate
    . Save the certificate in a location you’ll remember.

Set Okta as an Identity Provider in Adaptive Planning

Once you’ve created an app inside Okta, you can set up Okta as an identity provider in Adaptive Planning.
  1. Sign in to the Adaptive Planning instance as a user with administrator permissions.
  2. From the main menu select
    Administration
    . Under
    Users and Permissions
    , click
    SAML SSO Settings
    .
  3. Provide these SAML SSO details:
    1. In
      Identity provider name
      , enter...
    2. In
      Identity provider Entity ID
      copy and paste the Identity Provider Issuer value. To find this information, click the application that you created previously, and then click the
      Sign On
      tab in Okta. Next click
      View SAML setup Instructions
      .
      You can find this information in Okta.
    3. In
      Identity provider SSO URL
      , copy and paste the
      Identity Provider Single Sign-On URL
      . To find this URL, click the
      Sign On
      tab in Okta and then click
      View SAML setup Instructions
      .
    4. (Optional) In
      Custom logout URL
      , enter a URL where to redirect users if they click
      Logout
      in the Adaptive Planning application.
    5. For
      SAML user id
      , select
      User's Adaptive Planning user name
      .
    6. For
      SAML user id location
      , select
      User ID in NameID of Subject
      .
    7. For
      SAML nameID format:
      , select the same name ID format that you configured in Okta. Example: Unspecified
    8. User id in Attribute
    9. Click
      Download Certificate
      .
    10. n the
      Enable SAML
      section, select
      Allow SAML SSO and direct Adaptive Planning login
      .
  4. Click
    Save.

Test the Setup

You can test the SAML SSO sign in from Okta into Adaptive Planning.
  1. In Okta, click the application you created.
  2. Click the
    Assignments
    tab and then
    People
    .
  3. Click
    Assign
     and select
    Assign to People
    .
  4. Assign the application to yourself and any other users who will require access to it.
  5. Sign in to Adaptive Planning with your administrative credentials.
  6. From the main menu, select
    Administration
    . User
    Users and Permissions
    , click
    Users
    . Click
    Edit
    next to the user that you want to give access to the app.
  7. In
    SAML Federation ID
    , enter the email address for the user from your Okta account.
  8. Click
    Submit
    .
  9. Do the same for other users who need access to the app, if any.
  10. In Okta, click
    My Applications
    .
  11. Find the icon with the name of the application you created and click it. If you configure everything correctly, Okta redirects you to Adaptive Planning.
After successfully testing your setup, you can enable SAML SSO for your users. See Enable SAML SSO for all Users.

SSO Into Excel Interface for Planning and OfficeConnect

After you've successfully configured and tested SAML SSO,
Excel Interface for Planning
and
OfficeConnect
users can sign in using only their usernames. They can leave the password field blank.