> For the complete documentation index, see [llms.txt](https://docs.fusion.vectra.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.fusion.vectra.ai/settings/user-management/index-2/configuring-sso-with-okta.md).

# SSO with Okta

Vectra configuration Vectra’s SAML and your Identity Provider settings need to be configured in parallel. To start, log in to your Vectra account as an administrator. Navigate to Settings

### Vectra configuration <a href="#vectra-configuration" id="vectra-configuration"></a>

Vectra’s SAML and your Identity Provider settings need to be configured in parallel. To start, log in to your Vectra account as an administrator.

1. Navigate to **Settings > SSO** and enable **SAML Single Sign-on**:
2. Copy the **Assertion consumer service (ACS) URL** in the **SAML Single Sign-On Settings** page that appears.. It will be needed as input into Auth0 later.

### Okta Walkthrough <a href="#okta-walkthrough" id="okta-walkthrough"></a>

1. Navigate to **Applications**. Click **Create App Integration** and choose **SAML 2.0**.

![](https://1075194167-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F7upncbzIm3grJePXaOO9%2Fuploads%2Fgit-blob-412b19974b92479d608b1c32f30d39e3e4ed71bd%2F08e26ad6a8a0d2a6ac34720ab8a9e205fcaf9ea6e263f7f80f2c604125284ffa.png?alt=media) ![](https://1075194167-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F7upncbzIm3grJePXaOO9%2Fuploads%2Fgit-blob-5e32d804e5ab634494b11b1ae3259ab2b3c65d07%2F3d4159054609e4ff0e586b65c6a16ea3e7c50f2cb1eaf09757e574ae814d4a66.png?alt=media)

2. Provide the application name and logo. In the **General Settings** section, enter the following values into the corresponding fields:

   1. **App name**: Vectra
   2. **App logo** (optional):

   ![Vectra logo (right-click and save as to use)](https://1075194167-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F7upncbzIm3grJePXaOO9%2Fuploads%2Fgit-blob-35262f0e0dc9eed0c19a1ab9a25a0171f91179f2%2Fb098628a6855e78546087be1ebc05b0cf247b64f8b503eb21164a801b8d2a04d.png?alt=media) Vectra logo (right-click and save as to use)

![](https://1075194167-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F7upncbzIm3grJePXaOO9%2Fuploads%2Fgit-blob-f5303a8bcb2c09b8d974835fef543f08a821e0f8%2F51a167cee0c38165fefeaeafa35da4b0efcbcc3e971ed15dd670e9cd6610ccc2.png?alt=media)

3. Lookup/Copy SAML Integration values. You will need to reference the following information from the Vectra portal: Assertion Consumer Service, Entity ID, and account shortname. These values are found in the **Vectra Service Provider Settings** section in the **Essentials** area in **SAML Single Sign-On Settings**:
   * ![](https://1075194167-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F7upncbzIm3grJePXaOO9%2Fuploads%2Fgit-blob-575b94b5b21d00300c5f7e504c66c3670ede0a77%2F3e44222e7d1ddc65d863e7437df47ab47891a8c63114d2411cb797b3987990e2.png?alt=media)
4. In Okta, configure the General SAML Settings.
   1. **Single sign on URL**: Constructed using your account shortname. This URL will be the following: [https://fusion.netography.com/sso/\<shortname](https://fusion.netography.com/sso/%3Cshortname). Replace `<shortname>`with your company's identifier. This can be found in the upper right (just under your name, in red) of the Vectra portal.
   2. **Use this for Recipient URL and Destination URL**: uncheck
   3. **Allow this app to request other SSO URLs**: check
   4. **Requestable SSO URLs**: Paste the *Assertion consumer service URL* found in the Vectra portal
   5. **Recipient UR**L: Paste the same *Assertion consumer service URL* as above
   6. **Destination URL**: Paste the same *Assertion consumer service URL* as above
   7. **Audience URI (SP Entity ID)**: Paste the *Entity ID* found in the Vectra portal

![](https://1075194167-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F7upncbzIm3grJePXaOO9%2Fuploads%2Fgit-blob-9314a1df516cc097818c89c879f2576d78295f68%2F8d3f974c90e98d5dcb0af468389882ce5a6abcde88a08bda864e3577564d9fdb.png?alt=media)

5. Configure SAML attributes.
   1. Fill the **Attribute Statements** section by completing the fields as indicated below:

![](https://1075194167-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F7upncbzIm3grJePXaOO9%2Fuploads%2Fgit-blob-e49e66f326662bd9b4dd13f7791c05ba45d51ebe%2Fa25e17280f83d5d791ac46409fbb5ea54da910aa0c568ce98b4e92f91d953290.png?alt=media)

2. Fill the **Group Attribute Statements** section by completed the fields as indicated below:

![](https://1075194167-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F7upncbzIm3grJePXaOO9%2Fuploads%2Fgit-blob-5dee45f24f3d5c18508ed28cbe5707bdfc278265%2F75b39367439ecb6a7003440b521004c8d7d56c0ce039bf1a974498cde06d79fc.png?alt=media)

!!! Note\
You will need to assign users to these groups.

6. Configure the application type by completing the fields as indicated below and click **Finish**.

![](https://1075194167-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F7upncbzIm3grJePXaOO9%2Fuploads%2Fgit-blob-8470c1f8998c82dc64373f7609026e463dc0b7f5%2Fcd82a6b43847ebaef9dd606edb171a32cf760f61e7deb3ea849580235a9188c1.png?alt=media)

7. Download the metadata file. You'll need to upload this to Vectra when you configure Okta as the identity provider.

![](https://1075194167-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F7upncbzIm3grJePXaOO9%2Fuploads%2Fgit-blob-2d44627485d1aaea934d3ea51dd14ee89ec2dcc4%2F2dd5428c61e51a3adae382ac3b8455dab2f9cfa08610c6113260107217225417.png?alt=media)

### Vectra post-configuration <a href="#vectra-post-configuration" id="vectra-post-configuration"></a>

1. Return to the Vectra portal, and upload the metadata file to Vectra in the Metadata section in the **Provider** screen in the **SAML Single Sign-On Settings page**

![](https://1075194167-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F7upncbzIm3grJePXaOO9%2Fuploads%2Fgit-blob-2cecf83905f46b63c2dfd406208252b911cd9e1b%2F116412f45cf34fb84c4cb56e6c30545102b54303c55b322acbe678b7b83cd6f2.png?alt=media)

2. Click Next
3. Now configure the **User attribute mappers** to match the mapper values configured in Auth0 above:

![](https://1075194167-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F7upncbzIm3grJePXaOO9%2Fuploads%2Fgit-blob-88c468dd59af34afeb9dca7c0d0599c2c12333cf%2Fdad8238692ba771532ecdd3ee31c4d3bf9547e849e76f33e9561680c5fa65b7a.png?alt=media)

4. Click Next.
5. Next configure the Default user role and role mappers:
   1. Default user role: This is the role an IDM-authenticated user will default to if the role mappings are not found in the SAML exchange. For security purposes, we recommend setting this value to "readonly", but you may want to set this to "admin" as you are testing your configuration.
   2. Admin role mappers: Configure these according to the screenshot below:

![](https://1075194167-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F7upncbzIm3grJePXaOO9%2Fuploads%2Fgit-blob-862430f3cb97add3ec77fe58f31f2e1a5912b3fd%2Fc8806252cccdad06d64bc7315e8e5314d2a1d47953dd5064e28308bc5812927b.png?alt=media)

6. Click the **Save** button.

Done! Now your users can log in directly via your identity provider using a new account-specific login URL. The new SSO Login URL can now be found under the **Essentials** settings in the **SAML Single Sign-On Settings** page.

![](https://1075194167-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F7upncbzIm3grJePXaOO9%2Fuploads%2Fgit-blob-d44d92c9b923daa3195a579ebaa96de3801167ff%2F11dfdf8bed4da066db937d21220561ca20f72c0e467dc23260019ee04b76916e.png?alt=media)

{% hint style="warning" %}
**🚧The default login will still work for your account administrator, which is not bound to your IDM.**
{% endhint %}

{% hint style="danger" %}
**❗️Note: The corresponding internal account in the Vectra Portal needs to be deleted first, as configuring the Okta SSO setup will show an error box will appear when a user logs in Okta if they already had an internal portal account with the same name.**
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.fusion.vectra.ai/settings/user-management/index-2/configuring-sso-with-okta.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
