Configure SAML 2.0 SSO
This document walks you through the process of setting up SAML 2.0 Single-Sign On (SSO). This process uses Okta as the Identity Provider (IdP), but other IdPs are supported, such as Active Directory and Google Ping.
SAML 2.0 SSO Workflow
Follow these high level steps to configure SAML 2.0 SSO with Okta.
Prerequisites
Create an SSO Provider Role Mapping
To create an SSO provider role mapping from the
GUI:
Create a New App Integration in Okta
Follow these steps to set up Juniper Apstra as an app integration to work with Okta. Configure SAML 2.0 and SSO parameters for the desired SSO behavior.
To create an app integration in Okta from the GUI:
Assign Your New Okta Integration to Users
Assign users to your Juniper Apstra app integration
with Okta.
Assign Your New Okta Integration to User Groups
Assign groups of users to the Juniper Apstra app
integration with Okta.