Documentation Index

Fetch the complete documentation index at: https://support.fortanix.com/llms.txt

Use this file to discover all available pages before exploring further.

Fortanix DSM with Okta

Prev Next

1.0 Introduction

This article describes how to configure Security Assertion Markup Language (SAML) 2.0-based Single Sign-On (SSO) between Fortanix Data Security Manager (DSM) and Okta.

2.0 Prerequisites

Ensure the following:

  • An Okta administrator account.

  • Fortanix DSM administrator account.

3.0 Configure Okta SSO

Perform the following procedures to configure Okta as the Identity Provider (IdP) for Fortanix DSM SSO.

3.1 Create Application

Perform the following steps to create a SAML application in Okta:

  1. Log in to the Okta admin console.

  2. In the left navigation panel, navigate to Applications → Applications, and then click Create App Integration.

    Figure 1: Applications page

  3. In the Create a new app integration dialog box, select SAML 2.0 as the Sign-in method. Click NEXT.

    Figure 2: Create a new app integration

  4. In the Create SAML Integration form:

    1. General Settings tab:

      1. App name: Enter a name for the application. For example, SAML_Fortanix.

      2. App logo (Optional): Upload an application logo.

      3. App visibility: Leave the default setting unless you want to hide the application icon from users.

      4. Click NEXT.

      Figure 3: General Settings

    2. Configure SAML tab:

      • General Settings section:

        1. Single sign-on URL: Enter the Fortanix DSM SAML endpoint. For example, https://<FORTANIX_DSM_URL>/saml.

        2. Select the Use this for Recipient URL and Destination URL check box.

        3. Audience URI (SP Entity ID): Enter the Fortanix DSM service provider metadata URL. For example, https://<FORTANIX_DSM_URL>/saml/metadata.xml.

        4. Default RelayState: Leave this field blank.

        5. Name ID format: Select EmailAddress.

        6. Application username: Select Okta username.

        7. Update application username on: Select Create and update from the drop-down list.

      • Preview the SAML assertion generated from the information above section:

        1. Click Preview the SAML Assertion to review the SAML assertion generated from the configured settings.

        2. Click NEXT.

      Figure 4: Configure SAML settings

    3. Feedback tab:

      1. Optionally, provide feedback about the application configuration.

      2. Click FINISH.

      Figure 5: Feedback page

Verify that the newly created application is displayed on the Okta Applications page.

3.2 Assign Users

Perform the following steps to assign users or groups to the application:

  1. From the Applications list, select the newly created application.

  2. Click the Assignments tab.

  3. Click Assign drop down list and select one of the following options:

    1. People: Assign individual users to the application.

    2. Groups: Assign user groups to the application.

    NOTE

    Ensure that the SSO user exists in the Okta identity source before assigning the application.

    Figure 6: Assign users or groups

  4. Depending on the selected assignment option, the Assign dialog box is displayed.

    1. Username: Enter the Okta username or email address of the user to assign to the application.

    2. Click Save and Go Back.

    Figure 7: Assign dialog box

Verify that the assigned users or groups appear on the Assignments page.

Figure 8: Assigned users

3.3 Obtain the IdP Metadata

Perform the following steps to obtain the IdP metadata:

  1. In the detailed view of the application, click the Sign On tab.

  2. Under the Metadata details, click Copy to copy the Metadata URL.

    Figure 9: Metadata details

  3. Open the copied Metadata URL in a new browser tab or window. The IdP metadata XML is displayed.

    Figure 10: Identity Provider metadata XML

  4. Save the metadata XML as a file or copy its contents to use it for configuring Fortanix DSM in the next section.

4.0 Configure Okta SSO in Fortanix DSM

Perform the following steps to integrate Fortanix DSM with Okta using SAML configuration:

  1. Log in to Fortanix DSM.

  2. In the Fortanix DSM user interface (UI), navigate to SettingsAUTHENTICATION, and select SINGLE SIGN-ON as the authentication method.

  3. Click ADD SAML INTEGRATION.

    Figure 11: Select SSO

  4. On the Add SAML Integration page:

    1. Click UPLOAD A FILE to browse and upload the SAML metadata file obtained in Section 3.3: Obtain the IdP Metadata.

      Figure 12: Upload SAML metadata

    2. SSO Title: Enter a name for the SSO integration. For example, OKTA_SAML.

    3. Logo URL (Optional): Enter the URL of the logo image.

    4. Click ADD INTEGRATION.

    Figure 13: Customize SSO

Verify that the newly created SAML integration is displayed on the Authentication page under Single Sign-On.

Figure 14: Ping Identity configured

5.0 Test the Integration

Perform the following steps to verify the SSO integration:

  1. Log out of Fortanix DSM to sign in using SSO.  

  2. Open the Okta application URL in a new private or incognito browser window.

  3. Enter the SSO user credentials to log in.

    Test1_Okta.png

    Figure 15: Log in to SSO

  4. On the Fortanix DSM Login screen, click LOG IN WITH OKTA_SSO to log in using the newly added SSO configuration.

    Figure 16: Log in using Okta SSO

Verify that you are successfully redirected to the Fortanix DSM home page.

Fortanix-logo

4.6

star-ratings

As of August 2025