You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: pages/account/customer/ovhcloud-account-connect-saml-okta/guide.en-gb.md
+27-27Lines changed: 27 additions & 27 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,40 +1,40 @@
1
1
---
2
-
title: Enabling OKTA SSO connections with your OVHcloud account
2
+
title: Enabling Okta SSO connections with your OVHcloud account
3
3
slug: connect-saml-sso-okta
4
-
excerpt: "Learn how to associate your OKTA service with your OVHcloud account via SAML 2.0"
4
+
excerpt: "Learn how to associate your Okta service with your OVHcloud account via SAML 2.0"
5
5
section: 'Advanced use'
6
6
order: 02
7
-
updated: 2023-03-30
7
+
updated: 2023-04-18
8
8
---
9
9
10
-
**Last updated 30th March 2023**
10
+
**Last updated 18th April 2023**
11
11
12
12
## Objective
13
13
14
-
You can use unique **single sign-on** (SSO) to sign in to your OVHcloud account. To enable these connections, your account and OKTA accounts have to be configured using Security Assertion Markup Language (SAML) authentication.
14
+
You can use unique **single sign-on** (SSO) to sign in to your OVHcloud account. To enable these connections, your account and Okta accounts have to be configured using Security Assertion Markup Language (SAML) authentication.
15
15
16
-
**This guide explains how to associate your OVHcloud account with an external OKTA service.**
16
+
**This guide explains how to associate your OVHcloud account with an external Okta service.**
17
17
18
18
## Requirements
19
19
20
-
- Being an administrator of a OKTA service
20
+
- Being an administrator of a Okta service
21
21
- An [OVHcloud account](https://docs.ovh.com/gb/en/customer/create-ovhcloud-account/)
22
22
- Access to the [OVHcloud Control Panel](https://www.ovh.com/auth/?action=gotomanager&from=https://www.ovh.co.uk/&ovhSubsidiary=GB)
23
23
24
24
## Instructions
25
25
26
26
> [!primary]
27
27
>
28
-
> In order for a service provider (i.e. your OVHcloud account) to establish an SSO connection with an identity provider (i.e. your OKTA service), the key is to establish a mutual trust relationship by registering the SSO connection in both services.
28
+
> In order for a service provider (i.e. your OVHcloud account) to establish an SSO connection with an identity provider (i.e. your Okta service), the key is to establish a mutual trust relationship by registering the SSO connection in both services.
29
29
>
30
30
31
-
### Registering OVHcloud into OKTA
31
+
### Registering OVHcloud into Okta
32
32
33
-
Your OKTA acts as an identity provider. Requests to authenticate your OVHcloud account will only be accepted if you have first declared it as a trusted third party.
33
+
Your Okta service acts as an identity provider. Requests to authenticate your OVHcloud account will only be accepted if you have first declared it as a trusted third party.
34
34
35
35
This means that it must be added as `Applications`.
36
36
37
-
Log in to the OKTA administration interface with your administrator account.
37
+
Log in to the Okta administration interface with your administrator account.
38
38
39
39
Go to `Applications`{.action} then again `Applications`{.action}.
40
40
@@ -73,15 +73,15 @@ Then open the application and go to the "Assignments" tab and assign users or gr
Your OKTA service now trusts OVHcloud as a service provider. The next step is to ensure that the OVHcloud account trusts your OKTA as an identity provider.
80
+
Your Okta service now trusts OVHcloud as a service provider. The next step is to ensure that the OVHcloud account trusts your Okta as an identity provider.
81
81
82
-
### Registering OKTA into the OVHcloud account and configuring the connection
82
+
### Registering Okta into the OVHcloud account and configuring the connection
83
83
84
-
To add OKTA as a trusted identity provider, you need to provide the identity provider metadata in the [OVHcloud Control Panel](https://www.ovh.com/auth/?action=gotomanager&from=https://www.ovh.co.uk/&ovhSubsidiary=GB).
84
+
To add Okta as a trusted identity provider, you need to provide the identity provider metadata in the [OVHcloud Control Panel](https://www.ovh.com/auth/?action=gotomanager&from=https://www.ovh.co.uk/&ovhSubsidiary=GB).
85
85
86
86
Once logged in, click your profile at the top right.
87
87
@@ -99,11 +99,11 @@ Click the `SSO connection`{.action} button.
Your OKTA is now considered a trusted identity provider. However, you still need to add groups to your OVHcloud account.
118
+
Your Okta service is now considered a trusted identity provider. However, you still need to add groups to your OVHcloud account.
119
119
120
120
> [!warning]
121
121
> If you try to connect via SSO at this point, you will probably receive a `Not in valid groups` error message.
122
122
>
123
123
> That is because your OVHcloud account checks whether the authenticating user belongs to an existing group on the account.
124
124
>
125
125
126
-
You must then assign **roles** to OKTA user groups at OVHcloud. Otherwise, your OVHcloud account does not know what the user is allowed to do and, by default, no rights are assigned.
126
+
You must then assign **roles** to Okta user groups at OVHcloud. Otherwise, your OVHcloud account does not know what the user is allowed to do and, by default, no rights are assigned.
127
127
128
128
From the OVHcloud Control Panel, add a group by clicking the `Declare a group`{.action} button and filling in the fields:
129
129
130
-
-**Group name**: Group name within OKTA
130
+
-**Group name**: Group name within Okta
131
131
-**Role**: Level of rights granted to this group
132
132
133
-
{.thumbnail}
133
+
{.thumbnail}
134
134
135
-
{.thumbnail}
135
+
{.thumbnail}
136
136
137
137
You can then verify that the group is added to your OVHcloud account in the "Groups" section:
138
138
139
-
{.thumbnail}
139
+
{.thumbnail}
140
140
141
141
When you later log in with a user from the **Intern** group, your OVHcloud account will recognise that the user has the role "UNPRIVILEGED" specified by his group.
142
142
143
-
You will then be able to log out of your account and log back in with your OKTA as an identity provider.
143
+
You will then be able to log out of your account and log back in with your Okta as an identity provider.
144
144
145
145
### Connecting via SSO
146
146
147
147
On [the OVHcloud login page](https://www.ovh.com/auth/?action=gotomanager&from=https://www.ovh.co.uk/&ovhSubsidiary=GB), enter your [login](https://docs.ovh.com/gb/en/customer/create-ovhcloud-account/#what-is-my-nic-handle) followed by **/idp** without a password and click the `Login`{.action} button.
148
148
149
149
{.thumbnail}
150
150
151
-
You are then redirected to your OKTA login page. Enter the login and password for a user of your OKTA, then click the `Sign in`{.action} button.
151
+
You are then redirected to your Okta login page. Enter the login and password for a user of your Okta, then click the `Sign in`{.action} button.
0 commit comments