Skip to content

Commit c056153

Browse files
gbarideausebferrer
andcommitted
Apply suggestions from code review
Co-authored-by: Seb Ferrer <[email protected]>
1 parent cc4f430 commit c056153

File tree

2 files changed

+27
-27
lines changed

2 files changed

+27
-27
lines changed

pages/account/customer/ovhcloud-account-connect-saml-okta/guide.en-gb.md

Lines changed: 27 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -1,40 +1,40 @@
11
---
2-
title: Enabling OKTA SSO connections with your OVHcloud account
2+
title: Enabling Okta SSO connections with your OVHcloud account
33
slug: connect-saml-sso-okta
4-
excerpt: "Learn how to associate your OKTA service with your OVHcloud account via SAML 2.0"
4+
excerpt: "Learn how to associate your Okta service with your OVHcloud account via SAML 2.0"
55
section: 'Advanced use'
66
order: 02
7-
updated: 2023-03-30
7+
updated: 2023-04-18
88
---
99

10-
**Last updated 30th March 2023**
10+
**Last updated 18th April 2023**
1111

1212
## Objective
1313

14-
You can use unique **single sign-on** (SSO) to sign in to your OVHcloud account. To enable these connections, your account and OKTA accounts have to be configured using Security Assertion Markup Language (SAML) authentication.
14+
You can use unique **single sign-on** (SSO) to sign in to your OVHcloud account. To enable these connections, your account and Okta accounts have to be configured using Security Assertion Markup Language (SAML) authentication.
1515

16-
**This guide explains how to associate your OVHcloud account with an external OKTA service.**
16+
**This guide explains how to associate your OVHcloud account with an external Okta service.**
1717

1818
## Requirements
1919

20-
- Being an administrator of a OKTA service
20+
- Being an administrator of a Okta service
2121
- An [OVHcloud account](https://docs.ovh.com/gb/en/customer/create-ovhcloud-account/)
2222
- Access to the [OVHcloud Control Panel](https://www.ovh.com/auth/?action=gotomanager&from=https://www.ovh.co.uk/&ovhSubsidiary=GB)
2323

2424
## Instructions
2525

2626
> [!primary]
2727
>
28-
> In order for a service provider (i.e. your OVHcloud account) to establish an SSO connection with an identity provider (i.e. your OKTA service), the key is to establish a mutual trust relationship by registering the SSO connection in both services.
28+
> In order for a service provider (i.e. your OVHcloud account) to establish an SSO connection with an identity provider (i.e. your Okta service), the key is to establish a mutual trust relationship by registering the SSO connection in both services.
2929
>
3030
31-
### Registering OVHcloud into OKTA
31+
### Registering OVHcloud into Okta
3232

33-
Your OKTA acts as an identity provider. Requests to authenticate your OVHcloud account will only be accepted if you have first declared it as a trusted third party.
33+
Your Okta service acts as an identity provider. Requests to authenticate your OVHcloud account will only be accepted if you have first declared it as a trusted third party.
3434

3535
This means that it must be added as `Applications`.
3636

37-
Log in to the OKTA administration interface with your administrator account.
37+
Log in to the Okta administration interface with your administrator account.
3838

3939
Go to `Applications`{.action} then again `Applications`{.action}.
4040

@@ -73,15 +73,15 @@ Then open the application and go to the "Assignments" tab and assign users or gr
7373

7474
![Assign users](images/OKTA_add_user.png){.thumbnail}
7575

76-
Before going to the next section, go to the "Sign On" tab, and access to the **Metadata URL** and save the XML provided
76+
Before going to the next section, go to the "Sign On" tab, and access to the **Metadata URL** and save the provided XML file
7777

7878
![Retrieve metadata](images/OKTA_retrieve_metadata.png){.thumbnail}
7979

80-
Your OKTA service now trusts OVHcloud as a service provider. The next step is to ensure that the OVHcloud account trusts your OKTA as an identity provider.
80+
Your Okta service now trusts OVHcloud as a service provider. The next step is to ensure that the OVHcloud account trusts your Okta as an identity provider.
8181

82-
### Registering OKTA into the OVHcloud account and configuring the connection
82+
### Registering Okta into the OVHcloud account and configuring the connection
8383

84-
To add OKTA as a trusted identity provider, you need to provide the identity provider metadata in the [OVHcloud Control Panel](https://www.ovh.com/auth/?action=gotomanager&from=https://www.ovh.co.uk/&ovhSubsidiary=GB).
84+
To add Okta as a trusted identity provider, you need to provide the identity provider metadata in the [OVHcloud Control Panel](https://www.ovh.com/auth/?action=gotomanager&from=https://www.ovh.co.uk/&ovhSubsidiary=GB).
8585

8686
Once logged in, click your profile at the top right.
8787

@@ -99,11 +99,11 @@ Click the `SSO connection`{.action} button.
9999

100100
![OVHcloud SSO connection step 1](images/ovhcloud_user_management_connect_sso_1.png){.thumbnail}
101101

102-
Fill in the XML metadata of your OKTA service. Enter `groups` as the "Group Attribute Name". Click `Confirm`{.action}.
102+
Fill in the XML metadata of your Okta service. Enter `groups` as the "Group Attribute Name". Click `Confirm`{.action}.
103103

104104
![OVHcloud SSO connection step 2](images/ovhcloud_add_federation.png){.thumbnail}
105105

106-
Now you need to retrieve your OKTA as identity provider, as well as default groups.
106+
Now you need to retrieve your Okta as identity provider, as well as default groups.
107107

108108
![OVHcloud SSO connection step 3](images/ovhcloud_add_federation_success.png){.thumbnail}
109109

@@ -115,44 +115,44 @@ The `...`{.action} button allows you to update or delete the SSO, and view its d
115115

116116
![OVHcloud SSO connection step 5](images/ovhcloud_user_management_connect_sso_5.png){.thumbnail}
117117

118-
Your OKTA is now considered a trusted identity provider. However, you still need to add groups to your OVHcloud account.
118+
Your Okta service is now considered a trusted identity provider. However, you still need to add groups to your OVHcloud account.
119119

120120
> [!warning]
121121
> If you try to connect via SSO at this point, you will probably receive a `Not in valid groups` error message.
122122
>
123123
> That is because your OVHcloud account checks whether the authenticating user belongs to an existing group on the account.
124124
>
125125
126-
You must then assign **roles** to OKTA user groups at OVHcloud. Otherwise, your OVHcloud account does not know what the user is allowed to do and, by default, no rights are assigned.
126+
You must then assign **roles** to Okta user groups at OVHcloud. Otherwise, your OVHcloud account does not know what the user is allowed to do and, by default, no rights are assigned.
127127

128128
From the OVHcloud Control Panel, add a group by clicking the `Declare a group`{.action} button and filling in the fields:
129129

130-
- **Group name**: Group name within OKTA
130+
- **Group name**: Group name within Okta
131131
- **Role**: Level of rights granted to this group
132132

133-
![OKTA User Management Groups](images/ovhcloud_user_management_groups_1.png){.thumbnail}
133+
![Okta User Management Groups](images/ovhcloud_user_management_groups_1.png){.thumbnail}
134134

135-
![OKTA User Management Groups](images/ovhcloud_user_management_groups_2.png){.thumbnail}
135+
![Okta User Management Groups](images/ovhcloud_user_management_groups_2.png){.thumbnail}
136136

137137
You can then verify that the group is added to your OVHcloud account in the "Groups" section:
138138

139-
![OKTA User Management Groups](images/ovhcloud_user_management_groups_3.png){.thumbnail}
139+
![Okta User Management Groups](images/ovhcloud_user_management_groups_3.png){.thumbnail}
140140

141141
When you later log in with a user from the **Intern** group, your OVHcloud account will recognise that the user has the role "UNPRIVILEGED" specified by his group.
142142

143-
You will then be able to log out of your account and log back in with your OKTA as an identity provider.
143+
You will then be able to log out of your account and log back in with your Okta as an identity provider.
144144

145145
### Connecting via SSO
146146

147147
On [the OVHcloud login page](https://www.ovh.com/auth/?action=gotomanager&from=https://www.ovh.co.uk/&ovhSubsidiary=GB), enter your [login](https://docs.ovh.com/gb/en/customer/create-ovhcloud-account/#what-is-my-nic-handle) followed by **/idp** without a password and click the `Login`{.action} button.
148148

149149
![Connection to OVHcloud federation](images/ovhcloud_federation_login_1.png){.thumbnail}
150150

151-
You are then redirected to your OKTA login page. Enter the login and password for a user of your OKTA, then click the `Sign in`{.action} button.
151+
You are then redirected to your Okta login page. Enter the login and password for a user of your Okta, then click the `Sign in`{.action} button.
152152

153-
![OVHcloud Federation login Redirection OKTA](images/OKTA_login.png){.thumbnail}
153+
![OVHcloud Federation login Redirection Okta](images/OKTA_login.png){.thumbnail}
154154

155-
You are now logged in with the same customer ID, but through your OKTA user.
155+
You are now logged in with the same customer ID, but through your Okta user.
156156

157157
![OVHcloud User Info Federation](images/ovhcloud_user_infos_federation.png){.thumbnail}
158158

-48.6 KB
Loading

0 commit comments

Comments
 (0)