Okta - SAML Relying Party Configuration - RSA Ready Implementation Guide
Originally Published: 2021-11-07
This section describes how to integrate RSA Cloud Authentication Service with Okta using SAML Relying Party.
Configure RSA Cloud Authentication Service
Perform these steps to configure RSA Cloud Authentication Service
Procedure
- Sign in to RSA Cloud Administration Console.
- Navigate to Authentication Clients menu and select Relying Parties.
- In the Relying Party Catalog, select Add a Relying Party and click Add for Service Provider SAML.
- On the Basic Information page, enter the name for the application in the Name field and click Next Step.
- In the Authentication tab, select SecurID manages all authentication, Select a Primary Authentication Method and Access Policy as required and click Next Step.
- Under Data Input Method, click Import Metadata file from Okta to populate the Assertion Consumer Service URL value and Service Provider Entity ID.
- Under the Message Protection section, for SAML Response Protection:
-
- Select IdP signs assertion with response.
- Scroll down to the User Identity section and select the following:
- Identifier Type – emailAddress
- Property – mail
- Identity Provider, same Entity ID is required to configure in the Okta configuration.
- Click Save and Finish.
- On the My Relying Parties page, click Edit Dropdown and select Metadata option to download the metadata.
- Click Publish Changes. After publishing, your application is now enabled for SSO.
The Configuration is complete.
OKTA Configuration
Perform these steps to configure OKTA.
Procedure
- Log in to Okta with the admin account, browse to the Security > Identity Providers > Add Identity Provider.
- Select the Identity Provider as SAML 2.0 click on next.
- Provide the name details to configure General settings.
- Select IdP Usage as SSO only and select the checkbox for Account matching with Persistent Name ID.
- Provide details in the Account matching with IdP Username section.
-
- Select the idpuser.subjectNameID from drop down for IDP username.
- Match against field select the Email from drop down.
- If no match is found select the check box Redirec to Okta Sign-in page.
- Provide the following details in the SAML Protocol Setting section:
-
- IdP Issuer URI - Obtain from the metadata file downloaded from RSA.
- IdP Single Sign-On URL - Obtain from the metadata file downloaded from RSA.
- IdP Signature Certificate – Upload the downloaded certificate from RSA.
- Request Binding – Select HTTP POST.
- Provide the details as shown in the following figure and click Finish.
-
- Request Signature select the check box Sign SAML Authentication requests.
- Request Signature Algorithm select the SHA-256 from the drop down list.
- Destination Specify the destination RSA URL.
8. Navigate to the Identity Providers section and click Add Routing Rule under the Routing rules tab.
9. Provide the Rule name, select the IdP as Okta under IdPs, and click Create rule.
The configuration is complete.
Related Articles
Manage Relying Parties 34Number of Views Relying Parties 50Number of Views PurelyHR-integration-configuration-relying-party 2Number of Views Add a Relying Party 31Number of Views Microsoft Office 365 - SAML Relying Party Configuration - RSA Ready Implementation Guide 233Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.9 Release Notes (January 2026) An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?