Configure Okta with Lansweeper SSO

Prev Next
Okta is a third-party tool

This article uses Okta, a third-party tool. We aim to keep these details accurate, but we can't guarantee they're always complete or up to date. For the most reliable information, refer to the Okta documentation.

There are two ways to log in to Lansweeper Platform: with a login and password created in Lansweeper Platform itself, or with SSO. SSO is supported for identity providers that offer SAML (Security Assertion Markup Language) or OIDC (OpenID Connect). Okta is one such identity provider (IdP).

This article covers where in Okta to find the SSO connection details you enter in Lansweeper Platform, using SAML as the connection type. Read Set up an SSO connection first.

In Lansweeper Platform, you exchange these values in the SSO connection itself. Select your profile picture in the top-right corner, select Account settings > Single Sign-On, then select Create SSO connection. The Service provider metadata section holds the values you copy into Okta, and the Identity provider configuration section is where you enter the values you get back from Okta.

For more about securing your Lansweeper account, see 5 Features of Lansweeper Cloud that Strengthen Security.

Create a SAML app integration in Okta

  1. In the Okta Admin Console, go to Applications > Applications.
  2. Select Create App Integration, select SAML 2.0, and select Next.
  3. In General Settings, enter a descriptive App name and select Next.

Configure your SSO app

  1. Copy the Assertion Consumer Service (ACS) URL from the Service provider metadata section in Lansweeper and paste it into the Okta Single sign-on URL field.

  2. Copy the Entity ID from the Service provider metadata section in Lansweeper and paste it into the Okta Audience URI (SP Entity ID) field.

  3. In the Attribute Statements section, add an attribute with the following values:

    • Name: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
    • Value: user.email

    This name matches the default Email claim in Lansweeper. If you use a different name, such as email, enter the same name in the Email claim field in Lansweeper.

  4. Select Next, answer the feedback questions, and select Finish.

Copy the Okta details to Lansweeper

  1. On the Sign On tab of your new app, go to the SAML Signing Certificates section.
  2. For the active certificate, select Actions > Download certificate.
  3. Rename the downloaded file so it ends in ".cer" instead of ".cert".
  4. In Lansweeper, upload the certificate as the X509 signing certificate in the Identity provider configuration section.
  5. Back on the Sign On tab in Okta, select View SAML setup instructions.
  6. Copy the Identity Provider Single Sign-On URL and paste it into the Sign in URL field in the Identity provider configuration section in Lansweeper.