Overview
This guide describes how to configure Okta as the SAML 2.0 Identity Provider (IdP) for PRIZM. After completing the configuration, users assigned to the PRIZM application in Okta can securely access PRIZM using their corporate credentials.Prerequisites
Before you begin, ensure you have:- Okta Administrator privileges
- Permission to create SAML applications
- PRIZM Administrator access
- PRIZM Service Provider (SP) details:
- Entity ID
- ACS URL
- Sign-on URL
Step 1: Configure Okta
- Navigate to Applications → Create App Integration.

- Select SAML 2.0 and click Next.

- Enter the application name (for example, PRIZM).
- Configure the following SAML settings using the values available in PRIZM → Profile → Organization → SSO/SAML:

- Configure the required attribute mappings:


- Complete the application setup.
Step 2: Configure PRIZM
- In Okta, open the PRIZM application.
- Navigate to the Sign On tab.
- Download the Identity Provider Metadata XML (open the XML file URL and save the it in XML format)
- In PRIZM, navigate to: Profile → Organization → SSO/SAML
- Enable Single Sign-On.
- Select Okta as the Identity Provider.
- Upload the Metadata XML.
- Click Update Configuration.
Step 3: Assign Users
In Okta:- Open the PRIZM application.
- Navigate to Assignments.
- Assign the required users or groups.

Step 4: Test Login
- Navigate to the PRIZM login page.
- Enter your corporate email address.
- Authenticate through Okta.
- Existing PRIZM users are signed in.
- New users are automatically created during their first login (JIT provisioning).
- Roles are assigned based on incoming group mappings.
SCIM Provisioning (Optional)
- Navigate to Applications → PRIZM → Provisioning.
- Click Configure API Integration.
- Enable API Integration.
- Enter:
- SCIM Base URL
- Bearer Token
- Click Test API Credentials.
- Enable provisioning.
- Assign users or groups.

