Enable SSO for Okta
National Crime Check supports single sign-on (SSO) using Okta.
Single Sign-On connections support these features:
- SP-initiated SSO -- login from the NCC website
- IdP-initiated SSO -- login to NCC from your identity provider portal
- Just-In-Time provisioning
- Multiple roles and permission sets
The following SAML attributes are supported:
first_name | user.firstName |
last_name | user.lastName |
role | Used for role-based permissions |
To make use of role-based permissions you can supply the role attribute using a user field or by using group attributes.
Connecting to Okta
- Navigate to the Staff section and then the SSO tab
- Click the Okta icon
- Click the Add Application button
- Confirm the application details and then click the Done button
- Navigate to the Sign On tab and click the Edit link
- Scroll down to the Advanced Sign-on Settings area and enter the Connection ID
- Click the Save button
- Now find the Metadata URL on this same page and copy this value
- Paste the metadata url into the integration dashboard
- Choose the permissions which are available for single sign-on users
- Click the Enable Single-Sign-On button
- SSO is now enabledSome basic details are shown at the top of the page. You can see the Connection ID and Identity Provider (Okta).
- You will need to assing some people or groups to your app before it can be usedThis is done within the Okta admin portal in the same way that assignments are done for any other application.
Setting up roles (optional)
- In the Okta control panel, open the National Crime Check app
- Navigate to the Sign On tab and click the Edit link
- Expand the Attributes interface
- Under group attribute statements enter "role" as the name, matches regex, and
.*
for the filter - Set up your roles in the integration dashboard using role names which match your group namesSee also Roles & Permissions.
Logging in
You can provide the Login URL to your staff to access the integration dashboard using single sign-on
Staff can also login from within the Okta applications portal