How to Connect Okta
How to Connect Okta with CloudZero
CloudZero supports single-sign on (SSO) for Okta. This enables users to seamlessly log in to CloudZero from an Okta tile, without needing to enter a CloudZero username and password.
Set Up a New SSO Integration with Okta
To set up a new SSO integration for CloudZero using Okta, complete the following steps:
- Create a new Okta application.
- Configure the Okta SSO integration in CloudZero.
- Complete the configuration in Okta.
Step 1: Create Okta Application
-
Log in to Okta and navigate to Admin Console > Applications > Applications.
-
Select Create App Integration.
-
Select OIDC - OpenID Connect as the Sign-in method.
-
Select Single-Page Application.
-
Select Next.
-
Enter a name in the App integration name field, such as
CloudZero
. -
Optionally, upload a logo to the Logo field.
-
In the Grant type field, select Advanced, and then check the box for Implicit (hybrid).
-
In the Sign-in redirect URIs field, enter
https://auth.cloudzero.com/login/callback
-
Click Save to create the app integration, then select Edit to configure additional options.
-
In the General tab, ensure the Proof Key for Code Exchange (PKCE) box is checked in the Client Credentials section.
-
Copy the Client ID.
-
Keep the Okta settings page open so you can finish configuring it in a later step.
Step 2: Configure Okta SSO Integration in CloudZero
-
Log in to CloudZero and navigate to Settings > SSO Integration.
-
In the Select Your Identity Provider section, select Okta from the Identity Provider Type drop-down menu.
-
Enter the Email Domain. Users with an email address from this domain will be forwarded to your Okta integration to log in to CloudZero.
-
Enter the Issuer. This is your OIDC Discovery Endpoint (for example,
https://example.okta.com/.well-known/openid-configuration
). See Okta's documentation for more information. -
Paste the client ID you copied from Okta into the Client ID field.
-
Select Save.
-
Select the Open SSO Test Window button to open a new browser tab to log into your IdP and confirm a successful round trip with CloudZero. A successful round trip will redirect you to https://jwt.io/ with a valid token. After you see a decoded token, you can close this browser tab.
-
When the test is successful, CloudZero's SSO Integration page automatically displays the message Testing Complete. If this does not happen within one minute, refresh the page.
-
Check the Enable log-ins with my SSO box.
This will immediately switch over the specified email domain to use the configured SSO.
If you need to roll back this configuration, contact your CloudZero support representative.
- Copy the Bookmark URL at the bottom of the page.
Step 3: Complete the Configuration in Okta
- Return to the Okta settings page and paste the bookmark URL you copied into the Initiate login URI field, which is in the Login section of the General tab.
- Select Save in Okta.
Users can now log into CloudZero by selecting the applicable tile in their Okta dashboard.
Updated 25 days ago