This setup might fail without parameter values that are customized for your organization. Please use the Okta Administrator Dashboard to add an application and view the values that are specific for your organization.
Contents
Supported Features
The Okta/Avigilon Alta Security SAML integration currently supports the following features:
SP-initiated SSO
IdP-initiated SSO
For more information on the listed features, visit the Okta Glossary.
Configuration Steps
On Okta:
1. Go to your Okta instance and install the Avigilon Alta app.
Search for the
Avigilon Alta
app here:
2. Set up your Region Base URL:
The US region is
https;//api.openpath.com
The EU region is
https://api.eu.openpath.com
3. Create an API token in Okta:
In Okta, navigate to Security > API.
Click Create Token, name the token Openpath Security, then click Create Token.
Save the token value for later.
Important: This is the only time that you will able to view it.
4. Log in to the Avigilon Alta Control Center.
5. Navigate to App Marketplace, click ‘Get apps’, and select Okta:
6. Now, from App Marketplace, click ‘My apps’, and select Okta:
7. Enter the following:
API URL: Copy and paste the following:
Sign in to the Okta Admin Dashboard to have this variable generated for you
API Key: Enter the API Token you made a copy of in step 3.
Check Enable Single Sign-On (SSO) for users with portal access.
Namespace: Make a copy of this value.
Turn on Allow IDP-Initiated SSO.
SAML SSO URL: Copy and paste the following:
Sign into the Okta Admin Dashboard to generate this variable.
SAML Issuer: Copy and paste the following:
Sign into the Okta Admin Dashboard to generate this variable.
SAML Certificate: Copy and paste the following:
Sign into the Okta Admin Dashboard to generate this variable.
Click Save:
8. Go back to the Okta integration.
Auto-remove users from groups: This will remove users from Avigilon Alta groups if they no longer exist in Okta groups.
Only import users from groups with an Avigilon Alta group mapping: When enabled, this feature prevents users from being imported from the identity provider if they do not belong to at least one identity provider group mapped to an Avigilon Alta group. This is typically the desired behavior when the identity provider contains large numbers of users (or non-person system accounts) that will never need access to Avigilon Alta-managed resources.
Map Okta groups to Avigilon Alta groups.
Click Save:
9. Click Sync:
10. Navigate to Users > Users and check that the users were imported from Okta into Avigilon Alta.
11. Done!
Notes
The following SAML attributes are supported:
Name | Value |
---|---|
firstName | user.firstName |
lastName | user.lastName |
user.email | |
login | user.login |
id | user.id |
SP-initiated SSO
1. Go to: https://control.openpath.com/login/sso
2. Enter your email then click Sign In:
Note: Avigilon Alta only prompts for a Namespace (you made a copy of in step 4 above) if the namespace is required to disambiguate between multiple IDP-synced records on the Avigilon Alta side that have the identical email address.
Related Pages:
How do I log into the Avigilon Alta Open app with Okta SSO?
Add Comment