CluedIn PaaS

Sign in with Okta through Microsoft Entra

On this page

  1. Configure Okta
  2. Connect Entra and CluedIn
  3. Troubleshooting
  4. References

Use Okta as the upstream SAML provider and Entra as the token issuer for CluedIn. Review the shared prerequisites and SAML values first.

Configure Okta

  1. Open Applications > Applications > Create App Integration in the Okta Admin Console.
  2. Select SAML 2.0 and give the integration a descriptive name.
  3. Use the shared ACS as Single sign-on URL, and the shared audience as Audience URI (SP Entity ID).
  4. Choose Persistent as the Name ID format. Configure an administrator-managed, stable application username; do not rely on a user-editable profile field.
  5. Add an attribute statement named http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress, mapped to the user’s email.
  6. Finish the integration, assign the pilot user or group, and obtain the IdP metadata and signing certificate from its sign-on settings.

Inspect the emitted NameID across repeated sign-ins. Preserve it when email changes. Review any application username update behavior.

Connect Entra and CluedIn

Complete Entra federation, guest onboarding, and CluedIn role assignment. Use the resource tenant associated with your CluedIn SSO connection.

Start the pilot sign-in from CluedIn, verify the correct user and role, then test role changes and logout. Provider roles or groups require an explicit authorization design; forwarding them in SAML does not automatically assign CluedIn roles.

Validate this pattern in your deployment before rollout. The provider application authenticates to Entra; its ACS points to Entra rather than CluedIn.

Troubleshooting

Check Okta application assignment and the System Log when the user cannot reach authentication. If Entra rejects the assertion, inspect the NameID format and email attribute rather than using the wizard’s default email NameID settings.

References