Configure SAML SSO with Okta
Overview
This guide provides Okta administrators with the necessary steps to configure Single Sign-On (SSO) for Brivo using SAML 2.0. Before beginning, ensure you have administrative access to your Okta console.
Step 1: Create the SAML Integration in Okta
Log in to your Okta Admin Console. If you are currently in the Developer Console, switch to the Classic UI using the dropdown menu in the top-left corner.
Navigate to Applications and click the Add Application button.
Click Create New App.
In the dialog box, select Web as the Platform and SAML 2.0 as the Sign on method. Click Create.
Step 2: Configure General Settings
In the App Name field, enter a name for the application. Brivo recommends using your Brivo account name and account number to ensure the name is unique.
(Optional) Upload a logo (PNG, JPG, or GIF, max 1400x400px and <100kb).
Under App Visibility, ensure both checkboxes are checked.
Click Next.
Step 3: Configure SAML Settings
In this section, you will define how Okta communicates with Brivo. You will need a "connection name," which is typically your domain name.
Single sign on URL: Enter
https://login.brivo.com/login/callback?connection=(your connection name).Check the box for Use this for Recipient URL and Destination URL.
Audience URI (SP Entity ID): Enter
urn:auth0:brivo:(your connection name).Attribute Statements: Add a statement with the following details:
Name: email
Name format: Unspecified
Value: user.email
Click Next.
Step 4: Feedback and Assignments
On the Feedback page, select I’m an Okta customer adding an internal app and click Finish.
You will be redirected to the Application Description page. Click the Assignments tab.
Click Assign and select either Assign to People or Assign to Groups to grant users access to the Brivo SSO integration.
Click Done once assignments are complete.
Step 5: Retrieve Configuration Details
Click on the Sign On tab within your new application.
Click the View Setup Instructions button.
Locate and copy the following two items, as you will need them for the final step:
Identity Provider Single Sign-On URL
X.509 Certificate
Step 6: Submit Configuration to Brivo
To finalize the connection, you must submit your details to Brivo via their online configuration form.
Enter your email address and Brivo account number.
Select Okta as your provider.
Choose whether Local Auth should be enabled or disabled.
Important Warning: If Local Auth is disabled, all administrators MUST use the SSO integration to log in. They will no longer be able to use their email and password on the standard Brivo login screen. Furthermore, SSO is not currently supported on the Brivo Access mobile app; administrators will lose access to the mobile app if Local Auth is disabled.
Provide the Connection Name, X.509 Certificate, and Identity Provider Single Sign-On URL retrieved in Step 5.
Click Submit.
Once submitted, Brivo will complete the remaining backend configuration steps to activate your SSO connection.