Step 7 — Modify Okta SAML Application
Metadata with ExtremeCloud IQ Settings
For this step, we recommend having ExtremeCloud IQ and Okta open in separate tabs,
as you will select data from your new IdP profile in ExtremeCloud IQ and
copy it over to your SAML application in Okta.
In
Okta:
Browse to your Admin Portal, navigate to Applications > Applications, and then select your SAML application.
From the General tab, scroll down to
SAML Settings, and then select
Edit.
Select Next, and then select the
Configure SAML tab.
In ExtremeCloud IQ:
Navigate to General Settings > Enable Single Sign-on, in the row for your IdP profile completed in Step
6, select , and then select
Edit.
Select the ExtremeCloud (SP) Connection
tab.
Select Download Certificate, and save the file
to your computer.
Copy the SP Entity
ID value from ExtremeCloud IQ and copy it to the
Audience
URI (SP Entity ID) field in Okta.
Copy the ACS URL
value from ExtremeCloud IQ and copy it to the Single Sign-On
URL field in Okta.
In Okta:
Under SAML Settings > General, select Show Advanced
Settings.
For Signature Certificate, select
Browse files.
Select All Files, navigate to find the
certificate file you downloaded in the previous step, select the
certificate, and then select Open to upload the
ExtremeCloud IQ certificate.
Select Enable Single Logout.
Copy the SLO URL value from
ExtremeCloud IQ and copy it to the
Single Logout URL field in Okta.
Copy the SP Entity ID value from
ExtremeCloud IQ and copy it to the
SP Issuer field in Okta.
Select Next, and then select
Finish. Click to view your SAML application
again.
Select the Sign On tab, and in the
SAML 2.0 section, select More
Details.
Next to the Single Logout URL field, select
Copy.
Use this URL to replace the placeholder text we submitted
earlier.
In ExtremeCloud IQ:
Return to the IdP Connection tab of your IdP
profile and paste that value into the SLO URL and
SLO Response URL fields, replacing your
placeholder values.