Provision console users via Okta
My OPSWAT Central Management offers an integration with a 3rd-party Single Sign-on Service (SSO). This enables an account to provision new users to manage your account. When a user logs into the My OPSWAT Central Management console through your own SSO service, My OPSWAT Central Management will provision that user as a read-only user on your account. You can update the user's role later.
My OPSWAT Central Management uses the secure and widely adopted industry standard Security Assertion Markup Language 2.0 (SAML 2.0), so that you can integrate easily with any large identity provider that supports SAML 2.0.
Prerequisites
The 3rd-party Single Sign-on Service (SSO) feature is available for paid Customers. If you are using a free account, and you would like to use the SSO feature. Please click the "Upgrade Request" button on your Console Management \ Settings \ Global \ Account tab.
Supported features
- IdP-initiated SSO
- SP-initiated SSO
- Just-In-Time provisioning
Configuration steps
- Log into Okta as an administrator
- Navigate to Applications and click on "Browsers App Catalog" button
- Search OPSWAT and select My OPSWAT Central Management application

- Click the Add Integration button

- Enter the Application Label, for example OPSWAT MetaDefender IT Access and click the Done button

- Navigate to Sign On tab.
- Open the Metadata URL on another tab and save the content as idpmetadata.xml

- Login MetaDefender IT Access Console
- Navigate to User Management > SSO > Console Authentication
- Check Enable Single Sign On
- Upload idpmetadata.xml from step 7 and click the SAVE button

- Scroll down to the My OPSWAT Central Management Login URL and copy the URL

- Switch to Okta Admin
- Click the Edit button
- Scroll down to the Advanced Sign-on Settings and paste the My OPSWAT Central Management Login URL

- Click the Save button
- DONE. Now you need to assign people/groups who can access this application on Okta.
If You couldn't import the identity provider information from the IdP metadata file, you can get information from the Set up instruction page of the app and copy IdP certificate, Issuer, and IdP SSO URL to the My OPSWAT Central Management console
SP-initiated SSO
Contact OPSWAT Support to enable SP-initiated SSO for your domain users