Okta SSO
Configure SAML 2.0 SSO and SCIM provisioning for Natoma using the Okta Integration Network (OIN) application.
This guide covers setup for Natoma using the Okta OIN (Okta Integration Network) application, which supports both SAML 2.0 for Single Sign-On and SCIM for user and group provisioning.
SAML 2.0 SSO Setup
Prerequisites
When using SAML as the SSO mode with provisioning, your tenant must be upgraded from a free trial.
Supported Features
SP-initiated SSO (Single Sign-On)
IdP-initiated SSO (through Third-party Initiated Login)
Just-In-Time provisioning
Attribute Statements
The following SAML attributes are supported:
email
user.email
name
user.firstName + " " + user.lastName
SP-Initiated SSO
The sign-in process is initiated from Natoma:
From your browser, navigate to the Natoma sign-in page.
Enter your Okta email and click Sign in, then enter your Okta credentials when prompted.
If your credentials are valid, you are redirected to the Natoma dashboard.
Setup Instructions
1. Add the Application in Okta
Log in to your Okta admin account.
Navigate to Applications and select Browse App Catalog.
Search for Natoma and click Add Integration.
2. Copy your Tenant ID from Natoma
In Natoma, go to Admin > SSO.
Copy your tenant ID from the Entity ID or ACS URL field.
Paste the tenant ID into Okta and click Done.
3. Copy the Metadata URL to Natoma
In Okta, navigate to the Sign On tab and copy the Metadata URL.
Back in Natoma, paste the Metadata URL into the SSO settings.
Click Test SAML. Once the test passes, click Update.
4. Assign the Application
In Okta, go to the application, click Assignments, and assign the necessary people or groups.
SCIM Provisioning Setup
SCIM (System for Cross-domain Identity Management) enables continuous synchronization of users and groups between Okta and Natoma.
Prerequisites
When using SAML as the SSO mode with provisioning, your tenant must be upgraded from a free trial.
Supported Features
Create users
Update user attributes
Deactivate users
Import users
Import groups
Profile sourcing
Group push
Setup Instructions
1. Enable SCIM in Natoma
In the Natoma Admin Console, navigate to Admin Settings > SSO (or Identity Providers).
Toggle the option for SCIM Integration.
Click Generate Token and immediately copy the token.
You will not be able to view this token again — save it before closing.
2. Configure API Integration in Okta
In your Okta application, navigate to the Provisioning tab.
Under Settings, go to Integration and click Edit.
Check the Enable API Integration box.
Paste the generated SCIM token into the API token field.
Click Test API Credentials, then Save.
3. Enable Provisioning to App
After saving, click To App in the settings panel, then click Edit.
Enable the following provisioning actions:
Create Users
Update User Attributes
Deactivate Users
Click Save.
4. Provision Users and Groups
In Okta, go to the application, click Assignments, and confirm the users and groups you want to provision are assigned.
To push groups, navigate to the Push Groups tab, select By name, enter the group name, select Push group memberships immediately, and click Save.
Last updated

